Atlas / MCP servers / intina47 / Context Sync

Context SyncBLOCK

mcp/intina47/context-sync

Local persistent memory store for LLM applications including continue.dev, cursor, claude desktop, github copilot, codex, antigravity, etc.

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
8 5r · 3w · 0d
Transport
stdio
License
MIT
Stars
190
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Local-first project memory for AI coding tools over MCP.

Context Sync gives an agent a persistent memory layer for a codebase:

  • project identity and tech stack
  • active work, decisions, constraints, and caveats
  • structured file exploration
  • git-aware context
  • optional read-only Notion lookup

What It Does

Context Sync is built for session continuity. Instead of relying on a model to remember earlier conversations, it stores the project context that matters and makes it retrievable through a small MCP tool surface.

The current core tools are:

  • set_project
  • remember
  • recall
  • read_file
  • search
  • structure
  • git
  • notion

Install

Install globally:

npm install -g @context-sync/server

Auto-configuration runs during global install. After install, restart your AI tool.

If you install locally instead of globally, auto-config does not run. Use the manual config guide in docs/CONFIG.md.

Verify

Check that context-sync appears in your MCP tool list:

  • Claude Desktop: open the tools list
  • Cursor: open the tools list
  • VS Code / Copilot Chat Agent mode: check tools
  • Continue.dev: open the Continue panel
  • Codex CLI: codex mcp list
  • Claude Code: claude mcp list

If auto-config fails, use docs/TROUBLESHOOTING.md and docs/CONFIG.md.

Optional Notion Setup

Run the setup wizard if you want Notion integration:

context-sync-setup

or:

npx context-sync-setup

Notion support is intentionally read-only at the tool surface:

  • notion({ action: "search", query: "..." })
  • notion({ action: "read", pageId: "..." })

First-Time Workflow

Start every new session by setting the project first:

1. set_project({ path: "/absolute/path/to/project" })
2. recall()
3. structure({ depth: 2 })
4. read_file({ path: "src/index.ts" })
5. remember({ type: "decision", content: "Use SQLite for local s
Read from source at commit 7e3acaa519a1OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add server -- npx -y @context-sync/[email protected]
claude-desktop
{
  "mcpServers": {
    "server": {
      "command": "npx",
      "args": [
        "-y",
        "@context-sync/[email protected]"
      ]
    }
  }
}
03

Exposed tools (8)

5 read · 3 write · 0 destructive.

ToolRiskDescription
context-sync-usagewriteComplete guide on how to use Context Sync effectively as an AI agent
debugging-context-syncwriteHow to debug Context Sync when things go wrong
notionreadAccess your Notion workspace documentation. Use notion.search to find pages, notion.read to view content. Essential for pulling in external documentation context.
read_filereadRead a file from the current workspace. Use this to understand code context.
recallreadGet context about the current project. Returns project identity, active work, constraints, problems, and recent decisions. Call this at the start of a conversation to understand what the user is working on. Essential for
searchreadSearch the workspace. Can search by filename pattern or file contents. Use this to discover relevant files or find specific code.
set_projectwriteInitialize a project for context tracking. Detects project type, tech stack, and architecture. Call this once when starting work on a new project. This is the foundation - run this first.
structurereadGet the file/folder structure of current workspace. Use this to understand project layout.
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (1 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
bin/auto-configurator.cjs:395
configObj = yaml.load(raw) || {};
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
bin/register-continue.cjs:61
configObj = yaml.load(raw) || {};
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
bin/setup.cjs:222
exec(command);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
bin/platform-configs.cjs:36
'/usr/local/bin/claude',
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
bin/platform-configs.cjs:74
'/usr/local/bin/cursor',
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
bin/platform-configs.cjs:116
'/usr/local/bin/code',
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
bin/platform-configs.cjs:212
'/usr/local/bin/zed',
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
bin/platform-configs.cjs:252
'/usr/local/bin/windsurf'
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/context-layers.ts:1
/**
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/core-tools.ts:1
/**
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/git-context-engine.ts:1
/**
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/git-hook-manager.ts:1
/**
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/git-integration.ts:1
// Git Integration for Version Control Operations
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/path-normalizer.ts:109
const dangerous = ['..\\..\\..', '../../../', '\\\\', '//', '\\0', '\0'];
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@iarna/toml, @modelcontextprotocol/sdk, @notionhq/client, better-sqlite3, chokidar, commander, js-yaml, readline-sync
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/NOTION_INTEGRATION.md:36
You’re all set! Context Sync will connect directly to Notion using your API token. No extra server or config needed.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
RUST-MIGRATION-ASSESSMENT.md:491
curl -sSL https://install.context-sync.dev | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 7e3acaa519a1full audit observations/trust-audit/mcp-server/intina47__context-sync.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-067e3acaa519a1BLOCKF54first audit
06

Questions

What is the Context Sync MCP server?

Local persistent memory store for LLM applications including continue.dev, cursor, claude desktop, github copilot, codex, antigravity, etc.

What tools does Context Sync expose?

8 in total: 5 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Context Sync safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Context Sync need?

No credential environment variables were found in its source, so it appears to need none.

How does Context Sync run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @context-sync/server at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (7e3acaa519a1), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement