PCTXCAUTION
pctx is the execution layer for agentic tool calls. It auto-converts agent tools and MCP servers into code that runs in secure sandboxes for token-efficient workflows.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
pctx
[](https://portofcontext.com)
[](https://www.npmjs.com/package/@portofcontext/pctx) [](https://www.rust-lang.org) [](https://pctx.readthedocs.io/en/latest/)
The open source framework to connect AI agents to tools and mcp with Code Mode
— T R U S T E D B Y —
Install
# Homebrew brew install portofcontext/tap/pctx # cURL curl --proto '=https' --tlsv1.2 -LsSf https://raw.githubusercontent.com/portofcontext/pctx/main/install.sh | sh # npm npm i -g @portofcontext/pctx
Core Functionality
pctx can be run as a stateless HTTP server for Code Mode sessions or as a unified MCP server that exposes Code Mode functionality for registered upstream MCP servers.
# Start Code Mode for Python SDK pctx start # Start Code Mode as a unified MCP server pctx mcp init pctx mcp dev
Python SDK
Use the Python SDK if building agents in Python and want to run Code Mode with custom tools and/or MCP servers. The Python
ce11c1ff05fbOBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add nasa-mcp-example --env NASA_API_KEY=${NASA_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"nasa-mcp-example": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"NASA_API_KEY": "${NASA_API_KEY}",
"OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
}
}
}
}Exposed tools (13)
12 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | Add two numbers together |
browse_asteroids | read | |
concat | read | Concatenate two strings with a separator |
divide | read | Divide x by y |
echo | read | Echo back a message with metadata |
greet | read | Generate a greeting message |
lookup_asteroid | read | |
lookup_satellite | read | |
multiply | read | Multiply two numbers together |
reverse_string | read | Reverse a string and return metadata |
search_asteroids | read | |
search_satellites | read | |
subtract | read | Subtract b from a |
Trust audit
CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (22)
pctx-py/src/pctx_client/descriptions/data
"http://127.0.0.1".to_string(),
.readthedocs.yaml
.railwayignore
const CLI_DOCS: &str = include_str!("../../../../../../docs/CLI.md");const LOGO: &str = include_str!("../../../../assets/ascii-logo.txt");pub(crate) static LOGO: &str = include_str!("../../../../assets/ascii-logo.txt");SYMLINK_TARGET="../../../../crates/pctx_code_mode/descriptions"
"http://127.0.0.1".to_string(),
"http://127.0.0.1".to_string(),
"http://127.0.0.1".to_string(),
* `--allowed-origin <ALLOWED_ORIGINS>` — Allowed CORS origins. Can be specified multiple times. Defaults to localhost only (<http://localhost>, <http://127.0.0.1>, http://[`::1`]). Specify your own or
@modelcontextprotocol/sdk, dotenv, express, node-fetch, zod
The value is read from the environment variable at runtime.
curl --proto '=https' --tlsv1.2 -LsSf https://raw.githubusercontent.com/portofcontext/pctx/main/install.sh | sh
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/portofcontext/pctx/releases/latest/download/pctx-installer.sh | sh
curl --proto '=https' --tlsv1.2 -LsSf https://raw.githubusercontent.com/portofcontext/pctx/main/install.sh | sh
When running as a stdio MCP server (e.g. configured in Claude Desktop's `mcpServers`), the entire process lifetime is treated as a single session. A global session ID is assigned at startup, and all `
crates/pctx_code_execution_runtime/src/just-bash/bundle.js
crates/pctx_type_check_runtime/src/typescript.min.js
crates/pctx_type_check_runtime/ts-libs.json
pctx-py/uv.lock
Gates applied: no_behavioural_pass.
ce11c1ff05fbfull audit observations/trust-audit/mcp-server/portofcontext__pctx.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | ce11c1ff05fb | CAUTION | B | 88 | first audit |
Questions
What is the PCTX MCP server?
pctx is the execution layer for agentic tool calls. It auto-converts agent tools and MCP servers into code that runs in secure sandboxes for token-efficient workflows.
What tools does PCTX expose?
13 in total: 12 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is PCTX safe to connect to an agent?
With care. The audit graded it B (88/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does PCTX need?
It reads NASA_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does PCTX run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as nasa-mcp-example at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (ce11c1ff05fb), read on 2026-10-05. The repository is watched and re-audited when it changes.