Rigour MCP
OfficialClick on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Rigour MCPscan current repository for hardcoded secrets and structural issues"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Rigour
Your AI agent writes the code. Rigour makes sure it's right before anyone has to review it.
Coding agents are fast, and they make mistakes with confidence: an export nothing uses, a query that re-reads the whole table on every page, a fix that came back after the reviewer already flagged it. Today a human finds those at the pull request, round after round. Rigour checks the work while the agent is still writing, at the moments that matter, and the agent fixes it before anyone else has to look.
Works with Claude Code, Cursor, Codex, Cline and Windsurf. Free, open source, and runs on your machine.
What makes Rigour different
It works at the three moments that matter, not only at the pull request. On every edit, before your agent says "done", and before it pushes. Most problems are fixed before a pull request exists.
It remembers what your reviewer said last time. Before a push, a fresh reviewer checks every point from the last human review against the code, so a fix that only covered half of a comment is caught, not shipped. It uses your agent's own login: no API key.
It reports what you changed, not what was already there. Old problems in code you touched stay out of your review, so every finding is yours to fix.
It runs your team's own tools. Your formatter, linter, type check and the tests that touch the change run before every push, without anyone remembering to.
It only blocks on what it can prove. Dead code, offset paging, unbounded time windows, copied functions, merge conflicts, stale references: each check was run over real merged pull requests before it was allowed to block. Anything less certain is a note, never a gate.
It shows its work. Every review ends with a receipt: which risky changes were reviewed during development, which changed after review, and which nobody looked at.
One machine, many companies, nothing crosses. Profiles keep each employer's or client's memory, lessons and team apart, chosen by the repository you're in.
Related MCP server: Metsuke
How it works
When | What Rigour does | If something's wrong |
Every edit | Fast checks on the file: secrets, imports that don't exist, proven bugs | The agent sees it at once |
Before "done" | The whole branch against main: findings to fix, code nothing uses, risky patterns, a merge conflict | The agent keeps working (at most three times) |
Before | The same, plus your formatter, linter, type check and related tests, and the reviewer that remembers | The push is blocked, one line per problem |
On the pull request | A quiet safety net: at most two comments, only on what wasn't already checked | — |
Get started
brew install rigour-labs/tap/rigour # or: npm install -g @rigour-labs/cli
rigour setup # in your repositoryrigour setup connects Rigour to your agents, installs the three moments, and checks that everything works. Already set up before the push gate existed? Run rigour hooks init --force once.
Using Claude Code? The plugin does all of it:
/plugin marketplace add rigour-labs/rigour-plugin
/plugin install rigour@rigour-labsWant the reviewer too? Add this to rigour.yml:
review:
reviewer:
enabled: trueThe push goes through as soon as the checks pass; the reviewer then reads the pushed commit in the background (only when it has an open, non-draft pull request, so you pay for a model only when someone will read the push). rigour review --status shows its verdict; rigour review --reviewer --full runs two vendors and is the hard stop before you ask a person to review.
Then open Studio to watch it work:
rigour studioFour commands
Command | What it does |
| Gets your repository ready and checks it works |
| Reviews your current change, or a branch before you open a PR ( |
| Shows what Rigour stopped, learned and gave your agents |
| Tells you what's working, what isn't, and how to fix it |
Everything else is in rigour help --all.
Built to be trusted
It never cries wolf. A check blocks only after it has been measured on real pull requests. Guesses about style or size never block you and never show up on a PR.
Say "not a bug" once. That finding never comes back, and checks your team keeps overruling go quiet on their own.
When it can't check, it says so. No reviewer answer, nothing to review, a tool that isn't installed: each is reported plainly, never as a clean pass.
Your code stays on your machine. Nothing is sent anywhere unless you add a model key; team sync sends only lessons from your team's own repositories.
You see what it costs. When a model is used, Rigour records the real cost of each run.
Measured in the open. Claims about what Rigour catches are tested on real pull requests in the public driftbench arena.
Measured against your own reviewers.
rigour backtestreplays the review on commits your team reviewed, with the review hidden, and scores it: which of the reviewer's points it would have caught first, and whether it would have blocked anything they called good. See Backtest.One rule for what blocks. The review, the stop hook and the push gate decide from the same rule, so they never disagree about a finding.
What it costs
Rigour is free. With an agent you need nothing else: the checks run locally, and the reviewer and the review of risky changes use your agent's own model and login. A model key is only for reviewing code written without an agent, and for the pull request bot.
For teams
Pull request bot. Add one workflow file and Rigour reviews every PR, quietly. With enforce: true it becomes a required check, and a PR can't dismiss its own findings. See PR Bot.
Shared knowledge. Point Rigour at a PostgreSQL database and lessons one person's agent learns can be shared with the whole team, after someone approves them. Only lessons from the team's own repositories are ever sent. See Enterprise & Teams.
Working for more than one company? Profiles keep each one's memory, lessons and team apart, chosen by the repository you're in. See Profiles.
Learn more
If you want to… | Read |
Install and run Rigour step by step | |
Connect a coding agent | |
Set up the pull request bot | |
Use your own model key | |
Tune what Rigour checks | |
Work across several companies on one machine | |
See how each check is measured | |
Know exactly what is collected | Telemetry: opt-in, anonymous, never code |
Build from source
pnpm install
pnpm build
pnpm testDocumentation · Discussions · Issues
MIT © Rigour Labs · Built by Ashutosh
This server cannot be deployed
Maintenance
Related MCP Connectors
Security reviews for coding agents: diffs checked against your org policy and live infrastructure.
Pre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof.
Governance copilot for AI-assisted coding. 72 packs, 532 rules, proof bundles.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Related MCP Servers
- FlicenseAqualityDmaintenanceProvides real-time policy enforcement for AI coding agents by intercepting and validating their actions against organizational standards like naming conventions, security policies, and compliance rules before execution. Prevents violations through immediate feedback and auto-correction suggestions.5-
- AlicenseNot gradedqualityFmaintenanceProvides SDLC compliance verification as tools that AI agents can invoke, continuously monitoring and evaluating development processes.MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to scan code for security and quality issues and receive machine-readable reports with suggested fixes and verification criteria.58 npm2MIT

corbatofficial
AlicenseAqualityDmaintenancePolicy and quality engine for AI coding agents that enforces team coding standards and provides validation gates for agent-assisted software delivery.744 npm4MIT