Joern MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Joern MCP Servershow all calls to exec and their caller methods"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Joern MCP Server
MCP-сервер для взаимодействия с Joern — платформой для анализа исходного кода и построения графов свойств кода (CPG — Code Property Graph).
Сервер общается с Joern через синхронный HTTP-эндпоинт /query-sync, поэтому не требует опроса состояния и подходит для выполнения любых CPGQL-запросов.
Возможности
Сервер предоставляет три MCP-инструмента:
Инструмент | Назначение |
| Выполнить произвольный Joern/CPGQL-запрос к загруженному CPG |
| Загрузить исходный код и построить CPG (PHP, Java, JS, Python, C/C++…) |
| Показать загруженные проекты и активный CPG в рабочем пространстве |
Related MCP server: neo4j-server-remote
Требования
Python 3.10+
Joern — запущенный сервер (
joern --server) наhttp://localhost:8080Python-пакет
mcp
Установка
pip install -r requirements.txtЗапуск
Запустите сервер Joern:
joern --serverПодключите MCP-сервер к вашему клиенту (например, Trae). Пример конфигурации:
{ "mcpServers": { "joern": { "command": "python3", "args": ["/абсолютный/путь/к/server.py"] } } }
Интерактивный REPL
Для ручного выполнения запросов без MCP-клиента есть простой REPL:
python3 repl.pyПосле запуска вводите CPGQL-запросы в приглашении joern>.
Примеры запросов
cpg.method.name.l
cpg.call.name("exec").caller.name.l
cpg.identifier.name("_GET|_POST").l
cpg.method.name("login").ast.isCall.name.l
sink.reachableByFlows(source).pСтруктура проекта
.
├── server.py # MCP-сервер (инструменты joern_query / joern_load / joern_workspace)
├── repl.py # Интерактивный REPL для ручных запросов
├── requirements.txt # Python-зависимости
└── LICENSE # GNU GPL v3.0Переменные среды
Параметры подключения заданы в server.py и могут быть изменены:
JOERN_BASE— адрес сервера Joern (по умолчаниюhttp://localhost:8080)TIMEOUT— таймаут запроса в секундах (по умолчанию120)MAX_RESULT— максимальная длина вывода в символах (по умолчанию8000)
Лицензия
Проект распространяется под лицензией GNU General Public License v3.0.
This server cannot be deployed
Maintenance
Related MCP Connectors
The Cortex MCP server provides read-only access to real-time engineering context from the Cortex developer portal, allowing AI coding assistants to answer natural language questions about your organization's catalog (microservices, libraries, domains, teams, infrastructure), scorecards (engineering standards and best practices), initiatives (goals and deadlines), and Engineering Intelligence metrics. It includes tools for querying documentation, tracking personal entities, and accessing AI-assisted insights across the entire Cortex ecosystem.
Ask a codebase what calls what: search, blast radius, paths between symbols, and diffs.
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Repository knowledge graph MCP server for codebase understanding and debugging.
Related MCP Servers
- AlicenseBqualityBmaintenanceA simple MCP (Multimodal Conversational Plugin) server based on Joern that provides code review and security analysis capabilities through natural language interfaces.1851MIT
- AlicenseNot gradedqualityDmaintenanceEnables interaction with Neo4j graph databases through Cypher queries, supporting both read and write operations, schema exploration, and remote database connections via SSE or STDIO transport protocols.5MIT
- FlicenseNot gradedqualityBmaintenanceEnables querying a Neo4j-based code graph for Python projects, providing tools for code structure, call graph, and test coverage analysis.1-
- FlicenseNot gradedqualityBmaintenanceEnables querying cross-repo code dependencies, HTTP routes, database tables, and queues via an MCP server using Cypher queries.-