Skip to main content
Glama
cogniumhq

@cognium/mcp-server

Official
by cogniumhq

cognium-mcp

The Cognium MCP server and the editor plugins that use it.

What

Where

@cognium/mcp-server

MCP server for Cursor, Claude Desktop, Claude Code and any other MCP client

npm

Cognium SAST plugin

Skills, rules, commands and an agent, wired to the server

Cursor and Claude Code marketplaces, from this repository

The server

npx -y @cognium/mcp-server

It speaks MCP over stdio and serves eleven deterministic static-analysis tools built on circle-ir: scan a project, list entry points and reachable sinks, trace taint paths, explain a finding, check a sanitizer. No API key, no network, no model.

The same package is also a library, so a host can mount the server over its own transport:

import { createServer } from '@cognium/mcp-server';

const { server } = await createServer();
await server.connect(transport);

Optional tool modules are loaded when they are installed next to the server. circle-ir-ai ships one, circle-ir-ai/mcp, which adds ten more tools. A module built against a different circle-ir minor is refused on one line of stderr and the eleven built-in tools keep serving.

Client configuration, the environment variables and the licence states are in the package README.

Related MCP server: agentguard

What this repository promises

The tool list and its schemas are the API. A removed or renamed tool, or a changed schema, is a major version; a new tool or field is a minor. CI holds that, and the other promises, as separate checks:

Check

Holds

one answer

the same requests get byte-identical responses over stdio and over streamable HTTP

three states

the expected tool list and startup lines with and without a module, an endpoint and a licence token

module refusal

a module on another circle-ir minor is refused and the built-in tools serve

protocol

the handshake, valid JSON Schema for every tool, and no side effects on import

manifest

what the tarball contains, and that it carries only the MIT licence

install

a packed build installs into an empty directory and serves the same tools as the last release

pin check

circle-ir is pinned exactly, resolved once, and named in the changelog

self-scan

a published release of the scanner finds nothing high or critical in the server's own source, beyond a short, checked list of known false positives

Development

npm install
npm run build
npm test
npm run lint
npm run check:pins

Node.js 20.19 or newer. See CONTRIBUTING.md and RELEASING.md.

Where the engine lives

The analysis itself is circle-ir, in the cognium-dev repository, along with the cognium-dev command-line scanner. This package lived there until 0.2.0 and moved here with its history; issue numbers in older commits and changelog entries refer to that repository.

License

MIT. See LICENSE.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    Enables real-time code analysis for JavaScript, TypeScript, and Python through Claude Desktop and other MCP clients, detecting bugs, code smells, and security vulnerabilities with automated quick fixes.
    7
    192 npm
    4
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables scanning of AI agent code for security vulnerabilities such as prompt injection, tool abuse, and data exfiltration, directly from MCP-compatible clients like Claude Code.
    2
    LGPL 3.0
  • A
    license
    A
    quality
    B
    maintenance
    Enables triage of SAST findings by exposing a read-only MCP server with tools to access hash-verified source-to-sink code slices, unguarded sinks, and layered enrichment for local LLM analysis.
    10
    MIT
  • F
    license
    B
    quality
    C
    maintenance
    Enables AI agents to perform comprehensive, zero-infrastructure codebase analysis through 24 MCP tools, covering security, quality, architecture, type safety, git history, and dead code detection with high precision and local privacy.
    45
    -