Context SyncBLOCK
Local persistent memory store for LLM applications including continue.dev, cursor, claude desktop, github copilot, codex, antigravity, etc.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Local-first project memory for AI coding tools over MCP.
Context Sync gives an agent a persistent memory layer for a codebase:
- project identity and tech stack
- active work, decisions, constraints, and caveats
- structured file exploration
- git-aware context
- optional read-only Notion lookup
What It Does
Context Sync is built for session continuity. Instead of relying on a model to remember earlier conversations, it stores the project context that matters and makes it retrievable through a small MCP tool surface.
The current core tools are:
set_projectrememberrecallread_filesearchstructuregitnotion
Install
Install globally:
npm install -g @context-sync/server
Auto-configuration runs during global install. After install, restart your AI tool.
If you install locally instead of globally, auto-config does not run. Use the manual config guide in docs/CONFIG.md.
Verify
Check that context-sync appears in your MCP tool list:
- Claude Desktop: open the tools list
- Cursor: open the tools list
- VS Code / Copilot Chat Agent mode: check tools
- Continue.dev: open the Continue panel
- Codex CLI:
codex mcp list - Claude Code:
claude mcp list
If auto-config fails, use docs/TROUBLESHOOTING.md and docs/CONFIG.md.
Optional Notion Setup
Run the setup wizard if you want Notion integration:
context-sync-setup
or:
npx context-sync-setup
Notion support is intentionally read-only at the tool surface:
notion({ action: "search", query: "..." })notion({ action: "read", pageId: "..." })
First-Time Workflow
Start every new session by setting the project first:
1. set_project({ path: "/absolute/path/to/project" })
2. recall()
3. structure({ depth: 2 })
4. read_file({ path: "src/index.ts" })
5. remember({ type: "decision", content: "Use SQLite for local s7e3acaa519a1OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add server -- npx -y @context-sync/[email protected]
{
"mcpServers": {
"server": {
"command": "npx",
"args": [
"-y",
"@context-sync/[email protected]"
]
}
}
}Exposed tools (8)
5 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
context-sync-usage | write | Complete guide on how to use Context Sync effectively as an AI agent |
debugging-context-sync | write | How to debug Context Sync when things go wrong |
notion | read | Access your Notion workspace documentation. Use notion.search to find pages, notion.read to view content. Essential for pulling in external documentation context. |
read_file | read | Read a file from the current workspace. Use this to understand code context. |
recall | read | Get context about the current project. Returns project identity, active work, constraints, problems, and recent decisions. Call this at the start of a conversation to understand what the user is working on. Essential for |
search | read | Search the workspace. Can search by filename pattern or file contents. Use this to discover relevant files or find specific code. |
set_project | write | Initialize a project for context tracking. Detects project type, tech stack, and architecture. Call this once when starting work on a new project. This is the foundation - run this first. |
structure | read | Get the file/folder structure of current workspace. Use this to understand project layout. |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
configObj = yaml.load(raw) || {};configObj = yaml.load(raw) || {};exec(command);
'/usr/local/bin/claude',
'/usr/local/bin/cursor',
'/usr/local/bin/code',
'/usr/local/bin/zed',
'/usr/local/bin/windsurf'
/**
/**
/**
/**
// Git Integration for Version Control Operations
const dangerous = ['..\\..\\..', '../../../', '\\\\', '//', '\\0', '\0'];
@iarna/toml, @modelcontextprotocol/sdk, @notionhq/client, better-sqlite3, chokidar, commander, js-yaml, readline-sync
You’re all set! Context Sync will connect directly to Notion using your API token. No extra server or config needed.
curl -sSL https://install.context-sync.dev | sh
Gates applied: no_behavioural_pass.
7e3acaa519a1full audit observations/trust-audit/mcp-server/intina47__context-sync.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 7e3acaa519a1 | BLOCK | F | 54 | first audit |
Questions
What is the Context Sync MCP server?
Local persistent memory store for LLM applications including continue.dev, cursor, claude desktop, github copilot, codex, antigravity, etc.
What tools does Context Sync expose?
8 in total: 5 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Context Sync safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Context Sync need?
No credential environment variables were found in its source, so it appears to need none.
How does Context Sync run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @context-sync/server at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (7e3acaa519a1), read on 2026-10-06. The repository is watched and re-audited when it changes.