Atlas / MCP servers / lennix1337 / GeneXus 18

GeneXus 18BLOCK

mcp/lennix1337/genexus-18

GeneXus MCP server with native SDK support for GeneXus 16–18 plus basic legacy compatibility for GeneXus 8, 9, 10.1–10.3, and 15 via reflection/COM drivers.

Verdict
BLOCK
Grade
F
Trust score
33 /100
Exposed tools
76 71r · 2w · 3d
Transport
stdio · streamable-http
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/genexus-mcp) [](https://www.npmjs.com/package/genexus-mcp) [](https://opensource.org/licenses/MIT) [](https://safeskill.dev/scan/lennix1337-genexus18mcp) [](https://lobehub.com/mcp/lennix1337-genexus18mcp)

¿Hablás español? → Guía de inicio en español Fala português? → Guia de início em português Stuck? → Troubleshooting guide

GeneXus MCP Server lets AI agents — Claude Desktop, Claude Code, Cursor, Antigravity, and any MCP-compatible client — read, edit, analyze, and refactor objects inside a Knowledge Base supported by the selected native SDK or legacy compatibility driver. Native SDK paths work with the real GeneXus SDK and legacy paths use explicit reflection/COM adapters; neither path relies on a parsed copy of the KB.

In practice: you point the MCP at your KB, then ask your AI assistant things like "list all transactions with attribute CustomerId", "add a rule to the Order transaction that validates the total", or "refactor this procedure to use the new SDT" — and it does it.

Multi-version GeneXus support

The same MCP distribution supports the official native SDK majors listed in the generated compatibility document. It also includes basic, best-effort compatibility for the legacy versions listed there through separate drivers; that path is not equivalent to full native-SDK support. A process can route each declared KB to its own SDK/driver; --gx remains the convenient

Read from source at commit f14e66e3ca4bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add genexus-mcp -- npx -y [email protected]
03

Exposed tools (76)

71 read · 2 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AddwriteAdds an item to the collection.
AddDaysreadAdds days.
AddSecondsreadAdds seconds.
AudioreadAudio asset reference.
BlobreadBinary Large Object.
BlobFilereadReference to a file stored in a folder.
BooleanreadLogical value (True/False).
CharAtreadReturns the character at the specified index.
CharacterreadFixed-length character string.
CleardestructiveRemoves all items from the collection.
ContainsreadChecks if the string contains a substring.
CountreadReturns the number of items in the collection.
DAddreadAdds a number of days to a Date or DateTime value.
DDiffreadReturns the difference in days between two Date or DateTime values.
DatereadDate value.
DateTimereadDate and time value.
DayreadReturns the day.
DefaultreadAssigns a default value to an attribute or variable.
EndsWithreadChecks if the string ends with a substring.
ErrorreadDisplays an error message and stops execution if a condition is met.
FromJsonreadLoads the collection from a JSON string.
FromStringreadParses a string into a numeric value.
GUIDreadGlobally Unique Identifier.
HTMLCleanreadCleans HTML content.
HiddenreadHides an attribute in the form.
HourreadReturns the hour.
IfreadConditional execution block.
IifreadReturns one of two values depending on the result of a logical expression.
ImagereadImage asset reference.
IndexOfreadFinds substring position.
IsEmptyreadChecks if a value is empty (null or zero/blank).
IsMatchreadChecks if the string matches a regular expression.
IsNullreadChecks if a value is null.
ItemreadReturns an item from the collection by index.
LastIndexOfreadReturns the last index of a substring.
LenreadReturns the length of a string.
LengthreadReturns string length.
LongVarCharreadLarge variable-length character string.
LowerreadConverts a string to lowercase.
MinutereadReturns the minute.
MonthreadReturns the month.
MsgreadDisplays a message to the user.
NewreadCreates a new record in a table.
NoAcceptreadPrevents editing of an attribute or variable.
NowreadReturns the current date and time of the local machine.
NullValuereadReturns the null value of a given expression or attribute.
NumericreadNumeric value with optional decimals.
OrderwriteSpecifies the order of records in a Transaction or Data Provider.
ParmreadDefines the parameters of the object.
PromptreadCalls a prompt object for an attribute or variable.
RefreadDefines a referential integrity rule.
RemovedestructiveRemoves an item from the collection by index.
ReplacereadReplaces all occurrences of a string within another string.
RoundreadRounds the value.
ServerNowreadReturns the current date and time of the application server.
SetEmptyreadSets to empty value.
StartsWithreadChecks if the string starts with a substring.
StrreadConverts a numeric value to a string.
SubreadDefines a subroutine.
SubstrreadReturns a substring from a string.
TAddreadAdds a number of seconds to a DateTime value.
TDiffreadReturns the difference in seconds between two DateTime values.
ToFormattedStringreadConverts to formatted string.
ToJsonreadReturns a JSON representation of the collection.
ToLowerreadConverts to lowercase.
ToStringreadConverts to string.
ToUpperreadConverts to uppercase.
TodayreadReturns the current date.
TrimreadRemoves leading and trailing spaces.
TruncatedestructiveTruncates decimals.
UpperreadConverts a string to uppercase.
ValreadConverts a string to a numeric value.
VarCharreadVariable-length character string.
VideoreadVideo asset reference.
YMDtoDreadReturns a Date value from Year, Month, and Day.
YearreadReturns the year.
04

Trust audit

BLOCKgrade F · trust 33/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (3 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/GxMcp.Worker.Tests/SecurityAuditServiceTests.cs:43
var hits = SecurityAuditService.ScanText("-----BEGIN RSA PRIVATE KEY-----\nMIIEvAIBADANBgkq\n-----END RSA PRIVATE KEY-----");
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/GxMcp.Worker/Services/SecurityAuditService.cs:195
if (text.Contains("-----BEGIN RSA PRIVATE KEY-----") || text.Contains("-----BEGIN PRIVATE KEY-----"))
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cli/lib/config.js:1049
if (/^(?:-e|-p|--eval(?:=|$)|--print(?:=|$)|--check(?:=|$))/.test(arg)) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.gemini/skills/nexa/SKILL.md:147
* Read `*.env.gx` to get environment name and generator
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.rtl_override · CWE-94, CWE-1427
docs/sdk-probe/INDEX.md:15245
- `+` — 0 methods, 0 props
Why it matters. bidirectional override can render text differently from how it is read
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/sdk-probe/INDEX.md:15245
- `+` — 0 methods, 0 props
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
cli/commands/axi.js:408
const fallback = 'http://127.0.0.1:5000/mcp';
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
release.ps1:1
# GeneXus MCP - one-shot release script
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/check-build-warning-baseline.ps1:1
[CmdletBinding()]
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/install.ps1:1
# GeneXus MCP - Corporate Installer (fixed-path)
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/release-contract.ps1:1
function Test-GxMcpReleaseHasField {
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/release-doctor.ps1:1
[CmdletBinding()]
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
.gemini/skills/frontend/chameleon-controls-library/references/components/ch-live-kit-room/usage.md:33
room.token = "eyJhbGciOiJIUzI1NiIs..."; // JWT access token
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
.gemini/skills/frontend/chameleon-controls-library/references/components/ch-live-kit-room/usage.md:94
room.token = "eyJhbGciOiJIUzI1NiIs...";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/tests/test-collect-diagnostics.ps1:17
'[COLD-START] token=abc123def456 ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ012345',
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/tests/test-collect-diagnostics.ps1:34
'ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ012345',                # gh_ literal prefix
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/tests/test-integration-preflight.ps1:71
'ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ012345',
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/tests/test-release-preflight.ps1:479
'/c', 'echo token=abc123 & echo ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ012345 & echo user id=sa& echo MOCK-SECRET-TAIL', '1>&2'
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/tests/test-release-preflight.ps1:483
foreach ($secret in @('abc123', 'ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ012345', 'user id=sa')) {
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
.gemini/skills/frontend/chameleon-controls-library/references/components/ch-accordion-render/usage.md:107
<span style="background: orange; color: white; border-radius: 9999px; padding: 2px 8px; font-size: 11px;">3</span>
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
.gemini/skills/frontend/chameleon-controls-library/references/components/ch-barcode-scanner/usage.md:69
style="display: none;"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
Clear, Remove, Truncate
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/lib/update-check.js:20
const pkg = require('../../package.json');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/package.ps1:38
vsce package --out ../../release/nexus-ide.vsix
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/nexus-ide/src/test/runTest.ts:10
const extensionDevelopmentPath = path.resolve(__dirname, '../../');

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f14e66e3ca4bfull audit observations/trust-audit/mcp-server/lennix1337__genexus-18.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f14e66e3ca4bBLOCKF33first audit
06

Questions

What is the GeneXus 18 MCP server?

GeneXus MCP server with native SDK support for GeneXus 16–18 plus basic legacy compatibility for GeneXus 8, 9, 10.1–10.3, and 15 via reflection/COM drivers.

What tools does GeneXus 18 expose?

76 in total: 71 read-only, 2 that write, and 3 that can delete or overwrite (Clear, Remove, Truncate). Every one is listed on this page with its risk.

Is GeneXus 18 safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (33/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GeneXus 18 need?

No credential environment variables were found in its source, so it appears to need none.

How does GeneXus 18 run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as nexus-ide at 3.12.0.

How current is this page?

The grade is for one exact copy of the source (f14e66e3ca4b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement