{
  "schema_version": "2.0",
  "slug": "gabrielmaialva33-winx-code-agent",
  "name": "Winx",
  "agent_url": "https://crates.io/crates/winx-code-agent",
  "repo_url": "https://github.com/gabrielmaialva33/winx-code-agent",
  "category": "Coding",
  "run_id": "run-95a134b5dec03934-crates-io",
  "run_at": "2026-08-18T00:31:18.037Z",
  "editor": "Hlido Editor",
  "editorial_method": "public-surface-tier-2+editorial-narrative-v2",
  "methodology_version": "2026.05",
  "methodology_url": "/methodology/public-surface-tier-1/",
  "score": 78,
  "tier": "STEADY",
  "laddoo_score": 78,
  "confidence": "low-medium",
  "hlido_opinion": {
    "headline": "A Rust MCP server that gives a coding agent a real PTY-backed shell with unusually careful safety engineering — impressively thorough for a project only days old.",
    "body": "Winx (winx-code-agent, MIT, on crates.io at v0.2.332) is a native-Rust MCP server that hands a coding agent the shell, file IO and PTY-backed interactive sessions. Inspired by WCGW but written from scratch, everything runs on a real PTY: cd sticks, Ctrl+C interrupts, and background shells survive long-running TUIs without leaking output into the token budget. It exposes nine MCP tools (Initialize, BashCommand, ReadFiles, FileWriteOrEdit, MultiFileEdit, UndoEdit, ContextSave, ReadImage, CodeMap) with genuinely thoughtful ergonomics — SEARCH/REPLACE editing that forgives LLM whitespace and smart-quote drift while refusing over-fuzzy matches, all-or-nothing multi-file edits validated in memory, and tree-sitter code navigation across 11 languages. The safety posture is the standout and rare for a young project: three workspace modes (full / read-only architect / allowlisted code_writer), a tree-sitter-parsed command allowlist that inspects every command in a pipeline rather than the first word, secret redaction on by default, and an opt-in Landlock kernel sandbox. Robustness is fuzzed (proptest) and model-checked (loom). The honest caveats it states itself: the default local server has the same blast radius as giving the model your terminal, and the optional HTTP transport puts shell access on the network — mitigated by mandatory tokens and loopback binding. The real limits are maturity and provenance: the release is four days old, single-maintainer, and Hlido reviewed the crates.io page, not a running install.",
    "voice": "Hlido Editor",
    "as_of": "2026-08-19",
    "editor_signature_pending": true
  },
  "tier_rationale": "STEADY (78) for a well-engineered, MIT-licensed Rust MCP shell/coding server with a standout safety design (mode-scoped access, tree-sitter command allowlisting, default secret redaction, opt-in Landlock, fuzz + model-check testing) and honest self-documented threat model — held at low-medium confidence because the crate is only days old and single-maintainer, and Hlido reviewed the package surface, not a live session. Not VITAL on maturity and unverified runtime behaviour.",
  "what_it_does_well": [
    "Real PTY semantics via portable-pty — cd sticks, Ctrl+C interrupts, background shells survive TUIs without leaking into the token budget",
    "Serious, uncommon safety engineering: architect/code_writer modes, a tree-sitter command allowlist that checks every command in a pipeline, default secret redaction, and an opt-in Landlock sandbox",
    "Forgiving-but-safe SEARCH/REPLACE editing (handles LLM whitespace/quote drift, refuses over-fuzzy or ambiguous matches) plus all-or-nothing MultiFileEdit and UndoEdit",
    "Tree-sitter CodeMap navigation across 11 languages; token-aware output that collapses log spam losslessly",
    "Robustness is fuzzed (proptest) and model-checked (loom); MIT-licensed with clear multi-client setup (Claude Code, Codex, Cursor, VS Code, Zed and more)"
  ],
  "what_it_fails_at": [
    "Very new and single-maintainer — v0.2.332 with a release dated ~4 days before review; limited track record",
    "High inherent blast radius: the default local server is 'the model in your terminal', and the HTTP transport puts shell access on the network (token-gated, loopback-bound, but still)",
    "Surface-only review — Hlido read the crates.io page, not a running install, so tool behaviour and the sandbox are unverified",
    "Durable runtime is Linux/macOS/WSL2; native Windows falls back to an embedded runtime tied to the server process"
  ],
  "best_for": [
    "Developers running Claude Code / Codex / Cursor who want a fast, safety-conscious shell-and-edit MCP server written in Rust",
    "Users who value scoped modes, command allowlisting and secret redaction over a permissive default",
    "Teams comfortable adopting a young but carefully-built open-source tool and reading its threat model"
  ],
  "not_recommended_for": [
    "Anyone needing a mature, widely-deployed tool with a long track record",
    "Environments that cannot grant a coding agent shell access even under scoped modes",
    "Users who won't configure modes/sandboxing and want risk handled for them"
  ],
  "red_flags": [
    "The HTTP transport exposes shell and unrestricted (wcgw-mode) file access on the network; anyone with the token gets a shell as your user — the docs say so plainly, but it is a real footgun if bound beyond loopback"
  ],
  "compared_to": [],
  "evidence_urls": [
    {
      "claim": "Real PTY semantics via portable-pty — cd sticks, Ctrl+C interrupts, background shells survive TUIs without leaking into the token budget",
      "source": "https://crates.io/crates/winx-code-agent",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Serious, uncommon safety engineering: architect/code_writer modes, a tree-sitter command allowlist that checks every command in a pipeline, default secret redaction, and an opt-in Landlock sandbox",
      "source": "https://crates.io/crates/winx-code-agent",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Forgiving-but-safe SEARCH/REPLACE editing (handles LLM whitespace/quote drift, refuses over-fuzzy or ambiguous matches) plus all-or-nothing MultiFileEdit and UndoEdit",
      "source": "https://crates.io/crates/winx-code-agent",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Tree-sitter CodeMap navigation across 11 languages; token-aware output that collapses log spam losslessly",
      "source": "https://crates.io/crates/winx-code-agent",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Hands-on runtime behaviour (executing the tool / a live task)",
      "source": "https://crates.io/crates/winx-code-agent (surface-only review; not hands-on tested)",
      "tested_at": "2026-08-19",
      "verified": false
    }
  ],
  "agent_relevance": {
    "has_api": false,
    "has_cli": true,
    "has_mcp": true,
    "has_webhook": false,
    "has_sdk": false,
    "behavioral_testable": true,
    "agent_integration_path": "Install via `cargo install winx-code-agent`; it runs as an MCP server over stdio (or token-gated Streamable HTTP) exposing nine tools. Coding agents call Initialize then drive shell, file edits and tree-sitter navigation.",
    "agent_friendly_score": 9
  },
  "summary": "A Rust MCP server that gives a coding agent a real PTY-backed shell with unusually careful safety engineering — impressively thorough for a project only days old.",
  "_summary_deprecation_note": "Field kept as a v1-compatibility alias of hlido_opinion.headline. New consumers should read hlido_opinion.{headline,body,voice,as_of}.",
  "staleness_after": "2026-11-19",
  "review_age_days_at_publish": 0,
  "next_review_due_at": "2026-11-19",
  "attestation_url": "/data/attestations/gabrielmaialva33-winx-code-agent.json",
  "signature_pending": true,
  "source": "hlido-editor-v2",
  "marking_signal": {
    "marking_statement": false,
    "detection_tool": false,
    "cop_signatory": null,
    "evidence_url": null,
    "checked_at": "2026-08-19",
    "source": "r-publish-editorial-enrich",
    "not_applicable": true,
    "note": "A shell/coding MCP server, not a generator of synthetic media or deceptive content — Article-50(4) marking obligations do not apply."
  },
  "evidence_images": {
    "run_id": "run-95a134b5dec03934-crates-io",
    "base": "https://images.hlido.eu/reviews/gabrielmaialva33-winx-code-agent/run-95a134b5dec03934-crates-io",
    "files": [
      "home.png",
      "page_code.png",
      "page_versions.png",
      "page_dependencies.png"
    ],
    "urls": [
      "https://images.hlido.eu/reviews/gabrielmaialva33-winx-code-agent/run-95a134b5dec03934-crates-io/home.png",
      "https://images.hlido.eu/reviews/gabrielmaialva33-winx-code-agent/run-95a134b5dec03934-crates-io/page_code.png",
      "https://images.hlido.eu/reviews/gabrielmaialva33-winx-code-agent/run-95a134b5dec03934-crates-io/page_versions.png",
      "https://images.hlido.eu/reviews/gabrielmaialva33-winx-code-agent/run-95a134b5dec03934-crates-io/page_dependencies.png"
    ]
  },
  "pricing_facts": {
    "schema": "pricing-facts/1",
    "model": [
      "open-source"
    ],
    "free_tier": true,
    "last_verified": "2026-08-18",
    "basis": "Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page.",
    "derived_at": "2026-08-21"
  }
}
