Atlas / MCP servers / cornelcroi / Context Lens

Context LensSAFE

mcp/cornelcroi/context-lens

Semantic search knowledge base for MCP-enabled AI assistants. Index local files or GitHub repos, query with natural language. Built on LanceDB vector storage. Works with Claude Desktop, Cursor, and other MCP clients.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 3r · 1w · 2d
Transport
stdio · streamable-http
License
MIT
Stars
24
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Give your AI the ability to understand meaning, not just match keywords.

[](https://badge.fury.io/py/context-lens) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT)

What is Context Lens?

Context Lens transforms any content into a searchable knowledge base for your AI assistant. This self-contained Model Context Protocol (MCP) server with built-in serverless vector storage (LanceDB) brings semantic search to your conversations. Point it at any content - codebases, documentation, contracts, or text files - and your AI can instantly understand and answer questions about the content.

Traditional keyword search finds files containing specific words. Miss the exact term? Miss the content.

Context Lens understands meaning. Ask about "authentication" and find code about login, credentials, tokens, OAuth, and access control - even if those files never use the word "authentication."

See It In Action

Want to understand how Context-Lens works? Here's the fun part: you can use Context-Lens to learn about Context-Lens.

Demo: Using Claude Desktop with Context-Lens to index and query this repository itself. No git clone, no scrolling through code - just questions and answers.

Why LanceDB?

Context Lens uses LanceDB - a modern, serverless vector database:

  • 🆓 Completely Free & Local - No cloud services, API keys, or subscriptions
  • ⚡ Zero Infrastructure - Embedded database, just a file on disk
  • 🚀 Fast & Efficient - Built on Apache Arrow, optimized for vector search
  • 💾 Simple Storage - Single file database, easy to backup or move

Think of it as "SQLite for AI embeddings" - all the power of vec

Read from source at commit 5610bd8867dbOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add context-lens -- None context-lens==0.1.8
03

Exposed tools (6)

3 read · 1 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_documentwriteAdds a document or GitHub repository to the knowledge base.
clear_knowledge_basedestructiveRemoves all documents from the knowledge base.
get_document_inforeadGets metadata and statistics about a document in the knowledge base.
list_documentsreadLists all documents in the knowledge base with pagination support.
remove_documentdestructiveRemoves a document from the knowledge base.
search_documentsreadSearches documents using semantic vector similarity to find relevant content.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_knowledge_base, remove_document
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, lancedb, sentence-transformers, transformers, torch, numpy, pandas, pyarrow
Why it matters. 12 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
img/demo.gif
img/demo.gif
Why it matters. 5622022 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:157
# Load environment variables from .env file
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SETUP.md:145
# Load environment variables from .env file
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 5610bd8867dbfull audit observations/trust-audit/mcp-server/cornelcroi__context-lens.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-095610bd8867dbSAFEB89first audit
06

Questions

What is the Context Lens MCP server?

Semantic search knowledge base for MCP-enabled AI assistants. Index local files or GitHub repos, query with natural language. Built on LanceDB vector storage. Works with Claude Desktop, Cursor, and other MCP clients.

What tools does Context Lens expose?

6 in total: 3 read-only, 1 that write, and 2 that can delete or overwrite (clear_knowledge_base, remove_document). Every one is listed on this page with its risk.

Is Context Lens safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Context Lens need?

No credential environment variables were found in its source, so it appears to need none.

How does Context Lens run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as context-lens.

How current is this page?

The grade is for one exact copy of the source (5610bd8867db), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement