npm @rigour-labs/mcpstdioMITupdated 17d ago
Your AI agent just tried to commit an AWS secret. Rigour blocked it in <100ms.
rigour で何ができる?
Rigour
Your AI agent just tried to commit an AWS secret. Rigour blocked it in <100ms.
Agent Transaction Firewall (v6): treat the agent as an untrusted proposer. Rigour decides—deterministically—what it may write, run, call, and ship. No AI judge on the allow/deny path.
Try it now (zero config)
npx rigour-scan
Works on any repo. No init, no config, no setup. Instant results in your terminal:
HARDCODED SECRET DETECTED
AWS_SECRET_ACCESS_KEY found in src/config.ts:23
+ 22 more violations across 847 files (2.1s)
Score ████░░░░░░░░░░░░░░░░ 34/100
AI Health ███░░░░░░░░░░░░░░░░░░ 28/100
Gates: ✅ file-size ❌ security ❌ ast ✅ deps
Brain: learned 12 patterns · trend: improving ↑
Add to your AI IDE (30 seconds)
{ "mcpServers": { "rigour": { "command": "npx", "args": ["-y", "@rigour-labs/mcp@latest"] } } }
| IDE / Agent | MCP Tools | Live Dashboard | Real-Time Feed |
|---|---|---|---|
| Claude Desktop | ✅ | ✅ MCP App | ✅ Logging |
| VS Code Copilot | ✅ | ✅ MCP App | ✅ Logging |
| ChatGPT | ✅ | ✅ MCP App | ✅ Logging |
| Goose | ✅ | ✅ MCP App | ✅ Logging |
| Claude Code | ✅ | — | ✅ Logging |
| Cursor | ✅ | — | ✅ Logging |
| Cline | ✅ | — | ✅ Logging |
| Windsurf | ✅ | — | ✅ Logging |
| Codex | ✅ | — | ✅ Logging |
Then install hooks so writes are checked in real time:
npx @rigour-labs/cli hooks init --tool cursor # or claude, cline, windsurf
# or via MCP: rigour_hooks_init
Does the firewall run automatically?
Short answer: quality gates + DLP + mediated rigour_run paths run when MCP/hooks are installed. It does not yet sit in front of every third-party MCP tool (GitHub/Slack/etc.)—that gateway is designed but not the default proxy.
| Surface | Automatic once installed? | What you get |
|---|---|---|
MCP server (@rigour-labs/mcp) |
Yes for Rigour tools the agent calls | rigour_check, Fix Packets, memory DLP, agent register, Studio events |
rigour_run / rigour_run_supervised |
Yes when those tools are used | Typed argv allowlist (no free-form shell: true), fail-closed human arbitration (timeout = deny), one-time Studio token |
| IDE hooks (Cursor/Claude/Cline/Windsurf) | Yes after hooks init |
Per-write checks (secrets, imports, size, protected paths). If agents are registered, set RIGOUR_AGENT_ID so scope binds to the writer (fail-closed; no union-allow) |
rigour_agent_register |
Yes when called | Rejects **/* / sensitive globs unless operator scopes or RIGOUR_ALLOW_AGENT_SCOPE_AUTHORITY=1 |
| CLI firewall | On demand / CI | firewall adversarial, firewall transact, firewall admit |
| Third-party MCP proxy | Not yet | Capability broker + McpGateway interfaces exist; Rigour is not yet a MITM for all MCP servers |
Agent proposes action
↓
Hooks / MCP mediation (when on the path)
↓
Deterministic deny/allow + rule id
↓
Studio evidence · CI attestation (admit)
Agent Transaction Firewall
npx @rigour-labs/cli firewall status
npx @rigour-labs/cli firewall adversarial # deterministic corpus — unexpected allows fail CI
npx @rigour-labs/cli firewall transact --agent <id> --scope 'packages/foo/**'
npx @rigour-labs/cli firewall admit # CI: valid attestation + PASS + bound git tree
npx @rigour-labs/cli studio # Firewall tab: decisions, attestation, mediation health
Guarantees (on mediated paths): fail-closed arbitration · typed commands · per-agent scope · signed attestation bound to commit/tree · adversarial replay as regression fuel—not an AI red-team product.
See ADR 001.
Live governance dashboard (MCP App)
In supported editors, a real-time dashboard appears automatically as your agent works:
┌─ Rigour Governance ──────────────────────────┐
│ Score: 94/100 ✅ PASS │
│ │
│ 14:32:01 rigour_check → FAIL (34/100) │
│ 14:32:03 fix_packet → 8 fixes │
│ 14:32:15 rigour_check → 71/100 (+37) │
│ 14:32:22 rigour_check → ✅ PASS 94/100 │
│ │
│ Brain: 47 patterns · trend: improving ↑ │
└───────────────────────────────────────────────┘
No extra commands. The dashboard appears when the agent calls Rigour tools. Watch your agent self-heal in real time. Open Firewall in Studio for allow/deny decisions and mediation status (partial until the MCP gateway is fully wired).
What it catches
| Category | Gates |
|---|---|
| Security | Hardcoded secrets (29+ patterns), SQL injection, XSS, CSRF, prototype pollution, Shannon entropy |
| Structural | File size, cyclomatic complexity, method count, parameter count, nesting depth, TODO/FIXME |
| AI Drift | Hallucinated imports, phantom APIs, context drift, retry loop detection |
| Governance | Agent team isolation, checkpoint supervision, memory DLP |
| Firewall | Out-of-scope writes, undeclared MCP tools, disallowed shell, fail-closed timeouts |
AST-based. Not heuristics. TypeScript, JavaScript, Python, Go, Ruby, C#, Java, Kotlin, Rust.
How it works
Agent writes code → Hooks / gates fire → FAIL? → Fix Packet (JSON)
↓
Agent reads exact instructions
↓
Agent fixes → PASS ✓
Mediated run (rigour_run) → typed allowlist → human arbitration (fail-closed)
↓
execute or deny + evidence
Voluntary rigour_check is a quality workflow, not the security boundary. Hard guarantees require installed hooks/MCP mediation and (for CI) firewall admit.
The Brain — learns your codebase
Every scan reinforces patterns. Patterns decay when absent. At strength: 0.9, they promote to hard rules. Your project's own immune system — trained locally, zero telemetry.
First week: catches 12 violations
First month: catches 8 violations ← learning your patterns
Third month: catches 3 violations ← your agents have adapted
How it's different
| Rigour | ESLint | “AI security agents” | |
|---|---|---|---|
| Runs locally, zero telemetry | ✅ | ✅ | often ❌ |
| Learns YOUR codebase (Brain) | ✅ | ❌ | ❌ |
| Agent self-healing (Fix Packets) | ✅ | ❌ | ❌ |
| Deterministic execution firewall | ✅ | ❌ | usually LLM judge |
| Works offline (GGUF sidecar) | ✅ | ✅ | ❌ |
| AI-native drift detection | ✅ | ❌ | ❌ |
| MCP-native | ✅ | ❌ | varies |
Used in production
- 19,000+ total installs across CLI and MCP
- Organically forked by Alibaba iFlow
- OWASP project — listed
- Cursor MCP directory — listed
Quick reference
npx rigour-scan # zero-config scan
npx @rigour-labs/cli init # add gates to your project
npx @rigour-labs/cli hooks init --tool cursor
npx @rigour-labs/cli check # run gates
npx @rigour-labs/cli check --deep # + local AI analysis
npx @rigour-labs/cli check --deep --provider claude -k sk-ant-xxx # cloud AI
npx @rigour-labs/cli studio # monitoring + Firewall tab
npx @rigour-labs/cli firewall adversarial
npx @rigour-labs/cli firewall admit
Architecture
| Package | Purpose |
|---|---|
@rigour-labs/core |
Gate engine, AST, Fix Packets, Brain, firewall kernel |
@rigour-labs/cli |
init, check, scan, run, studio, firewall |
@rigour-labs/mcp |
MCP server — governance tools for agent integration |
rigour-scan |
Zero-config shortcut: npx rigour-scan |
Stack: TypeScript strict, web-tree-sitter, Zod, Vitest.
Full docs | Technical Spec | Philosophy | Firewall ADR
MIT © Rigour Labs — Built by Ashutosh
If Rigour caught something real in your codebase — tell us.
インストール
rigour をクライアントに追加します。お使いのものを選んでください。
claude mcp add mcp -- npx -y @rigour-labs/mcpcodex mcp add mcp -- npx -y @rigour-labs/mcpamp mcp add mcp -- npx -y @rigour-labs/mcp{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"mcp","command":"npx","args":["-y","@rigour-labs/mcp"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"mcp": {
"type": "local",
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"mcp": {
"command": {
"path": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
}
}Add to your Zed `settings.json`.
npx -y @rigour-labs/mcpRun `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
スコア
39 / 100
情報不足
- ドキュメント25/25
- メンテナンス25/25
- 信頼性16/20
- 機能0/15
- 導入のしやすさ12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 10 days ago
- Has a release history
- Repository is not archived
- Licensed MIT
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 0 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
バージョン履歴
| バージョン | 公開日 |
|---|---|
| 5.2.7 | 2026年3月18日 |
| 5.2.6 | 2026年3月17日 |
| 5.2.5 | 2026年3月17日 |
| 5.2.4 | 2026年3月17日 |
| 5.2.3 | 2026年3月15日 |
| 5.2.2 | 2026年3月12日 |
| 5.2.1 | 2026年3月11日 |
| 5.2.0 | 2026年3月11日 |
| 5.1.2 | 2026年3月9日 |
| 5.1.1 | 2026年3月9日 |
| 5.1.0 | 2026年3月9日 |
| 5.0.1 | 2026年3月7日 |
| 5.0.0 | 2026年3月7日 |
| 4.3.6 | 2026年3月7日 |
| 4.3.5 | 2026年3月6日 |
| 4.3.4 | 2026年3月6日 |
| 4.3.2 | 2026年3月4日 |
| 4.3.1 | 2026年3月4日 |
| 4.3.0 | 2026年3月4日 |
| 4.2.3 | 2026年3月3日 |
| 4.2.2 | 2026年3月2日 |
| 4.2.1 | 2026年3月2日 |
| 4.2.0 | 2026年3月2日 |
| 4.1.1 | 2026年2月27日 |
| 4.1.0 | 2026年2月27日 |
| 4.0.5 | 2026年2月26日 |
| 4.0.4 | 2026年2月25日 |
| 4.0.3 | 2026年2月25日 |
| 4.0.2 | 2026年2月25日 |
| 4.0.1 | 2026年2月21日 |
| 4.0.0 | 2026年2月21日 |
| 3.0.6 | 2026年2月18日 |
| 3.0.5 | 2026年2月18日 |
| 3.0.4 | 2026年2月18日 |
| 3.0.3 | 2026年2月18日 |
| 3.0.2 | 2026年2月18日 |
| 3.0.1 | 2026年2月18日 |
| 3.0.0 | 2026年2月17日 |
| 2.22.0 | 2026年2月17日 |
| 2.21.2 | 2026年2月17日 |
| 2.21.1 | 2026年2月17日 |
| 2.21.0 | 2026年2月17日 |
| 2.20.0 | 2026年2月10日 |
| 2.19.2 | 2026年2月10日 |
| 2.19.1 | 2026年2月9日 |
| 2.19.0 | 2026年2月9日 |
| 2.18.2 | 2026年2月9日 |
| 2.18.1 | 2026年2月6日 |
| 2.18.0 | 2026年2月4日 |
| 2.17.2 | 2026年2月4日 |
| 2.17.1 | 2026年2月3日 |
| 2.17.0 | 2026年2月1日 |
| 2.16.0 | 2026年2月1日 |
| 2.15.0 | 2026年2月1日 |
| 2.14.0 | 2026年1月30日 |
| 2.13.0 | 2026年1月30日 |
| 2.12.0 | 2026年1月30日 |
| 2.11.0 | 2026年1月30日 |
| 2.9.4 | 2026年1月28日 |
| 2.9.3 | 2026年1月27日 |