Winx
Coding · tested 2026-08-19 · re-test due 2026-11-19 · by the Hlido desk, not the vendor
In short: A Rust MCP server that gives a coding agent a real PTY-backed shell with unusually careful safety engineering — impressively thorough for a project only days old.
Quick answer
Winx scores 78/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-19). STEADY (78) for a well-engineered, MIT-licensed Rust MCP shell/coding server with a standout safety design (mode-scoped access, tree-sitter command allowlisting, default secret redaction, opt-in Landlock, fuzz + model-ch Pricing: Open source (free entry point documented).
Winx (winx-code-agent, MIT, on crates.io at v0.2.332) is a native-Rust MCP server that hands a coding agent the shell, file IO and PTY-backed interactive sessions. Inspired by WCGW but written from scratch, everything runs on a real PTY: cd sticks, Ctrl+C interrupts, and background shells survive long-running TUIs without leaking output into the token budget. It exposes nine MCP tools (Initialize, BashCommand, ReadFiles, FileWriteOrEdit, MultiFileEdit, UndoEdit, ContextSave, ReadImage, CodeMap) with genuinely thoughtful ergonomics — SEARCH/REPLACE editing that forgives LLM whitespace and smart-quote drift while refusing over-fuzzy matches, all-or-nothing multi-file edits validated in memory, and tree-sitter code navigation across 11 languages. The safety posture is the standout and rare for a young project: three workspace modes (full / read-only architect / allowlisted code_writer), a tree-sitter-parsed command allowlist that inspects every command in a pipeline rather than the first word, secret redaction on by default, and an opt-in Landlock kernel sandbox. Robustness is fuzzed (proptest) and model-checked (loom). The honest caveats it states itself: the default local server has the same blast radius as giving the model your terminal, and the optional HTTP transport puts shell access on the network — mitigated by mandatory tokens and loopback binding. The real limits are maturity and provenance: the release is four days old, single-maintainer, and Hlido reviewed the crates.io page, not a running install.
Why STEADY
STEADY (78) for a well-engineered, MIT-licensed Rust MCP shell/coding server with a standout safety design (mode-scoped access, tree-sitter command allowlisting, default secret redaction, opt-in Landlock, fuzz + model-check testing) and honest self-documented threat model — held at low-medium confidence because the crate is only days old and single-maintainer, and Hlido reviewed the package surface, not a live session. Not VITAL on maturity and unverified runtime behaviour.
What we saw
4 screenshots captured by the Hlido engine during the reviewed run (run-95a134b5dec03934-crates-io). Our own captures — not vendor marketing material.
What it does well
- Real PTY semantics via portable-pty — cd sticks, Ctrl+C interrupts, background shells survive TUIs without leaking into the token budget
- Serious, uncommon safety engineering: architect/code_writer modes, a tree-sitter command allowlist that checks every command in a pipeline, default secret redaction, and an opt-in Landlock sandbox
- Forgiving-but-safe SEARCH/REPLACE editing (handles LLM whitespace/quote drift, refuses over-fuzzy or ambiguous matches) plus all-or-nothing MultiFileEdit and UndoEdit
- Tree-sitter CodeMap navigation across 11 languages; token-aware output that collapses log spam losslessly
- Robustness is fuzzed (proptest) and model-checked (loom); MIT-licensed with clear multi-client setup (Claude Code, Codex, Cursor, VS Code, Zed and more)
What it fails at
- Very new and single-maintainer — v0.2.332 with a release dated ~4 days before review; limited track record
- High inherent blast radius: the default local server is 'the model in your terminal', and the HTTP transport puts shell access on the network (token-gated, loopback-bound, but still)
- Surface-only review — Hlido read the crates.io page, not a running install, so tool behaviour and the sandbox are unverified
- Durable runtime is Linux/macOS/WSL2; native Windows falls back to an embedded runtime tied to the server process
Red flags
- The HTTP transport exposes shell and unrestricted (wcgw-mode) file access on the network; anyone with the token gets a shell as your user — the docs say so plainly, but it is a real footgun if bound beyond loopback
Best for
- Developers running Claude Code / Codex / Cursor who want a fast, safety-conscious shell-and-edit MCP server written in Rust
- Users who value scoped modes, command allowlisting and secret redaction over a permissive default
- Teams comfortable adopting a young but carefully-built open-source tool and reading its threat model
Not recommended for
- Anyone needing a mature, widely-deployed tool with a long track record
- Environments that cannot grant a coding agent shell access even under scoped modes
- Users who won't configure modes/sandboxing and want risk handled for them
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-18.
Related agents
Agent relevance
CLI MCP Behavioral-testable
Install via `cargo install winx-code-agent`; it runs as an MCP server over stdio (or token-gated Streamable HTTP) exposing nine tools. Coding agents call Initialize then drive shell, file edits and tree-sitter navigation.
Agent-friendly score: 9/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Real PTY semantics via portable-pty — cd sticks, Ctrl+C interrupts, background shells survive TUIs without leaking into the token budget — source (2026-08-19) verified
- Serious, uncommon safety engineering: architect/code_writer modes, a tree-sitter command allowlist that checks every command in a pipeline, default secret redaction, and an opt-in Landlock sandbox — source (2026-08-19) verified
- Forgiving-but-safe SEARCH/REPLACE editing (handles LLM whitespace/quote drift, refuses over-fuzzy or ambiguous matches) plus all-or-nothing MultiFileEdit and UndoEdit — source (2026-08-19) verified
- Tree-sitter CodeMap navigation across 11 languages; token-aware output that collapses log spam losslessly — source (2026-08-19) verified
- Hands-on runtime behaviour (executing the tool / a live task) — source (2026-08-19)



