Atlas / MCP servers / portofcontext / PCTX

PCTXCAUTION

mcp/portofcontext/pctx

pctx is the execution layer for agentic tool calls. It auto-converts agent tools and MCP servers into code that runs in secure sandboxes for token-efficient workflows.

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
13 12r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
279
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

pctx

[](https://portofcontext.com)

[](https://www.npmjs.com/package/@portofcontext/pctx) [](https://www.rust-lang.org) [](https://pctx.readthedocs.io/en/latest/)

The open source framework to connect AI agents to tools and mcp with Code Mode

— T R U S T E D B Y —

Install

# Homebrew
brew install portofcontext/tap/pctx

# cURL
curl --proto '=https' --tlsv1.2 -LsSf https://raw.githubusercontent.com/portofcontext/pctx/main/install.sh | sh

# npm
npm i -g @portofcontext/pctx

Core Functionality

pctx can be run as a stateless HTTP server for Code Mode sessions or as a unified MCP server that exposes Code Mode functionality for registered upstream MCP servers.

# Start Code Mode for Python SDK
pctx start

# Start Code Mode as a unified MCP server
pctx mcp init
pctx mcp dev

Python SDK

Use the Python SDK if building agents in Python and want to run Code Mode with custom tools and/or MCP servers. The Python

Read from source at commit ce11c1ff05fbOBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add nasa-mcp-example --env NASA_API_KEY=${NASA_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "nasa-mcp-example": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "NASA_API_KEY": "${NASA_API_KEY}",
        "OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
      }
    }
  }
}
03

Exposed tools (13)

12 read · 1 write · 0 destructive.

ToolRiskDescription
addwriteAdd two numbers together
browse_asteroidsread
concatreadConcatenate two strings with a separator
dividereadDivide x by y
echoreadEcho back a message with metadata
greetreadGenerate a greeting message
lookup_asteroidread
lookup_satelliteread
multiplyreadMultiply two numbers together
reverse_stringreadReverse a string and return metadata
search_asteroidsread
search_satellitesread
subtractreadSubtract b from a
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (22)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
pctx-py/src/pctx_client/descriptions/data
pctx-py/src/pctx_client/descriptions/data
Why it matters. link not followed
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/pctx/src/commands/start.rs:60
"http://127.0.0.1".to_string(),
LOWInventory / provenance · inv.hidden_file · CWE-1104
.readthedocs.yaml
.readthedocs.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/nasa-mcp/.railwayignore
.railwayignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/pctx/src/commands/mcp/dev/renderers.rs:470
const CLI_DOCS: &str = include_str!("../../../../../../docs/CLI.md");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/pctx/src/commands/start.rs:21
const LOGO: &str = include_str!("../../../../assets/ascii-logo.txt");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/pctx_mcp_server/src/utils/mod.rs:3
pub(crate) static LOGO: &str = include_str!("../../../../assets/ascii-logo.txt");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/build-python.sh:8
SYMLINK_TARGET="../../../../crates/pctx_code_mode/descriptions"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/pctx_session_server/tests/metadata.rs:73
"http://127.0.0.1".to_string(),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/pctx_session_server/tests/utils.rs:18
"http://127.0.0.1".to_string(),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/pctx_session_server/tests/utils.rs:49
"http://127.0.0.1".to_string(),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CLI.md:65
* `--allowed-origin <ALLOWED_ORIGINS>` — Allowed CORS origins. Can be specified multiple times. Defaults to localhost only (<http://localhost>, <http://127.0.0.1>, http://[`::1`]). Specify your own or
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/nasa-mcp/package.json
@modelcontextprotocol/sdk, dotenv, express, node-fetch, zod
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/config.md:489
The value is read from the environment variable at runtime.
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:33
curl --proto '=https' --tlsv1.2 -LsSf https://raw.githubusercontent.com/portofcontext/pctx/main/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
RELEASING.md:79
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/portofcontext/pctx/releases/latest/download/pctx-installer.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
pctx-py/README.md:36
curl --proto '=https' --tlsv1.2 -LsSf https://raw.githubusercontent.com/portofcontext/pctx/main/install.sh | sh
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/upstream-mcp-servers.md:119
When running as a stdio MCP server (e.g. configured in Claude Desktop's `mcpServers`), the entire process lifetime is treated as a single session. A global session ID is assigned at startup, and all `
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
crates/pctx_code_execution_runtime/src/just-bash/bundle.js
crates/pctx_code_execution_runtime/src/just-bash/bundle.js
Why it matters. 1088825 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
crates/pctx_type_check_runtime/src/typescript.min.js
crates/pctx_type_check_runtime/src/typescript.min.js
Why it matters. 9020174 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
crates/pctx_type_check_runtime/ts-libs.json
crates/pctx_type_check_runtime/ts-libs.json
Why it matters. 2377890 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
pctx-py/uv.lock
pctx-py/uv.lock
Why it matters. 1188958 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha ce11c1ff05fbfull audit observations/trust-audit/mcp-server/portofcontext__pctx.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-05ce11c1ff05fbCAUTIONB88first audit
06

Questions

What is the PCTX MCP server?

pctx is the execution layer for agentic tool calls. It auto-converts agent tools and MCP servers into code that runs in secure sandboxes for token-efficient workflows.

What tools does PCTX expose?

13 in total: 12 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is PCTX safe to connect to an agent?

With care. The audit graded it B (88/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does PCTX need?

It reads NASA_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does PCTX run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as nasa-mcp-example at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (ce11c1ff05fb), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement