Context GeneratorBLOCK
CTX: a tool that solves the context management gap when working with LLMs like ChatGPT or Claude. It helps developers organize and automatically collect information from their codebase into structured documents that can be easily shared with AI assistants.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP-powered development toolkit that gives AI full access to your codebase
437aff4d650bOBSERVED · 2026-10-03Exposed tools (43)
34 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
collection | read | Collection name to operate on (operates on all if not specified) |
context | read | List all contexts in the project context config |
context-get | read | Get a specific context document from the project context config |
context-request | read | Request a context document using JSON schema, filters and modifiers |
directory-list | read | List directories and files with filtering options using Symfony Finder. Always ask for source path. |
file-delete-content | destructive | Delete specific line(s) from a file. Supports individual lines or ranges. |
file-insert-content | write | Insert content at specific line number(s) in a file. Supports single or batch insertions with automatic line offset calculation. |
file-read | read | Read content from one or more files within the project directory structure |
file-replace-content | read | Replace a unique occurrence of text in a file with exact matching. |
file-search | read | Search for text or regex patterns in files. Returns matches with surrounding context lines and line numbers. Useful for finding code patterns, function definitions, or specific content across the codebase. |
file-write | write | Write content to a file (mostly new files, use apply-path for updates if possible). Can create parent directories automatically. |
filesystem-ops | read | Guidance for using filesystem operations like reading, writing, moving, renaming, and updating files. |
find-docs | read | Find documentation for a specific library |
generate | read | Generate context files from configuration |
git-add | write | Add files to the staging area for the next commit. Stages changes in the working directory to be included in the next commit |
git-commit | write | Create a new commit with staged changes. Records changes to the repository with a commit message. Use git-add tool first to stage files, or use stageAll option to stage all tracked files automatically |
git-status | read | Show the working tree status - displays paths that have differences between the index and the working tree, between the index and HEAD, and paths that are untracked |
host | read | SSE host to bind to (default: 127.0.0.1) |
id | read | The ID of the prompt to display |
json | read | Output as JSON |
keep-aliases | read | Keep aliases when removing project (by default aliases are removed) |
library-search | read | Search for available documentation libraries in Context7 |
name | read | Alias name for the project |
output-json | read | Output result as JSON for machine parsing |
path | read | Path to the project directory. Use |
php-structure | read | Analyze PHP file structure and relationships. Returns class/interface/trait signatures with links to related files (extends, implements, use statements, type hints). Use depth parameter to follow relationships recursively. |
port | read | SSE port to bind to (default: 8080) |
project | read | Manage projects and change the working directory |
project-structure | read | Tries to guess the project structure |
project-switch | read | Switch to a different project by path or alias |
projects-list | read | List all registered projects with their paths, aliases, and configuration details. Also shows whitelisted projects available for the |
prompt-get | read | Use this tool when you already know the specific prompt ID and need to retrieve its full content. First use prompts-list tool to discover available prompts, then use this tool to get the detailed content of a specific prompt you need. Requires the prompt ID as a parameter. |
prompts-list | read | Use this tool to get a complete list of available prompts and their descriptions. This is useful when you need to discover what prompts exist and determine which might be helpful for your current task. |
rag-manage | read | Manage the project knowledge base. View statistics and configuration. |
rag-search | read | Search the project knowledge base using natural language. Returns relevant documentation, code explanations, and insights. |
rag-store | read | Store documentation, code explanations, or insights in the project knowledge base for later retrieval. |
repository | write | GitHub repository to update from |
schema | read | Get information about or download the JSON schema for IDE integration |
self-update | write | Update app to the latest version |
server | write | Start MCP server |
sse | write | Enable SSE (Server-Sent Events) support |
stdin | read | Read JSON arguments from stdin |
version | read | Display the current version and check for updates |
Trust audit
BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (16)
\exec($command, $output, $resultCode);
\exec($command, $output, $resultCode);
<env name="OAUTH_ISSUER_URL" value="http://127.0.0.1:8090"/>
<env name="OAUTH_SERVER_URL" value="http://127.0.0.1:8090"/>
issuerUrl: $env->get('OAUTH_ISSUER_URL', 'http://127.0.0.1:8090'),baseUrl: $env->get('OAUTH_SERVER_URL', 'http://127.0.0.1:8090'),file-delete-content
.php-cs-fixer.dist.php
__DIR__ . '/../../autoload.php',
<a href="https://t.me/spiralphp/2504"><img alt="Telegram" src="https://img.shields.io/badge/telegram-blue.svg?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmc
<a href="https://zread.ai/context-hub/generator" target="_blank"><img src="https://img.shields.io/badge/Ask_Zread-_.svg?style=for-the-badge&color=00b0aa&labelColor=000000&logo=data%3Aimage%2Fsvg%2Bxml
> MCP-powered development toolkit that gives AI full access to your codebase
That's it. Your AI assistant now has full access to your project through MCP.
All CTX commands support the `--env` (`-e`) option to load a specific `.env` file:
# Load .env file (default)
curl -sSL https://raw.githubusercontent.com/context-hub/generator/main/download-latest.sh | sh
Gates applied: no_behavioural_pass.
437aff4d650bfull audit observations/trust-audit/mcp-server/context-hub__context-generator.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 437aff4d650b | BLOCK | D | 67 | first audit |
Questions
What is the Context Generator MCP server?
CTX: a tool that solves the context management gap when working with LLMs like ChatGPT or Claude. It helps developers organize and automatically collect information from their codebase into structured documents that can be easily shared with AI assistants.
What tools does Context Generator expose?
43 in total: 34 read-only, 8 that write, and 1 that can delete or overwrite (file-delete-content). Every one is listed on this page with its risk.
Is Context Generator safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (67/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Context Generator need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (437aff4d650b), read on 2026-10-03. The repository is watched and re-audited when it changes.