@cognium/mcp-server
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@cognium/mcp-serverscan this project and trace any taint paths from user input"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
cognium-mcp
The Cognium MCP server and the editor plugins that use it.
What | Where | |
MCP server for Cursor, Claude Desktop, Claude Code and any other MCP client | ||
Skills, rules, commands and an agent, wired to the server | Cursor and Claude Code marketplaces, from this repository |
The server
npx -y @cognium/mcp-serverIt speaks MCP over stdio and serves eleven deterministic static-analysis tools
built on circle-ir: scan a project,
list entry points and reachable sinks, trace taint paths, explain a finding,
check a sanitizer. No API key, no network, no model.
The same package is also a library, so a host can mount the server over its own transport:
import { createServer } from '@cognium/mcp-server';
const { server } = await createServer();
await server.connect(transport);Optional tool modules are loaded when they are installed next to the server.
circle-ir-ai ships one,
circle-ir-ai/mcp, which adds ten more tools. A module built against a
different circle-ir minor is refused on one line of stderr and the eleven
built-in tools keep serving.
Client configuration, the environment variables and the licence states are in the package README.
Related MCP server: agentguard
What this repository promises
The tool list and its schemas are the API. A removed or renamed tool, or a changed schema, is a major version; a new tool or field is a minor. CI holds that, and the other promises, as separate checks:
Check | Holds |
one answer | the same requests get byte-identical responses over stdio and over streamable HTTP |
three states | the expected tool list and startup lines with and without a module, an endpoint and a licence token |
module refusal | a module on another |
protocol | the handshake, valid JSON Schema for every tool, and no side effects on import |
manifest | what the tarball contains, and that it carries only the MIT licence |
install | a packed build installs into an empty directory and serves the same tools as the last release |
pin check |
|
self-scan | a published release of the scanner finds nothing high or critical in the server's own source, beyond a short, checked list of known false positives |
Development
npm install
npm run build
npm test
npm run lint
npm run check:pinsNode.js 20.19 or newer. See CONTRIBUTING.md and RELEASING.md.
Where the engine lives
The analysis itself is circle-ir,
in the cognium-dev repository, along with the cognium-dev command-line
scanner. This package lived there until 0.2.0 and moved here with its history;
issue numbers in older commits and changelog entries refer to that repository.
License
MIT. See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Self-hosted MCP server: 26 deterministic dev, security, and EVM tools.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Enable secure connectivity between Sentry issues and debugging data, and LLM clients, using a Model Context Protocol (MCP) server.
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables real-time code analysis for JavaScript, TypeScript, and Python through Claude Desktop and other MCP clients, detecting bugs, code smells, and security vulnerabilities with automated quick fixes.7192 npm4MIT
- AlicenseNot gradedqualityAmaintenanceEnables scanning of AI agent code for security vulnerabilities such as prompt injection, tool abuse, and data exfiltration, directly from MCP-compatible clients like Claude Code.2LGPL 3.0
- AlicenseAqualityBmaintenanceEnables triage of SAST findings by exposing a read-only MCP server with tools to access hash-verified source-to-sink code slices, unguarded sinks, and layered enrichment for local LLM analysis.10MIT
- FlicenseBqualityCmaintenanceEnables AI agents to perform comprehensive, zero-infrastructure codebase analysis through 24 MCP tools, covering security, quality, architecture, type safety, git history, and dead code detection with high precision and local privacy.45-