Context+CAUTION
Semantic Intelligence for Large-Scale Engineering. Context+ is an MCP server designed for developers who demand 99% accuracy. By combining RAG, Tree-sitter AST, Spectral Clustering, and Obsidian-style linking, Context+ turns a massive codebase into a searchable, hierarchical feature graph.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Semantic Intelligence for Large-Scale Engineering.
Context+ is an MCP server designed for developers who demand 99% accuracy. By combining RAG, Tree-sitter AST, Spectral Clustering, and Obsidian-style linking, Context+ turns a massive codebase into a searchable, hierarchical feature graph.
https://github.com/user-attachments/assets/a97a451f-c9b4-468d-b036-15b65fc13e79
Tools
Discovery
Analysis
34be165ae6eeOBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add contextplus --env CONTEXTPLUS_OPENAI_API_KEY=${CONTEXTPLUS_OPENAI_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"contextplus": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CONTEXTPLUS_OPENAI_API_KEY": "${CONTEXTPLUS_OPENAI_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (17)
10 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_interlinked_context | write | Bulk-add multiple memory nodes with automatic similarity linking. Computes embeddings for all items, |
create_relation | write | Create a typed edge between two memory nodes. Supports relation types: relates_to, depends_on, implements, references, similar_to, contains. |
get_blast_radius | read | Before deleting or modifying code, check the BLAST RADIUS. Traces every file and line where a specific symbol |
get_context_tree | read | Get the structural tree of the project with file headers, function names, classes, enums, and line ranges. |
get_feature_hub | read | Obsidian-style feature hub navigator. Hub files are .md files containing [[path/to/file]] wikilinks that act as a Map of Content. |
get_file_skeleton | read | Get detailed function signatures, class methods, and type definitions of a specific file WITHOUT reading the full body. |
list_restore_points | read | List all shadow restore points created by propose_commit. Each point captures the file state before the AI made changes. |
propose_commit | write | The ONLY way to write code. Validates the code against strict rules before saving: |
prune_stale_links | destructive | Remove stale memory graph edges whose weight has decayed below threshold via e^(-λt) formula. |
retrieve_with_traversal | write | Start from a specific memory node and traverse the graph outward. Returns the starting node plus all reachable neighbors |
run_static_analysis | write | Run the project |
search_memory_graph | read | Search the memory graph by meaning with graph traversal. First finds direct matches via embedding similarity, |
semantic_code_search | read | Search the codebase by MEANING, not just exact variable names. Uses Ollama embeddings over file headers and symbol names. |
semantic_identifier_search | read | Search semantic intent at identifier level (functions, methods, classes, variables) with definition lines and ranked call sites. |
semantic_navigate | read | Browse the codebase by MEANING, not directory structure. Uses spectral clustering on Ollama embeddings to group |
undo_change | read | Restore files to their state before a specific AI change. Uses the shadow restore point system. |
upsert_memory_node | write | Create or update a memory node in the linking graph. Nodes represent concepts, files, symbols, or notes with auto-generated embeddings. |
Trust audit
CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
| \`prune_stale_links\` | Remove decayed edges (e^(-λt)) and orphan nodes periodically. |
| \`prune_stale_links\` | Remove decayed edges (e^(-λt)) and orphan nodes periodically. |
"Edges have weights (0-1) that decay over time via e^(-λt). Duplicate edges update weight instead of creating new ones.",
"Remove stale memory graph edges whose weight has decayed below threshold via e^(-λt) formula. " +
prune_stale_links
const GRAMMAR_DIR = join(dirname(fileURLToPath(import.meta.url)), "../../node_modules/tree-sitter-wasms/out");
const { getBlastRadius } = await import("../../build/tools/blast-radius.js");await import("../../build/core/clustering.js");const { getContextTree } = await import("../../build/tools/context-tree.js");await import("../../build/core/embeddings.js");geist, @opennextjs/cloudflare, @tailwindcss/postcss, @types/node, @types/react, @types/react-dom, eslint, tailwindcss
@modelcontextprotocol/sdk, claude, ignore, ml-matrix, ollama, simple-git, tree-sitter-wasms, web-tree-sitter
Gates applied: no_behavioural_pass.
34be165ae6eefull audit observations/trust-audit/mcp-server/forloopcodes__context-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 34be165ae6ee | CAUTION | B | 88 | source changed, verdict held |
Questions
What is the Context+ MCP server?
Semantic Intelligence for Large-Scale Engineering. Context+ is an MCP server designed for developers who demand 99% accuracy. By combining RAG, Tree-sitter AST, Spectral Clustering, and Obsidian-style linking, Context+ turns a massive codebase into a searchable, hierarchical feature graph.
What tools does Context+ expose?
17 in total: 10 read-only, 6 that write, and 1 that can delete or overwrite (prune_stale_links). Every one is listed on this page with its risk.
Is Context+ safe to connect to an agent?
With care. The audit graded it B (88/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Context+ need?
It reads CONTEXTPLUS_OPENAI_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Context+ run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as contextplus at 1.0.9.
How current is this page?
The grade is for one exact copy of the source (34be165ae6ee), read on 2026-09-23. The repository is watched and re-audited when it changes.