Atlas / MCP servers / rigour-labs / Rigour

RigourBLOCK

mcp/rigour-labs/rigour

The immune system for AI coding agents

Verdict
BLOCK
Grade
F
Trust score
50 /100
Exposed tools
45 33r · 11w · 1d
Transport
stdio
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@rigour-labs/cli) [](https://www.npmjs.com/package/@rigour-labs/cli) [](https://opensource.org/licenses/MIT) [](https://rigour.run)

A reviewer that knows how your team works, whichever agent writes the code.

Whichever agent your engineers use, its work arrives already shaped by how your team builds software, and it gets closer to your standards every week.

Teams used to carry their judgment through people: the senior who briefed you before you started, the reviewer who caught what you missed, the engineer who remembered why the last attempt failed. Coding agents write faster than any person can brief, review or remember. The knowledge is still in your team; Rigour is how it reaches every agent, at the speed agents work.

Works with Claude Code, Cursor, Codex, Cline and Windsurf. Free, open source, and runs on your machine.

How it does it

  1. Brief before writing. Before an agent edits a file, it is told what your team asks of that file: the rules your repository wrote for it, the lessons your team learned on it, the points your team settled against. At most three items per file, each cited. Opt-in: rigour hooks init --brief, or rigour_brief for any agent with MCP. See The briefing.
  2. Verify while writing and before push. Your team's checks and rules gate any agent's work: on every edit, before the agent says "done", and before git push, where your formatter, linter, type check and the tests that touch the change run too.
  3. Review with your team's context, at your team's severity. A reviewer that reads every point from your last human review, checks each rule your repository
Read from source at commit 67ad92620e21OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp -- npx -y @rigour-labs/[email protected]
03

Exposed tools (45)

33 read · 11 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cwdreadAbsolute path to the project root.
echoreadEcho input
gitwriteRun a read-only git command in the repository: log, show, diff, blame, grep, ls-files, rev-parse, merge-base.
grepreadSearch tracked files with an extended regular expression. Returns path:line:text matches.
hiddenreadNot allowed
list_dirreadList a directory in the repository or the review inputs.
read_filereadRead lines of a repository file, numbered. Use it to check callers, callees, types and constants before claiming a defect.
rigour-ai-health-reportreadAI code health report focusing on drift detection: hallucinated imports, duplication drift, context window artifacts, inconsistent error handling, and promise safety.
rigour-deep-analysiswriteRun deep LLM-powered code quality analysis. AST extracts facts, LLM interprets patterns (SOLID violations, code smells, architecture issues), AST verifies findings. Local sidecar by default; cloud provider mode when configured.
rigour-fix-loopreadIteratively fix all quality gate violations until the project passes. Retrieves fix packets and resolves issues in priority order (critical → low).
rigour-pre-commitwritePre-commit review: Rigour
rigour-security-reviewreadFull security review: CVE audit on dependencies + code-level vulnerability scan (OWASP LLM Top 10). Reports all findings with remediation steps.
rigour-setupreadInitialize Rigour quality gates for a project. Runs gate checks, installs IDE hooks, and reports the initial quality score breakdown.
rigour_agent_deregisterreadDeregister an agent from the multi-agent session. Use when an agent completes its work or needs to release its scope for another agent.
rigour_agent_registerwriteRegister an agent in a multi-agent session. Use this at the START of agent execution to claim task scope and enable cross-agent conflict detection. Required for Agent Team Governance.
rigour_briefreadBefore writing: with goal, the team
rigour_cache_statsreadReturns detailed performance stats across all 4 cache layers (exact hits, semantic hits, partial hits, misses, hit rate, tokens served from cache).
rigour_checkwriteRun quality gate checks on the project. MUST be called before declaring any coding task complete. Checks code complexity, file size, required docs, security patterns, and more. Returns PASS or FAIL with details. **Always show the user the headline summary from this tool
rigour_check_deepwriteRun quality gates WITH deep LLM-powered analysis. Three-step pipeline: AST extracts facts → LLM interprets → AST verifies. Local-first by default (Qwen2.5-Coder-0.5B lite sidecar), or bring your own API key for any cloud provider.
rigour_check_patternreadCALL THIS BEFORE creating any new function, component, hook, or class. Checks if it already exists in the codebase (prevents duplication), checks for known security vulnerabilities, and BLOCKS writes to protected paths (.github/, CI/CD configs, rigour.yml). Always pass the target file path.
rigour_context_explainreadAudits why specific files/services were included or excluded, cache hit/miss status, invalidation reasons, and prior agent requests.
rigour_context_statsreadReturns context retrieval efficiency, candidate tokens vs returned tokens, potential avoided tokens, cache hit rate, and repeated reads prevented.
rigour_deep_statsreadGet deep analysis statistics from SQLite storage. Returns recent scan scores, top issues, and score trends for a repository.
rigour_explainreadExplain WHY quality gates failed in human-readable language. Use this to understand the reasoning behind each violation before fixing. For machine-readable fix instructions, use rigour_get_fix_packet instead.
rigour_forgetdestructiveRemove a stored memory by key.
rigour_get_configreadReturns the current Rigour configuration (rigour.yml) for agent reasoning.
rigour_get_fix_packetreadCall this after rigour_check returns FAIL. Returns a bounded, prioritized page of violations with file locations and fix instructions. Use next_offset from the response to read further pages, then re-run rigour_check. Report only fixes that were actually verified.
rigour_handoffreadHandoff task to another agent in a multi-agent workflow. Use when delegating a subtask or completing your scope. Enables verified handoff governance.
rigour_handoff_acceptreadAccept a pending handoff from another agent. Use to formally acknowledge receipt of a task and verify you are the intended recipient.
rigour_hooks_checkwriteRun the fast hook checker on specific files. Same checks that run inside IDE hooks (Claude, Cursor, Cline, Windsurf). Catches: hardcoded secrets, hallucinated imports, command injection, file size. Completes in <100ms. NEW: Pass
rigour_hooks_initreadGenerate hook configs for AI coding tools (Claude, Cursor, Cline, Windsurf). Installs real-time quality checks and non-blocking DLP credential warnings by default. Pass dlp=false to disable DLP hooks only.
rigour_list_gatesreadLists all configured quality gates and their thresholds for the current project.
rigour_mcp_get_settingsreadGet Rigour MCP runtime settings for this repository (.rigour/mcp-settings.json).
rigour_mcp_set_settingswriteSet Rigour MCP runtime settings for this repository. Currently supports deep_default_mode: off | quick | full.
rigour_recallwriteLoad stored conventions. At the START of a task, call it with
rigour_rememberreadStore an instruction or convention to remember across sessions. Provide
rigour_reviewreadReview the change you just made before calling it done: runs Rigour
rigour_review_ackreadRecord that you reviewed a function from rigour_review
rigour_reviewer_verdictreadWhat the model reviewer last decided for this branch: the confirmed items to fix (with id, file:line, consequence and evidence), the disputed ones that are not work, which mode ran, and whether the verdict is for the current commit. Read-only: never runs a model, never dismisses.
rigour_runwriteExecute a command under Rigour supervision. This tool can be INTERCEPTED and ARBITRATED by the Governance Studio.
rigour_run_supervisedwriteRun a command under FULL Supervisor Mode. Iteratively executes the command, checks quality gates, and returns fix packets until PASS or max retries reached. Use this for self-healing agent loops.
rigour_security_auditreadRuns a live security audit (CVE check) on the project dependencies.
rigour_statusreadQuick PASS/FAIL check with JSON-friendly output for polling current project state.
rigour_task_costreadRigour
searchreadSearch the tracked files for a regular expression (git grep -n), optionally under one path.
04

Trust audit

BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (3 observation(s))
Shell
declared (13 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/rigour-core/src/gates/deprecated-apis-rules-lang.ts:29
api: 'pickle.load()/loads()',
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/rigour-core/src/gates/deprecated-apis-rules-lang.ts:36
api: 'yaml.load() without Loader',
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/rigour-core/src/gates/deprecated-apis-rules-lang.ts:38
replacement: 'yaml.safe_load() or yaml.load(data, Loader=yaml.SafeLoader)',
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/rigour-core/src/firewall/typed-command.ts:41
/(^|\s)--eval(\s|=|$)/,
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/rigour-core/src/gates/deprecated-apis-rules-lang.ts:43
api: 'exec() with user input',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/rigour-core/src/gates/deprecated-apis-rules-node.ts:177
api: 'eval()',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/rigour-core/src/deep/review-tools.ts:19
const SECRET_FILE = /(^|\/)(\.env(\..*)?|.*\.(pem|key|p12|pfx)|id_[a-z0-9]+|\.npmrc|\.netrc|credentials(\.json)?)$/i;
Why it matters. touches a credential store
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/rigour-cli/src/commands/demo-injections.ts:134
'    DATABASE_URL = "postgresql://admin:p@ssw0rd@prod-db:5432/app"',
MEDIUMInventory / provenance · inv.binary · CWE-1104
.pnpm-store/v11/index.db
index.db
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/rigour-core/src/gates/frontend-secret-exposure.ts:146
Logger.info(`Frontend Secret Exposure Gate: scanning ${sourceFiles.length} files`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/rigour-cli/src/commands/studio.ts:536
announce(studioLaunchUrl(`http://127.0.0.1:${studioPort}`, guard));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/rigour-cli/src/commands/studio.ts:566
announce(studioLaunchUrl(`http://127.0.0.1:${studioPort}`, guard));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/rigour-studio/vite.config.ts:13
target: `http://127.0.0.1:${apiPort}`,
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
packages/rigour-core/src/hooks/input-validator.test.ts:60
const result = scanInputForCredentials('sk-ant-api03-Z9Y8X7W6V5U4T3S2R1Q0');
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
packages/rigour-cli/src/commands/hooks.test.ts:301
files: 'AKIAZ9Y8X7W6V5U4T3Q2',
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
packages/rigour-cli/src/commands/hooks.test.ts:306
expect(output).not.toContain('AKIAZ9Y8X7W6V5U4T3Q2');
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
packages/rigour-cli/src/commands/hooks.test.ts:318
files: 'AKIAZ9Y8X7W6V5U4T3Q2',
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
packages/rigour-core/src/hooks/dlp-confidence.test.ts:34
const result = scanInputForCredentials('// AWS_ACCESS_KEY_ID=AKIAZ9Y8X7W6V5U4T3Q2');
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
packages/rigour-core/src/hooks/input-validator.test.ts:16
const result = scanInputForCredentials('Here is my key: AKIAZ9Y8X7W6V5U4T3Q2');
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/TEAM_DATABASE.md:199
--database-url 'postgresql://postgres:[email protected]:54329/postgres' --pgvector
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/TEAM_DATABASE.md:211
--database-url 'postgresql://rigour_jane:[email protected]:54329/postgres' \
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/rigour-cli/src/commands/demo-scaffold.ts:57
const API_KEY = "sk-live-4f3c2b1a0987654321abcdef";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/rigour-cli/src/commands/demo-scenarios.ts:39
'const API_KEY = "sk-live-4f3c2b1a0987654321abcdef";',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/rigour-cli/src/commands/hooks.test.ts:279
fs.writeFileSync(filePath, "const password = 'abcdefghijklmnopqrstuvwxyz12345';\n");
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/rigour-core/src/gates/security-patterns.test.ts:91
const API_KEY = "sk-1234567890abcdefghijklmnopqrst";

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 67ad92620e21full audit observations/trust-audit/mcp-server/rigour-labs__rigour.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0967ad92620e21BLOCKF50first audit
06

Questions

What is the Rigour MCP server?

The immune system for AI coding agents

What tools does Rigour expose?

45 in total: 33 read-only, 11 that write, and 1 that can delete or overwrite (rigour_forget). Every one is listed on this page with its risk.

Is Rigour safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (50/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Rigour need?

It reads ANTHROPIC_API_KEY, API_KEY, AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, CURSOR_ADMIN_API_KEY, DATABASE_SECRET_URL, GEMINI_API_KEY, GH_TOKEN, GITHUB_TOKEN, INTERNAL_TOKEN_FOR_DOCS and NEXT_PUBLIC_STRIPE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Rigour run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @rigour-labs/studio at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (67ad92620e21), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement