cortex — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cortex (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<p align="center"> <img src="docs/logo.png" alt="Cortex" width="600" /> </p>
The context layer for AI-assisted software engineering.
Cortex is a local, repository-scoped context engine for coding assistants. It parses your source code with tree-sitter, indexes it into a structured knowledge graph of entities (files, symbols, rules, ADRs) and their relationships (calls, defines, constrains, implements, supersedes), and exposes that context through CLI commands. MCP remains available as a compatibility and integration bridge for clients that support it.
Where a general-purpose AI assistant sees your codebase as a pile of text files, Cortex gives it a precise map: what exists, how it is connected, which rules govern it, and which parts are source-of-truth versus deprecated.
Cortex runs entirely on the developer's machine. Source code never leaves the host.
Cortex is designed for engineering teams that rely on AI assistants for non-trivial work on real codebases. Use it when:
Cortex is not a replacement for your editor, your version control, or your coding assistant. It is the grounding layer that makes those assistants act with knowledge of your specific repository.
cortex init --bootstrap) scaffolds everything needed for local indexing, git hooks, CLI retrieval, and optional MCP compatibility.Cortex operates as a five-stage pipeline between your repository and your AI assistant.
CALLS, DEFINES, CONSTRAINS, IMPLEMENTS, IMPORTS, SUPERSEDES).cortex ... --json, with MCP exposing equivalent tool responses when enabled.Git hooks keep the index fresh on every checkout, pull, commit, and rewrite. A live TUI dashboard (cortex dashboard) shows what Cortex adds to the repository in real time.
Modern coding assistants are bottlenecked by context, not by model capability. Feeding a model more files rarely helps; feeding it the right files almost always does.
Cortex is built on one principle: prefer retrieval quality over analysis completeness. A smaller, sharper context package outperforms a broad dump of files. Every component — from tree-sitter parsing to graph traversal to rule filtering — exists to raise the signal-to-noise ratio of what the assistant sees.
The result is an assistant that behaves as if it already knows your codebase, because — through Cortex — it does.

claude and/or codex CLI in PATHnpm i -g @danielblomma/cortex-mcpTo upgrade an already-scaffolded project to a new Cortex version:
npm i -g @danielblomma/cortex-mcp
cortex init --force # re-scaffolds .context runtime + .context/scripts
cortex bootstrap
cortex updatecortex init --force preserves per-project files: .context/config.yaml, .context/rules.yaml, and your notes/decisions.
Version-specific notes (see CHANGELOG.md for details):
cortex update after upgrading triggers a full re-embed automatically (~2 min per 1000 entities plus a one-time model download). The CORTEX_EMBED_MAX_CHARS env var is removed and silently ignored. Existing projects keep their old ranking weights in config.yaml; the recommended block is now semantic: 0.55, graph: 0.10, trust: 0.20, recency: 0.15. If you use MCP, restart the MCP server after re-embedding. The first search after a re-embed can hit a stale embeddings cache — re-run the query.
From the repository you want to index:
cortex init --bootstrapThis will:
.context/, .context/scripts/, the local context runtime (.context/mcp compatibility path), .githooks/, and docs filescortex connect or cortex init --connectDisable watcher setup:
cortex init --bootstrap --no-watchCheck context status:
cortex statusUse the CLI as the default local agent interface:
cortex search "authentication flow" --json
cortex related file:src/auth.ts --json
cortex impact "payment service" --json
cortex rules --json
cortex explain "where retries are configured" --jsonThese commands read the same local graph, embeddings, and rules used by the MCP server, but they do not require an MCP client registration.
MCP remains supported for clients that need it. Register MCP clients explicitly:
cortex connectThen verify the client registration:
Claude:
claude mcp listCodex:
codex mcp listInstall via Claude Code plugin marketplace:
/plugin marketplace add DanielBlomma/cortex
/plugin install cortex@cortex-marketplace
/plugin enable cortexThen initialize Cortex in your target repository. If you want the plugin to call the local MCP server, also run cortex connect from that repository:
cortex init --bootstrap
cortex connectIf client registration is unavailable, configure MCP manually.
Claude Desktop (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"cortex": {
"command": "cortex",
"args": ["mcp"],
"env": {
"CORTEX_PROJECT_ROOT": "/absolute/path/to/your-project"
}
}
}
}Codex (~/.config/codex/mcp-config.json):
{
"mcpServers": {
"cortex-myproject": {
"command": "cortex",
"args": ["mcp"],
"cwd": "/absolute/path/to/your-project"
}
}
}If you run Node.js inside WSL but use Claude Desktop or another MCP client on Windows:
# In a WSL terminal
npm i -g @danielblomma/cortex-mcp
cd /mnt/c/Users/yourname/your-project
cortex init --bootstrap%APPDATA%\Claude\claude_desktop_config.json):{
"mcpServers": {
"cortex": {
"command": "wsl.exe",
"args": ["--distribution", "Ubuntu", "--exec", "cortex", "mcp"],
"env": {
"CORTEX_PROJECT_ROOT": "C:\\Users\\yourname\\your-project",
"CORTEX_AUTO_BOOTSTRAP_ON_MCP": "1"
}
}
}
}Cortex automatically converts Windows paths (e.g. C:\Users\...) to WSL paths (/mnt/c/Users/...).
For projects on the WSL filesystem (e.g. ~/projects/myapp), use the WSL path directly:
{
"mcpServers": {
"cortex": {
"command": "wsl.exe",
"args": ["--distribution", "Ubuntu", "--exec", "cortex", "mcp"],
"env": {
"CORTEX_PROJECT_ROOT": "/home/yourname/projects/myapp",
"CORTEX_AUTO_BOOTSTRAP_ON_MCP": "1"
}
}
}
}Notes:
/mnt/ paths (Windows filesystem) automatically uses poll mode since inotify is unreliable across filesystem boundaries.~/...) rather than /mnt/c/....context.searchRanked context search across indexed entities.
Input:
query (string, required)top_k (int, 1-20, default 5)include_deprecated (bool, default false)include_content (bool, default false)context.get_relatedFetch entity relationships from the graph.
Input:
entity_id (string, required)depth (int, 1-3, default 1)include_edges (bool, default true)context.impactTraverse likely impact paths across config, code and SQL starting from an entity id or query.
Input:
entity_id (string, optional) — either entity_id or query is requiredquery (string, optional)depth (int, 1-4, default 2)top_k (int, 1-20, default 8)include_edges (bool, default true)profile ("all" | "config_only" | "config_to_sql" | "code_only" | "sql_only", default "all")sort_by ("impact_score" | "shortest_path" | "semantic_score" | "graph_score" | "trust_score", default "impact_score")context.get_rulesList indexed rules and optionally include inactive rules.
Input:
scope (string, optional)include_inactive (bool, default false)context.reloadReload the RyuGraph connection after updates/maintenance.
Input:
force (bool, default true)A live TUI that shows what Cortex adds to your repository at a glance.
cortex dashboard
The dashboard displays:
Options:
--interval <sec> — auto-refresh interval (default: 2 seconds).r to force refresh, q to quit.cortex init [path] [--force] [--bootstrap] [--connect] [--no-connect] [--watch] [--no-watch]
cortex connect [path] [--skip-build]
cortex mcp
cortex bootstrap
cortex update
cortex search <query> [--json]
cortex related <entity-id> [--json]
cortex impact <query|entity-id> [--json]
cortex rules [--json]
cortex explain <query|entity-id> [--json]
cortex status
cortex dashboard [--interval <sec>]
cortex watch [start|stop|status|run|once] [--interval <sec>] [--debounce <sec>] [--mode <auto|event|poll>]
cortex helpThis repository includes two GitHub Actions workflows:
Release Bump (.github/workflows/release-bump.yml)workflow_dispatch from mainpatch/minor/major)package.json, server.json, plugin manifests)vX.Y.ZRelease Publish (.github/workflows/release-publish.yml)v*.*.*@danielblomma/cortex-mcp to npm via npm trusted publishing (GitHub OIDC)Required npm configuration:
@danielblomma/cortex-mcp on npmjs.comDanielBlomma/cortexrelease-publish.ymlEmbedding generation tunes itself to the machine: the number of parallel workers, memory limits for long files, and skip-work caching are all derived from the available CPU cores and RAM at run time (container memory limits included). No configuration is needed — on a laptop or a CI runner, cortex picks safe, fast settings by itself. The one exception worth knowing: when several cortex instances share one machine, set CORTEX_EMBED_THREADS to give each its fair share of cores.
cortex init --bootstrap)..context/.mcp/dist/server.js missing:Run cortex bootstrap (or re-run cortex init --bootstrap).
claude or codex not found during cortex connect:MCP registration is skipped for that client; use manual config above if needed.
Run cortex update, then rerun the CLI query. If you use MCP, reconnect the client or call context.reload.
frontend/ hosts the cortex website (GitHub Pages, deployed on push to main):product overview plus bootstrap evaluation metrics.
benchmark/bootstrapbench/ runs cortex bootstrap against 69 pinnedreal-world repositories in isolated containers and extracts chunk, embedding and graph statistics. See benchmark/bootstrapbench/README.md.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.