Mmcp.market

Is Contextual MCP server safe?

Yes, with the usual care.

B75/100grade B

Safe to use. Minor gaps such as a missing repository or slower maintenance.

No critical or high findings in the latest scan.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

2 medium
  • Code scan232 source files scanned15/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 8 days ago15/15
  • Maintainer identityregistry namespace matches repository owner7/10

Findings (2)

  • mediumsubprocess with shell=Trueexec.shell-true
    contextual_engine-1.0.2/contextual/mcp/tools/semantic.py: …r shell safety (passed as list arg, not shell=True) if target == "WORKING"…
  • mediumeval / new Function usedexec.eval
    contextual_engine-1.0.2/eval/manifest.yml: …too small for realistic retrieval eval (this was flagged as a possible risk in b…
Overall 75/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Contextual does

  • Nexusmem
    Local-first memory for AI coding agents: shell history with exit codes, git diffs, docs, MCP.
    A
  • Agent Memory
    Git-native project memory for AI coding agents: Markdown source of truth, reviewable, secret-safe.
    A
  • Kindex
    Persistent knowledge graph and MCP server for AI workflows with git-tracked project context.
    A

Contextual reviews, tools and install