Context-EngineBLOCK
Context-Engine MCP - Agentic Context Compression Suite
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Context Engine
Semantic code search, memory, and symbol intelligence for AI coding assistants.
Get your free account at dev.context-engine.ai
Website · Get Started · License
Install Skills
Context Engine ships AI agent skills that teach your coding assistant how to use 30+ MCP tools for semantic search, symbol graph navigation, memory, and more.
Claude Code / Claude Desktop
Recommended: Install natively from the public GitHub repo:
# Add the marketplace (one-time) /plugin marketplace add Context-Engine-AI/Context-Engine # Install the skill /plugin install context-engine
This pulls the skill directly from GitHub and auto-loads MCP tool guidance into your session.
Alternatively, copy the rules file manually:
cp -r skills/context-engine/ your-project/.claude/
Cursor
Context Engine rules are included in .cursorrules at the root of your workspace. Cursor picks this up automatically when the file is present.
# Copy to your project root cp .cursorrules your-project/.cursorrules
Codex (OpenAI)
Recommended: Install natively using the built-in skill installer — just ask Codex:
"Install the context-engine skill from https://github.com/Context-Engine-AI/Context-Engine"
Codex will pull .codex/skills/context-engine/ (including SKILL.md and reference docs) into ~/.codex/skills/ automatically.
Or install manually:
cp -r .codex/skills/context-engine/ ~/.codex/skills/context-engine/
Windsurf
cp -r .codex/skills/ your-project/.codex/skills/
Augment Code
cp -r .augment/ your-project/.augment/
Gemini
cp GEMINI.md
c39f0761d319OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add context-engine --env CLICKHOUSE_PASSWORD=${CLICKHOUSE_PASSWORD} --env COMMIT_SUMMARY_MAX_TOKENS=${COMMIT_SUMMARY_MAX_TOKENS} --env CTXCE_AUTH_ADMIN_TOKEN=${CTXCE_AUTH_ADMIN_TOKEN} --env CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN=${CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN} -- npx -y [email protected]{
"mcpServers": {
"context-engine": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CLICKHOUSE_PASSWORD": "${CLICKHOUSE_PASSWORD}",
"COMMIT_SUMMARY_MAX_TOKENS": "${COMMIT_SUMMARY_MAX_TOKENS}",
"CTXCE_AUTH_ADMIN_TOKEN": "${CTXCE_AUTH_ADMIN_TOKEN}",
"CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN": "${CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN}"
}
}
}
}Exposed tools (25)
22 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
change_history_for_path | read | Summarize recent change metadata for a file path from the index. |
code_search | read | Exact alias of repo_search (hybrid code search with reranking enabled by default). |
collection_map | read | Return collection↔repo mappings with optional Qdrant payload samples. |
context_answer_compat | read | Compatibility wrapper for context_answer (lenient argument handling). |
context_search | read | Blend code search results with memory-store entries (notes, docs) for richer context. |
expand_query | read | LLM-assisted query expansion (local llama.cpp, if enabled). |
list_workspaces | read | Scan search_root recursively for .codebase/state.json and summarize workspaces. |
memory_find | read | Find memory-like entries by vector similarity (dense + lexical fusion). |
memory_store | read | Store a memory entry into Qdrant (dual vectors consistent with indexer). |
pattern_search | read | Find structurally similar code patterns across all languages. |
qdrant_index | read | Index the workspace (/work) or a specific subdirectory. |
qdrant_index_root | read | Initialize or refresh the vector index for the workspace root (/work). |
qdrant_list | read | List available Qdrant collections. |
qdrant_prune | destructive | Remove stale points for /work (files deleted/moved but still in the index). |
qdrant_status | read | Summarize collection size and recent index timestamps. |
repo_search | read | Zero-config code search over repositories (hybrid: vector + lexical RRF, rerank ON by default). |
repo_search_compat | read | Compatibility wrapper for repo_search (lenient argument handling). |
search_callers_for | read | Heuristic search for callers/usages of a symbol. |
search_commits_for | write | Search git commit history indexed in Qdrant. |
search_config_for | read | Find likely configuration files for a service/query. |
search_importers_for | read | Find files likely importing or referencing a module/symbol. |
search_tests_for | read | Find test files related to a query. |
set_session_defaults | write | Set defaults (e.g., collection, mode, under) for subsequent calls. |
symbol_graph | read | Query the symbol graph to find callers, definitions, or importers. |
workspace_info | read | Read .codebase/state.json for the current workspace and resolve defaults. |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
.env
help="Path to query file for latency eval (one query per line)"
help="Path to gold queries JSONL for quality eval (Hit@k, MRR)"
.DS_Store
mod = __import__(pkg_name)
mod = __import__(pkg_name)
# MCP_INDEXER_URL=http://127.0.0.1:30810/mcp
qdrant_prune
.DS_Store
.env
.indexignore
.prettierignore
.qdrantignore
__import__(pkg)
content_hash = hashlib.md5(func_content.encode()).hexdigest()[:8]
return hashlib.md5(doc_id.encode()).hexdigest()
content_hash = hashlib.md5(code.encode("utf-8", errors="ignore")).hexdigest()[:12]content_hash = hashlib.md5(query.encode("utf-8", errors="ignore")).hexdigest()[:12]idx = int(hashlib.md5(query_hash.encode()).hexdigest(), 16) % len(self.variants)
docker build -t $(IMAGE_REGISTRY)/context-engine:$(IMAGE_TAG) ../../
[{"operation": "created", "path": "../../evil.txt"}],"source_path": "../../escape.txt",
{"operation": "created", "path": "../../evil.txt"},`http://127.0.0.1:30810/mcp`) and is what the VS Code extension uses in its
http://127.0.0.1:<port>/mcp
Gates applied: no_behavioural_pass.
c39f0761d319full audit observations/trust-audit/mcp-server/context-engine-ai__context-engine-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | c39f0761d319 | BLOCK | F | 55 | first audit |
Questions
What is the Context-Engine MCP server?
Context-Engine MCP - Agentic Context Compression Suite
What tools does Context-Engine expose?
25 in total: 22 read-only, 2 that write, and 1 that can delete or overwrite (qdrant_prune). Every one is listed on this page with its risk.
Is Context-Engine safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Context-Engine need?
It reads CLICKHOUSE_PASSWORD, COMMIT_SUMMARY_MAX_TOKENS, CTXCE_AUTH_ADMIN_TOKEN, CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN, CTXCE_AUTH_BACKEND_URL, CTXCE_AUTH_DB_URL, CTXCE_AUTH_ENABLED, CTXCE_AUTH_PASSWORD, CTXCE_AUTH_SESSION_TTL_SECONDS, CTXCE_AUTH_SHARED_TOKEN, CTXCE_AUTH_TOKEN and CTXCE_AUTH_USERNAME from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Context-Engine run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as context-engine at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (c39f0761d319), read on 2026-10-01. The repository is watched and re-audited when it changes.