Atlas / MCP servers / forloopcodes / Context+

Context+CAUTION

mcp/forloopcodes/context-4

Semantic Intelligence for Large-Scale Engineering. Context+ is an MCP server designed for developers who demand 99% accuracy. By combining RAG, Tree-sitter AST, Spectral Clustering, and Obsidian-style linking, Context+ turns a massive codebase into a searchable, hierarchical feature graph.

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
17 10r · 6w · 1d
Transport
stdio
License
MIT
Stars
1,985
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Semantic Intelligence for Large-Scale Engineering.

Context+ is an MCP server designed for developers who demand 99% accuracy. By combining RAG, Tree-sitter AST, Spectral Clustering, and Obsidian-style linking, Context+ turns a massive codebase into a searchable, hierarchical feature graph.

https://github.com/user-attachments/assets/a97a451f-c9b4-468d-b036-15b65fc13e79

Tools

Discovery

Analysis

Read from source at commit 34be165ae6eeOBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add contextplus --env CONTEXTPLUS_OPENAI_API_KEY=${CONTEXTPLUS_OPENAI_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "contextplus": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CONTEXTPLUS_OPENAI_API_KEY": "${CONTEXTPLUS_OPENAI_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (17)

10 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_interlinked_contextwriteBulk-add multiple memory nodes with automatic similarity linking. Computes embeddings for all items,
create_relationwriteCreate a typed edge between two memory nodes. Supports relation types: relates_to, depends_on, implements, references, similar_to, contains.
get_blast_radiusreadBefore deleting or modifying code, check the BLAST RADIUS. Traces every file and line where a specific symbol
get_context_treereadGet the structural tree of the project with file headers, function names, classes, enums, and line ranges.
get_feature_hubreadObsidian-style feature hub navigator. Hub files are .md files containing [[path/to/file]] wikilinks that act as a Map of Content.
get_file_skeletonreadGet detailed function signatures, class methods, and type definitions of a specific file WITHOUT reading the full body.
list_restore_pointsreadList all shadow restore points created by propose_commit. Each point captures the file state before the AI made changes.
propose_commitwriteThe ONLY way to write code. Validates the code against strict rules before saving:
prune_stale_linksdestructiveRemove stale memory graph edges whose weight has decayed below threshold via e^(-λt) formula.
retrieve_with_traversalwriteStart from a specific memory node and traverse the graph outward. Returns the starting node plus all reachable neighbors
run_static_analysiswriteRun the project
search_memory_graphreadSearch the memory graph by meaning with graph traversal. First finds direct matches via embedding similarity,
semantic_code_searchreadSearch the codebase by MEANING, not just exact variable names. Uses Ollama embeddings over file headers and symbol names.
semantic_identifier_searchreadSearch semantic intent at identifier level (functions, methods, classes, variables) with definition lines and ranked call sites.
semantic_navigatereadBrowse the codebase by MEANING, not directory structure. Uses spectral clustering on Ollama embeddings to group
undo_changereadRestore files to their state before a specific AI change. Uses the shadow restore point system.
upsert_memory_nodewriteCreate or update a memory node in the linking graph. Nodes represent concepts, files, symbols, or notes with auto-generated embeddings.
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
landing/src/app/api/instructions/route.ts:148
| \`prune_stale_links\`          | Remove decayed edges (e^(-λt)) and orphan nodes periodically.                      |
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
landing/src/components/InstructionsSection.tsx:150
| \`prune_stale_links\`    | Remove decayed edges (e^(-λt)) and orphan nodes periodically. |
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/index.ts:453
"Edges have weights (0-1) that decay over time via e^(-λt). Duplicate edges update weight instead of creating new ones.",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/index.ts:490
"Remove stale memory graph edges whose weight has decayed below threshold via e^(-λt) formula. " +
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
prune_stale_links
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/tree-sitter.ts:13
const GRAMMAR_DIR = join(dirname(fileURLToPath(import.meta.url)), "../../node_modules/tree-sitter-wasms/out");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/demo/blast-radius.demo.mjs:5
const { getBlastRadius } = await import("../../build/tools/blast-radius.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/demo/clustering.demo.mjs:4
await import("../../build/core/clustering.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/demo/context-tree.demo.mjs:5
const { getContextTree } = await import("../../build/tools/context-tree.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/demo/embeddings-proof.demo.mjs:6
await import("../../build/core/embeddings.js");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
landing/package.json
geist, @opennextjs/cloudflare, @tailwindcss/postcss, @types/node, @types/react, @types/react-dom, eslint, tailwindcss
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, claude, ignore, ml-matrix, ollama, simple-git, tree-sitter-wasms, web-tree-sitter
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha 34be165ae6eefull audit observations/trust-audit/mcp-server/forloopcodes__context-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2334be165ae6eeCAUTIONB88source changed, verdict held
06

Questions

What is the Context+ MCP server?

Semantic Intelligence for Large-Scale Engineering. Context+ is an MCP server designed for developers who demand 99% accuracy. By combining RAG, Tree-sitter AST, Spectral Clustering, and Obsidian-style linking, Context+ turns a massive codebase into a searchable, hierarchical feature graph.

What tools does Context+ expose?

17 in total: 10 read-only, 6 that write, and 1 that can delete or overwrite (prune_stale_links). Every one is listed on this page with its risk.

Is Context+ safe to connect to an agent?

With care. The audit graded it B (88/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Context+ need?

It reads CONTEXTPLUS_OPENAI_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Context+ run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as contextplus at 1.0.9.

How current is this page?

The grade is for one exact copy of the source (34be165ae6ee), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement