Atlas / MCP servers / context-hub / Context Generator

Context GeneratorBLOCK

mcp/context-hub/context-generator

CTX: a tool that solves the context management gap when working with LLMs like ChatGPT or Claude. It helps developers organize and automatically collect information from their codebase into structured documents that can be easily shared with AI assistants.

Verdict
BLOCK
Grade
D
Trust score
67 /100
Exposed tools
43 34r · 8w · 1d
Transport
—
License
MIT
Stars
345
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP-powered development toolkit that gives AI full access to your codebase
Read from source at commit 437aff4d650bOBSERVED · 2026-10-03
02

Exposed tools (43)

34 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
collectionreadCollection name to operate on (operates on all if not specified)
contextreadList all contexts in the project context config
context-getreadGet a specific context document from the project context config
context-requestreadRequest a context document using JSON schema, filters and modifiers
directory-listreadList directories and files with filtering options using Symfony Finder. Always ask for source path.
file-delete-contentdestructiveDelete specific line(s) from a file. Supports individual lines or ranges.
file-insert-contentwriteInsert content at specific line number(s) in a file. Supports single or batch insertions with automatic line offset calculation.
file-readreadRead content from one or more files within the project directory structure
file-replace-contentreadReplace a unique occurrence of text in a file with exact matching.
file-searchreadSearch for text or regex patterns in files. Returns matches with surrounding context lines and line numbers. Useful for finding code patterns, function definitions, or specific content across the codebase.
file-writewriteWrite content to a file (mostly new files, use apply-path for updates if possible). Can create parent directories automatically.
filesystem-opsreadGuidance for using filesystem operations like reading, writing, moving, renaming, and updating files.
find-docsreadFind documentation for a specific library
generatereadGenerate context files from configuration
git-addwriteAdd files to the staging area for the next commit. Stages changes in the working directory to be included in the next commit
git-commitwriteCreate a new commit with staged changes. Records changes to the repository with a commit message. Use git-add tool first to stage files, or use stageAll option to stage all tracked files automatically
git-statusreadShow the working tree status - displays paths that have differences between the index and the working tree, between the index and HEAD, and paths that are untracked
hostreadSSE host to bind to (default: 127.0.0.1)
idreadThe ID of the prompt to display
jsonreadOutput as JSON
keep-aliasesreadKeep aliases when removing project (by default aliases are removed)
library-searchreadSearch for available documentation libraries in Context7
namereadAlias name for the project
output-jsonreadOutput result as JSON for machine parsing
pathreadPath to the project directory. Use
php-structurereadAnalyze PHP file structure and relationships. Returns class/interface/trait signatures with links to related files (extends, implements, use statements, type hints). Use depth parameter to follow relationships recursively.
portreadSSE port to bind to (default: 8080)
projectreadManage projects and change the working directory
project-structurereadTries to guess the project structure
project-switchreadSwitch to a different project by path or alias
projects-listreadList all registered projects with their paths, aliases, and configuration details. Also shows whitelisted projects available for the
prompt-getreadUse this tool when you already know the specific prompt ID and need to retrieve its full content. First use prompts-list tool to discover available prompts, then use this tool to get the detailed content of a specific prompt you need. Requires the prompt ID as a parameter.
prompts-listreadUse this tool to get a complete list of available prompts and their descriptions. This is useful when you need to discover what prompts exist and determine which might be helpful for your current task.
rag-managereadManage the project knowledge base. View statistics and configuration.
rag-searchreadSearch the project knowledge base using natural language. Returns relevant documentation, code explanations, and insights.
rag-storereadStore documentation, code explanations, or insights in the project knowledge base for later retrieval.
repositorywriteGitHub repository to update from
schemareadGet information about or download the JSON schema for IDE integration
self-updatewriteUpdate app to the latest version
serverwriteStart MCP server
ssewriteEnable SSE (Server-Sent Events) support
stdinreadRead JSON arguments from stdin
versionreadDisplay the current version and check for updates
03

Trust audit

BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (12 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (16)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/Lib/BinaryUpdater/Strategy/UnixUpdateStrategy.php:54
\exec($command, $output, $resultCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/Lib/BinaryUpdater/Strategy/WindowsUpdateStrategy.php:47
\exec($command, $output, $resultCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
phpunit.xml:22
<env name="OAUTH_ISSUER_URL" value="http://127.0.0.1:8090"/>
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
phpunit.xml:23
<env name="OAUTH_SERVER_URL" value="http://127.0.0.1:8090"/>
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/McpServer/HttpTransportBootloader.php:105
issuerUrl: $env->get('OAUTH_ISSUER_URL', 'http://127.0.0.1:8090'),
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/McpServer/HttpTransportBootloader.php:106
baseUrl: $env->get('OAUTH_SERVER_URL', 'http://127.0.0.1:8090'),
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
file-delete-content
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.php-cs-fixer.dist.php
.php-cs-fixer.dist.php
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app.php:38
__DIR__ . '/../../autoload.php',
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:10
<a href="https://t.me/spiralphp/2504"><img alt="Telegram" src="https://img.shields.io/badge/telegram-blue.svg?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmc
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:12
<a href="https://zread.ai/context-hub/generator" target="_blank"><img src="https://img.shields.io/badge/Ask_Zread-_.svg?style=for-the-badge&color=00b0aa&labelColor=000000&logo=data%3Aimage%2Fsvg%2Bxml
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:3
> MCP-powered development toolkit that gives AI full access to your codebase
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:185
That's it. Your AI assistant now has full access to your project through MCP.
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/config/variables-guide.md:99
All CTX commands support the `--env` (`-e`) option to load a specific `.env` file:
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/config/variables-guide.md:102
# Load .env file (default)
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:136
curl -sSL https://raw.githubusercontent.com/context-hub/generator/main/download-latest.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha 437aff4d650bfull audit observations/trust-audit/mcp-server/context-hub__context-generator.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-03437aff4d650bBLOCKD67first audit
05

Questions

What is the Context Generator MCP server?

CTX: a tool that solves the context management gap when working with LLMs like ChatGPT or Claude. It helps developers organize and automatically collect information from their codebase into structured documents that can be easily shared with AI assistants.

What tools does Context Generator expose?

43 in total: 34 read-only, 8 that write, and 1 that can delete or overwrite (file-delete-content). Every one is listed on this page with its risk.

Is Context Generator safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (67/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Context Generator need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (437aff4d650b), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement