Winx

Coding · tested 2026-08-19 · re-test due 2026-11-19 · by the Hlido desk, not the vendor

In short: A Rust MCP server that gives a coding agent a real PTY-backed shell with unusually careful safety engineering — impressively thorough for a project only days old.

Quick answer

Winx scores 78/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-19). STEADY (78) for a well-engineered, MIT-licensed Rust MCP shell/coding server with a standout safety design (mode-scoped access, tree-sitter command allowlisting, default secret redaction, opt-in Landlock, fuzz + model-ch Pricing: Open source (free entry point documented).

Winx (winx-code-agent, MIT, on crates.io at v0.2.332) is a native-Rust MCP server that hands a coding agent the shell, file IO and PTY-backed interactive sessions. Inspired by WCGW but written from scratch, everything runs on a real PTY: cd sticks, Ctrl+C interrupts, and background shells survive long-running TUIs without leaking output into the token budget. It exposes nine MCP tools (Initialize, BashCommand, ReadFiles, FileWriteOrEdit, MultiFileEdit, UndoEdit, ContextSave, ReadImage, CodeMap) with genuinely thoughtful ergonomics — SEARCH/REPLACE editing that forgives LLM whitespace and smart-quote drift while refusing over-fuzzy matches, all-or-nothing multi-file edits validated in memory, and tree-sitter code navigation across 11 languages. The safety posture is the standout and rare for a young project: three workspace modes (full / read-only architect / allowlisted code_writer), a tree-sitter-parsed command allowlist that inspects every command in a pipeline rather than the first word, secret redaction on by default, and an opt-in Landlock kernel sandbox. Robustness is fuzzed (proptest) and model-checked (loom). The honest caveats it states itself: the default local server has the same blast radius as giving the model your terminal, and the optional HTTP transport puts shell access on the network — mitigated by mandatory tokens and loopback binding. The real limits are maturity and provenance: the release is four days old, single-maintainer, and Hlido reviewed the crates.io page, not a running install.

Why STEADY

STEADY (78) for a well-engineered, MIT-licensed Rust MCP shell/coding server with a standout safety design (mode-scoped access, tree-sitter command allowlisting, default secret redaction, opt-in Landlock, fuzz + model-check testing) and honest self-documented threat model — held at low-medium confidence because the crate is only days old and single-maintainer, and Hlido reviewed the package surface, not a live session. Not VITAL on maturity and unverified runtime behaviour.

What we saw

4 screenshots captured by the Hlido engine during the reviewed run (run-95a134b5dec03934-crates-io). Our own captures — not vendor marketing material.

Winx — run screenshot 1 (home.png)
home.png
Winx — run screenshot 2 (page_code.png)
page_code.png
Winx — run screenshot 3 (page_versions.png)
page_versions.png
Winx — run screenshot 4 (page_dependencies.png)
page_dependencies.png

What it does well

What it fails at

Red flags

Best for

  • Developers running Claude Code / Codex / Cursor who want a fast, safety-conscious shell-and-edit MCP server written in Rust
  • Users who value scoped modes, command allowlisting and secret redaction over a permissive default
  • Teams comfortable adopting a young but carefully-built open-source tool and reading its threat model

Not recommended for

  • Anyone needing a mature, widely-deployed tool with a long track record
  • Environments that cannot grant a coding agent shell access even under scoped modes
  • Users who won't configure modes/sandboxing and want risk handled for them

Pricing & access

Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-18.

Related agents

Agent relevance

CLI MCP Behavioral-testable

Install via `cargo install winx-code-agent`; it runs as an MCP server over stdio (or token-gated Streamable HTTP) exposing nine tools. Coding agents call Initialize then drive shell, file edits and tree-sitter navigation.

Agent-friendly score: 9/10

Evidence

scorecard.json · transparency passport · registry · methodology

More: compare agents · best of · developer tools · incident registry

Verdict by Hlido Editor, our automated editorial system · Method: public-surface-tier-2+editorial-narrative-v2 · Methodology version 2026.05 · Next review due 2026-11-19

How this page was produced. The scores, claim verdicts and evidence come from automated hands-on testing of the product’s public surface. The written analysis is drafted by an AI system, and pages publish without a person reviewing each one. Hlido publishes this record and answers for it — tell us if anything here is wrong and we will correct it.

Embed this trust badge

Hlido trust score

Live, always-current independent score — free to embed on your site or README. No vendor pays for placement.

Markdown

[![Hlido trust score](https://hlido.eu/badge/gabrielmaialva33-winx-code-agent.svg)](https://hlido.eu/check/?agent=gabrielmaialva33-winx-code-agent)

HTML

<a href="https://hlido.eu/check/?agent=gabrielmaialva33-winx-code-agent"><img src="https://hlido.eu/badge/gabrielmaialva33-winx-code-agent.svg" alt="Hlido trust score"></a>