RigourBLOCK
The immune system for AI coding agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@rigour-labs/cli) [](https://www.npmjs.com/package/@rigour-labs/cli) [](https://opensource.org/licenses/MIT) [](https://rigour.run)
A reviewer that knows how your team works, whichever agent writes the code.
Whichever agent your engineers use, its work arrives already shaped by how your team builds software, and it gets closer to your standards every week.
Teams used to carry their judgment through people: the senior who briefed you before you started, the reviewer who caught what you missed, the engineer who remembered why the last attempt failed. Coding agents write faster than any person can brief, review or remember. The knowledge is still in your team; Rigour is how it reaches every agent, at the speed agents work.
Works with Claude Code, Cursor, Codex, Cline and Windsurf. Free, open source, and runs on your machine.
How it does it
- Brief before writing. Before an agent edits a file, it is told what your team asks of that file: the rules your repository wrote for it, the lessons your team learned on it, the points your team settled against. At most three items per file, each cited. Opt-in:
rigour hooks init --brief, orrigour_brieffor any agent with MCP. See The briefing. - Verify while writing and before push. Your team's checks and rules gate any agent's work: on every edit, before the agent says "done", and before
git push, where your formatter, linter, type check and the tests that touch the change run too. - Review with your team's context, at your team's severity. A reviewer that reads every point from your last human review, checks each rule your repository
67ad92620e21OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp -- npx -y @rigour-labs/[email protected]
Exposed tools (45)
33 read · 11 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
cwd | read | Absolute path to the project root. |
echo | read | Echo input |
git | write | Run a read-only git command in the repository: log, show, diff, blame, grep, ls-files, rev-parse, merge-base. |
grep | read | Search tracked files with an extended regular expression. Returns path:line:text matches. |
hidden | read | Not allowed |
list_dir | read | List a directory in the repository or the review inputs. |
read_file | read | Read lines of a repository file, numbered. Use it to check callers, callees, types and constants before claiming a defect. |
rigour-ai-health-report | read | AI code health report focusing on drift detection: hallucinated imports, duplication drift, context window artifacts, inconsistent error handling, and promise safety. |
rigour-deep-analysis | write | Run deep LLM-powered code quality analysis. AST extracts facts, LLM interprets patterns (SOLID violations, code smells, architecture issues), AST verifies findings. Local sidecar by default; cloud provider mode when configured. |
rigour-fix-loop | read | Iteratively fix all quality gate violations until the project passes. Retrieves fix packets and resolves issues in priority order (critical → low). |
rigour-pre-commit | write | Pre-commit review: Rigour |
rigour-security-review | read | Full security review: CVE audit on dependencies + code-level vulnerability scan (OWASP LLM Top 10). Reports all findings with remediation steps. |
rigour-setup | read | Initialize Rigour quality gates for a project. Runs gate checks, installs IDE hooks, and reports the initial quality score breakdown. |
rigour_agent_deregister | read | Deregister an agent from the multi-agent session. Use when an agent completes its work or needs to release its scope for another agent. |
rigour_agent_register | write | Register an agent in a multi-agent session. Use this at the START of agent execution to claim task scope and enable cross-agent conflict detection. Required for Agent Team Governance. |
rigour_brief | read | Before writing: with goal, the team |
rigour_cache_stats | read | Returns detailed performance stats across all 4 cache layers (exact hits, semantic hits, partial hits, misses, hit rate, tokens served from cache). |
rigour_check | write | Run quality gate checks on the project. MUST be called before declaring any coding task complete. Checks code complexity, file size, required docs, security patterns, and more. Returns PASS or FAIL with details. **Always show the user the headline summary from this tool |
rigour_check_deep | write | Run quality gates WITH deep LLM-powered analysis. Three-step pipeline: AST extracts facts → LLM interprets → AST verifies. Local-first by default (Qwen2.5-Coder-0.5B lite sidecar), or bring your own API key for any cloud provider. |
rigour_check_pattern | read | CALL THIS BEFORE creating any new function, component, hook, or class. Checks if it already exists in the codebase (prevents duplication), checks for known security vulnerabilities, and BLOCKS writes to protected paths (.github/, CI/CD configs, rigour.yml). Always pass the target file path. |
rigour_context_explain | read | Audits why specific files/services were included or excluded, cache hit/miss status, invalidation reasons, and prior agent requests. |
rigour_context_stats | read | Returns context retrieval efficiency, candidate tokens vs returned tokens, potential avoided tokens, cache hit rate, and repeated reads prevented. |
rigour_deep_stats | read | Get deep analysis statistics from SQLite storage. Returns recent scan scores, top issues, and score trends for a repository. |
rigour_explain | read | Explain WHY quality gates failed in human-readable language. Use this to understand the reasoning behind each violation before fixing. For machine-readable fix instructions, use rigour_get_fix_packet instead. |
rigour_forget | destructive | Remove a stored memory by key. |
rigour_get_config | read | Returns the current Rigour configuration (rigour.yml) for agent reasoning. |
rigour_get_fix_packet | read | Call this after rigour_check returns FAIL. Returns a bounded, prioritized page of violations with file locations and fix instructions. Use next_offset from the response to read further pages, then re-run rigour_check. Report only fixes that were actually verified. |
rigour_handoff | read | Handoff task to another agent in a multi-agent workflow. Use when delegating a subtask or completing your scope. Enables verified handoff governance. |
rigour_handoff_accept | read | Accept a pending handoff from another agent. Use to formally acknowledge receipt of a task and verify you are the intended recipient. |
rigour_hooks_check | write | Run the fast hook checker on specific files. Same checks that run inside IDE hooks (Claude, Cursor, Cline, Windsurf). Catches: hardcoded secrets, hallucinated imports, command injection, file size. Completes in <100ms. NEW: Pass |
rigour_hooks_init | read | Generate hook configs for AI coding tools (Claude, Cursor, Cline, Windsurf). Installs real-time quality checks and non-blocking DLP credential warnings by default. Pass dlp=false to disable DLP hooks only. |
rigour_list_gates | read | Lists all configured quality gates and their thresholds for the current project. |
rigour_mcp_get_settings | read | Get Rigour MCP runtime settings for this repository (.rigour/mcp-settings.json). |
rigour_mcp_set_settings | write | Set Rigour MCP runtime settings for this repository. Currently supports deep_default_mode: off | quick | full. |
rigour_recall | write | Load stored conventions. At the START of a task, call it with |
rigour_remember | read | Store an instruction or convention to remember across sessions. Provide |
rigour_review | read | Review the change you just made before calling it done: runs Rigour |
rigour_review_ack | read | Record that you reviewed a function from rigour_review |
rigour_reviewer_verdict | read | What the model reviewer last decided for this branch: the confirmed items to fix (with id, file:line, consequence and evidence), the disputed ones that are not work, which mode ran, and whether the verdict is for the current commit. Read-only: never runs a model, never dismisses. |
rigour_run | write | Execute a command under Rigour supervision. This tool can be INTERCEPTED and ARBITRATED by the Governance Studio. |
rigour_run_supervised | write | Run a command under FULL Supervisor Mode. Iteratively executes the command, checks quality gates, and returns fix packets until PASS or max retries reached. Use this for self-healing agent loops. |
rigour_security_audit | read | Runs a live security audit (CVE check) on the project dependencies. |
rigour_status | read | Quick PASS/FAIL check with JSON-friendly output for polling current project state. |
rigour_task_cost | read | Rigour |
search | read | Search the tracked files for a regular expression (git grep -n), optionally under one path. |
Trust audit
BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (13 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
api: 'pickle.load()/loads()',
api: 'yaml.load() without Loader',
replacement: 'yaml.safe_load() or yaml.load(data, Loader=yaml.SafeLoader)',
/(^|\s)--eval(\s|=|$)/,
api: 'exec() with user input',
api: 'eval()',
const SECRET_FILE = /(^|\/)(\.env(\..*)?|.*\.(pem|key|p12|pfx)|id_[a-z0-9]+|\.npmrc|\.netrc|credentials(\.json)?)$/i;
' DATABASE_URL = "postgresql://admin:p@ssw0rd@prod-db:5432/app"',
index.db
Logger.info(`Frontend Secret Exposure Gate: scanning ${sourceFiles.length} files`);announce(studioLaunchUrl(`http://127.0.0.1:${studioPort}`, guard));announce(studioLaunchUrl(`http://127.0.0.1:${studioPort}`, guard));target: `http://127.0.0.1:${apiPort}`,const result = scanInputForCredentials('sk-ant-api03-Z9Y8X7W6V5U4T3S2R1Q0');files: 'AKIAZ9Y8X7W6V5U4T3Q2',
expect(output).not.toContain('AKIAZ9Y8X7W6V5U4T3Q2');files: 'AKIAZ9Y8X7W6V5U4T3Q2',
const result = scanInputForCredentials('// AWS_ACCESS_KEY_ID=AKIAZ9Y8X7W6V5U4T3Q2');const result = scanInputForCredentials('Here is my key: AKIAZ9Y8X7W6V5U4T3Q2');--database-url 'postgresql://postgres:[email protected]:54329/postgres' --pgvector
--database-url 'postgresql://rigour_jane:[email protected]:54329/postgres' \
const API_KEY = "sk-live-4f3c2b1a0987654321abcdef";
'const API_KEY = "sk-live-4f3c2b1a0987654321abcdef";',
fs.writeFileSync(filePath, "const password = 'abcdefghijklmnopqrstuvwxyz12345';\n");
const API_KEY = "sk-1234567890abcdefghijklmnopqrst";
Gates applied: no_behavioural_pass.
67ad92620e21full audit observations/trust-audit/mcp-server/rigour-labs__rigour.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 67ad92620e21 | BLOCK | F | 50 | first audit |
Questions
What is the Rigour MCP server?
The immune system for AI coding agents
What tools does Rigour expose?
45 in total: 33 read-only, 11 that write, and 1 that can delete or overwrite (rigour_forget). Every one is listed on this page with its risk.
Is Rigour safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (50/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Rigour need?
It reads ANTHROPIC_API_KEY, API_KEY, AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, CURSOR_ADMIN_API_KEY, DATABASE_SECRET_URL, GEMINI_API_KEY, GH_TOKEN, GITHUB_TOKEN, INTERNAL_TOKEN_FOR_DOCS and NEXT_PUBLIC_STRIPE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Rigour run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @rigour-labs/studio at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (67ad92620e21), read on 2026-10-09. The repository is watched and re-audited when it changes.