5 min read

Context7: Up-to-Date Library Docs for AI Coding Agents (GitHub, Scanned)

An MCP server and CLI that feeds coding agents current, version-specific docs so they stop inventing APIs.

Context7 logo
✅
Scan: safe. Nothing malicious. Two things to know: the ctx7 CLI sends anonymous usage events to context7.com unless you set CTX7_TELEMETRY_DISABLED, and every documentation lookup goes to Upstash's hosted service, whose backend is not in this repository. Scanned Oct 2, 2026; the full report is below.

Context7 attacks one of the most common failures of AI coding tools: answers based on a library as it looked in the model's training data. When your agent needs to use Next.js, Supabase or a Cloudflare Worker API, Context7 looks up the library in its index and returns current documentation and code examples for the version you name, which the agent reads before it writes code. It works either as an MCP server with two tools (resolve-library-id and query-docs) or as a ctx7 command-line tool driven by a skill, and one setup command configures Claude Code, Cursor or OpenCode.

It is made by Upstash, the serverless database company, and has about 63,000 stars and a long run of TikTok and YouTube videos recommending it as an essential MCP server. The repository is MIT-licensed, but it contains the client side only: the MCP server, CLI and SDKs. The documentation index, parser and crawler behind mcp.context7.com are private, and library entries are community-submitted.

  • Repository: github.com/upstash/context7
  • Licence: MIT (MIT License)
  • Language: TypeScript. Stars: 62.6K. Forks: 3,044. Last push: Oct 2, 2026.
  • Scan: safe, Oct 2, 2026, commit bfa02ea

Who it is for

Developers who use Claude Code, Cursor, Codex or similar agents with fast-moving frameworks and are tired of fixing code written against last year's API.

Getting started

1. Set up Context7 for your agent (Node.js 18+); signs in with OAuth and creates an API key

npx ctx7 setup

2. Target a specific agent if you use more than one

npx ctx7 setup --claude

3. Then ask for docs in a prompt

How do I set up Next.js 14 middleware? use context7

Your queries go to Upstash's hosted service at mcp.context7.com; nothing about the lookup runs locally. The ctx7 CLI also sends anonymous setup and install events unless you set CTX7_TELEMETRY_DISABLED=1. To undo the setup, run npx ctx7 remove. Manual MCP configuration for 30-plus clients is documented at context7.com.

Safety scan

We cloned upstash/context7 at commit bfa02ea on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • One secret candidate in 502 files and about 51,000 lines: a Kubernetes example in docs/enterprise/integrations/other-git.mdx whose private key body is literally "...". No pattern hits, no committed binaries, no bare-IP URLs and no install hooks.
  • We read the network code. packages/cli/src/utils/tracking.ts posts setup, install and upgrade events (which agents you configured, the auth mode) to context7.com/api/v2/cli/events, skipped when CTX7_TELEMETRY_DISABLED is set or you point the CLI at another server. The MCP server's OpenTelemetry Prometheus exporter only loads when explicitly enabled for HTTP deployments and exposes metrics locally rather than sending them anywhere.
  • pnpm-lock.yaml pins 839 packages with 144 known advisories, none critical and 61 high. Most are denial-of-service issues in build and lint tooling (brace-expansion, minimatch, js-yaml); the runtime-adjacent ones are fast-uri and hono in the server stack and figlet in the CLI's banner.
  • Six workflows, none using pull_request_target; none of the 10 third-party actions is pinned to a commit. Security policy, Dependabot and licence present; no CodeQL or contributing guide.

What the scanner counted

CheckResult
Secrets1 candidate found and read; see the notes above.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows6 workflows. None use pull_request_target. 10 of 10 third-party actions pinned to a tag rather than a commit.
Network hosts27 distinct hosts referenced from source; most often mcp.context7.com, context7.internal.example, other.com, context7.com. No URLs to bare IP addresses.
Known vulnerabilities144 advisories across 839 pinned packages: 0 critical, 61 high, 68 moderate, 15 low. pnpm-lock.yaml: 839 packages, 144 advisories.
Project hygieneHas security policy, automated dependency updates, licence file. Missing CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (1, redacted)
WhereRuleMatch
docs/enterprise/integrations/other-git.mdx:71private-key-----B…--- (35 chars)
Worst known vulnerabilities (24 of 144)
AdvisorySeverityPackageSummary
GHSA-jfgx-wxx8-mp94high@earendil-works/pi-coding-agent@0.78.0Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
GHSA-3jxr-9vmj-r5cphighbrace-expansion@1.1.15brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
GHSA-6j4f-fj2g-mc7phighbrace-expansion@1.1.15brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-mh99-v99m-4gvghighbrace-expansion@1.1.15brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-qhr7-859c-m2p7highbrace-expansion@1.1.15brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-rgw5-rvv9-x895highbrace-expansion@1.1.15brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-3jxr-9vmj-r5cphighbrace-expansion@2.0.2brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
GHSA-6j4f-fj2g-mc7phighbrace-expansion@2.0.2brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-mh99-v99m-4gvghighbrace-expansion@2.0.2brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-qhr7-859c-m2p7highbrace-expansion@2.0.2brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-rgw5-rvv9-x895highbrace-expansion@2.0.2brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-3jxr-9vmj-r5cphighbrace-expansion@5.0.6brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
GHSA-6j4f-fj2g-mc7phighbrace-expansion@5.0.6brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-mh99-v99m-4gvghighbrace-expansion@5.0.6brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-qhr7-859c-m2p7highbrace-expansion@5.0.6brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-rgw5-rvv9-x895highbrace-expansion@5.0.6brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-4c8g-83qw-93j6highfast-uri@3.1.0fast-uri vulnerable to host confusion via failed IDN canonicalization
GHSA-7p8r-x3mc-p8w7highfast-uri@3.1.0fast-uri vulnerable to host confusion via backslash authority introducer
GHSA-f65p-4m7j-42xchighfast-uri@3.1.0fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
GHSA-jqff-g426-hqxphighfast-uri@3.1.0fast-uri vulnerable to host confusion via percent-encoded scheme normalization
GHSA-q3j6-qgpj-74h6highfast-uri@3.1.0fast-uri vulnerable to path traversal via percent-encoded dot segments
GHSA-qw65-cvwx-89v3highfast-uri@3.1.0fast-uri vulnerable to authority injection via an unvalidated port in serialize
GHSA-v2hh-gcrm-f6hxhighfast-uri@3.1.0fast-uri vulnerable to host confusion via literal backslash authority delimiter

By the numbers

Stars62.6K
Forks3,044
Contributors132
Commits1,000
Open issues34
Open pull requests58
Releases128
Latest release@upstash/context7-opencode@0.2.0
LicenceMIT
Main languageTypeScript
Project age1 year
Last pushOct 2, 2026
Tracked files502
Lines of code50.9K
Checkout size25 MB

Lines by language: Markdown 25.8K, TypeScript 21.6K, JSON 2,441, YAML 709, JavaScript 384.

Questions

Is Context7 free?

The client is MIT-licensed, and the hosted service has a free plan of 1,000 API calls a month for public libraries, with 20 bonus calls a day once you hit the limit. Pro is $10 per seat a month with 2,000 calls per seat and private repositories, extra calls at $5 per 1,000, and Enterprise adds SSO and self-hosting.

Does Context7 see my code?

It sees the queries your agent sends: the library name and the question it is trying to answer, which can describe what you are building. It does not read your files. If that matters, review what your agent passes in the query, or use the Enterprise self-hosted option.

Can I trust the docs Context7 returns?

Mostly, with care. Libraries are indexed from their own repositories and sites, but entries are community-contributed and Upstash says it cannot guarantee their accuracy or security. Prefer library IDs from the official project (for example /vercel/next.js) and report anything suspicious.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.