Code Context EngineBLOCK
Save 94% on AI coding tokens. Index your codebase, agents search instead of reading files. Works with Claude Code, Codex, Copilot, Cursor, Gemini CLI. Local MCP server, free, open source.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Code Context Engine
Index your codebase. AI searches instead of re-reading files.94% token savings, reproducibly benchmarked.
Website · Docs · Why CCE? · Benchmark · GitHub
Python 3.11+ · macOS · Li
a0d1ac690714OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add code-context-engine -- uvx code-context-engine==0.4.26
Exposed tools (6)
5 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
expand_chunk | read | Get the full original content for a compressed chunk |
index_status | read | Check when the index was last updated |
record_code_area | read | Record a code area (file + description) worked on, for future session_recall |
record_decision | read | Record a decision (with reason) for future session_recall |
reindex | write | Trigger re-indexing of a file or the entire project |
related_context | read | Find related code via graph edges |
Trust audit
BLOCKgrade F · trust 53/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
".npmrc", ".pypirc", ".netrc",
".git-credentials",
"id_rsa", "id_dsa", "id_ecdsa", "id_ed25519", "id_xmss",
("AWS_KEY = AKIA1234567890ABCDEF", "AWS_ACCESS_KEY"),out, fired = redact_secrets("key=AKIAQ4ZRTPPPK1ABCDEF")assert "AKIAQ4ZRTPPPK1ABCDEF" not in out
("export TOKEN=ghp_abcdefghijklmnopqrstuvwxyz0123456789", "GITHUB_PAT"),text = "# comment\ntoken = ghp_abcdefghijklmnopqrstuvwxyz0123456789\n"
(p / "id_rsa").write_text("-----BEGIN RSA PRIVATE KEY-----\n...\n")"-----BEGIN RSA PRIVATE KEY-----\n"
("xoxb-1234567890-abcdef-1234567890abcdef1234", "SLACK_TOKEN"),en_2079337.pf_fragment
en_29c695e.pf_fragment
en_4210912.pf_fragment
en_61a169c.pf_fragment
en_738641a.pf_fragment
.nojekyll
(p / "id_rsa").write_text("-----BEGIN RSA PRIVATE KEY-----\n...\n")assert "id_rsa" not in names
assert _ollama_available("http://10.255.255.1:11434") is False"On SessionStart, the hook script POSTs JSON to http://127.0.0.1:${PORT}/hooks/SessionStart","http://127.0.0.1:11434",
"http://0.0.0.0:11434",
"http://192.168.1.50:11434",
@astrojs/starlight, astro, sharp
Gates applied: no_behavioural_pass.
a0d1ac690714full audit observations/trust-audit/mcp-server/elara-labs__code-context-engine.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | a0d1ac690714 | BLOCK | F | 53 | first audit |
Questions
What is the Code Context Engine MCP server?
Save 94% on AI coding tokens. Index your codebase, agents search instead of reading files. Works with Claude Code, Codex, Copilot, Cursor, Gemini CLI. Local MCP server, free, open source.
What tools does Code Context Engine expose?
6 in total: 5 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Code Context Engine safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (53/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Code Context Engine need?
It reads CCE_API_TOKEN, CCE_DASHBOARD_TOKEN, SECRET_KEY and TOKENIZERS_PARALLELISM from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Code Context Engine run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as cce-docs at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (a0d1ac690714), read on 2026-10-01. The repository is watched and re-audited when it changes.