Atlas / MCP servers / jordyzomer / CodeQL

CodeQLSAFE

mcp/jordyzomer/codeql

This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like [Cursor](https://cursor.sh/) or AI agents to interact with CodeQL through structured commands.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 6r · 0w · 0d
Transport
—
License
—
Stars
149
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like Cursor or AI agents to interact with CodeQL through structured commands and doc search.

Features

  • ✅ Register CodeQL databases
  • ✅ Run full queries or quick-evaluate a symbol
  • ✅ Decode .bqrs files into JSON
  • ✅ Locate predicate/class symbol positions

File Structure

Requirements

Install with `uv`:

uv pip install -r requirements.txt

or with pip:

pip install fastmcp httpx

Running the MCP Server

uv run mcp run server.py -t sse
  • Starts the server at http://localhost:8000/sse
  • Required for Cursor or AI agent use

Cursor Config

Make sure your .cusor/config.json contains:

{
"mcpServers": {
"CodeQL": {
"url": "http://localhost:8000/sse"
}
}
}

Notes

  • Tools like Cursor will invoke these commands directly via natural language.
  • You must have a codeql binary in your $PATH, or hardcode its path in codeqlclient.py.
  • You should probably specify query locations, query write locations and database paths in your prompts.
Read from source at commit eccf8716a62aOBSERVED · 2026-10-07
02

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
decode_bqrsreadThis can be used to decode CodeQL results, format is either csv for problem queries or json for path-problems
evaluate_queryreadRuns a CodeQL query on a given database
find_class_positionreadFinds startline, startcol, endline endcol of a class for quickeval
find_predicate_positionreadFinds startline, startcol, endline endcol of a predicate for quickeval
quick_evaluatereadThis will allow you to quick_evaluate either a class or a predicate in a codeql query
register_databasereadThis tool registers a CodeQL database given a path
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, httpx
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha eccf8716a62afull audit observations/trust-audit/mcp-server/jordyzomer__codeql.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07eccf8716a62aSAFEB89first audit
05

Questions

What is the CodeQL MCP server?

This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like [Cursor](https://cursor.sh/) or AI agents to interact with CodeQL through structured commands.

What tools does CodeQL expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CodeQL safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does CodeQL need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (eccf8716a62a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement