Atlas / MCP servers / neuledge / Context

ContextBLOCK

mcp/neuledge/context-5

Local-first documentation for AI agents

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
417
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Every file here is one package definition — a small YAML file describing where a library's documentation lives and how to build it. A daily job reads these, builds a searchable .db package from each, and publishes it so context install can fetch it.

Adding a library means adding one YAML file. No code.

Where the file goes

The directory name is the registry the package is distributed by, and the filename is the package name within it:

registry/npm/react.yaml          → npm/react
registry/pip/fastapi.yaml        → pip/fastapi
registry/npm/@trpc/server.yaml   → npm/@trpc/server     (scoped: use a subdirectory)

Go modules use the full module path, so every slash becomes a subdirectory:

registry/go/github.com/spf13/cobra.yaml   → go/github.com/spf13/cobra

Maven coordinates use _ in place of :, since : isn't filesystem-safe:

registry/maven/org.springframework.boot_spring-boot.yaml

If the project isn't distributed by a package manager at all — a language runtime, a daemon, a CLI tool — give it a directory named after the project containing a single self-named file. That's how the language runtimes are already done:

registry/python/python.yaml
registry/java/java.yaml

So Docker, Kubernetes, Podman and systemd would be registry/docker/docker.yaml, registry/kubernetes/kubernetes.yaml, and so on.

The name: field inside the file must match the path, or loading fails.

Which shape to use

A definition is either unversioned (one source:, always built from the current tip and published as latest) or versioned (a versions: list). Not both.

Unversioned — simplest, start here

name: drizzle-orm
description: "TypeScript ORM"
repository: https://github.com/drizzle-team/drizzle-orm

source:
type: git
url: https://github.com/drizzle-team/drizzle-orm-docs
docs_path: src/content/docs

Add ref: if the docs aren't on the default branch.

#

Read from source at commit d52e22e61212OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add context -- npx -y @neuledge/[email protected]
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
download_packageread
get_docsread
search_packagesread
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (4 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (22)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
registry/npm/payload.yaml
payload.yaml
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/context/src/database.ts:21
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/context/src/database.ts:123
exec(sql: string): void {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/context/src/sql.js.d.ts:11
exec(sql: string): QueryExecResult[];
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.clinerules
.clinerules
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.cursorrules
.cursorrules
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
README.md
README.md
Why it matters. link not followed
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/context/src/git.ts:30
return createHash("md5").update(content).digest("hex").slice(0, 16);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/context/src/package-builder.ts:16
return createHash("md5").update(content).digest("hex").slice(0, 16);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/registry/src/cli.ts:27
"../../..",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/registry/src/html-index-build.test.ts:142
const root = resolve(import.meta.dirname, "../../..", "registry/systemd");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/registry/src/html-index.test.ts:267
"258/../../latest",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/registry/src/test-registry.ts:31
"../../..",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/context/src/server.test.ts:49
new URL(`http://127.0.0.1:${port}/mcp`),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/context/src/server.test.ts:100
new URL(`http://127.0.0.1:${port}/mcp`),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/context/src/server.test.ts:337
new URL(`http://127.0.0.1:${port}/mcp`),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/context/src/server.test.ts:355
new URL(`http://127.0.0.1:${port}/mcp`),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/context/src/server.test.ts:358
new URL(`http://127.0.0.1:${port}/mcp`),
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@changesets/changelog-github, @changesets/cli, turbo
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/context/package.json
@inquirer/prompts, @modelcontextprotocol/sdk, commander, defuddle, ignore, linkedom, remark-frontmatter, remark-parse
Why it matters. 25 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/registry/package.json
commander, linkedom, p-retry, yaml, zod, @total-typescript/tsconfig, @types/node, rimraf
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha d52e22e61212full audit observations/trust-audit/mcp-server/neuledge__context-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02d52e22e61212BLOCKF54first audit
06

Questions

What is the Context MCP server?

Local-first documentation for AI agents

What tools does Context expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Context safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Context need?

It reads REGISTRY_PUBLISH_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Context run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @neuledge/registry at 0.0.23.

How current is this page?

The grade is for one exact copy of the source (d52e22e61212), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement