Skip to content
MCP ThesaurusMCP Thesaurus

rigour

CommunityIncomplete39/100Claim

npm @rigour-labs/mcpstdioMITupdated 17d ago

Your AI agent just tried to commit an AWS secret. Rigour blocked it in <100ms.

SourceWebsiteDocs26

What can you do with rigour?

Rigour

npm version cli downloads mcp downloads License: MIT MCP Registry OWASP

Your AI agent just tried to commit an AWS secret. Rigour blocked it in <100ms.

Agent Transaction Firewall (v6): treat the agent as an untrusted proposer. Rigour decidesβ€”deterministicallyβ€”what it may write, run, call, and ship. No AI judge on the allow/deny path.

Try it now (zero config)

npx rigour-scan

Works on any repo. No init, no config, no setup. Instant results in your terminal:

  HARDCODED SECRET DETECTED
  AWS_SECRET_ACCESS_KEY found in src/config.ts:23

  + 22 more violations across 847 files (2.1s)

  Score        β–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  34/100
  AI Health    β–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘β–‘  28/100

  Gates:  βœ… file-size  ❌ security  ❌ ast  βœ… deps

  Brain: learned 12 patterns Β· trend: improving ↑

Add to your AI IDE (30 seconds)

{ "mcpServers": { "rigour": { "command": "npx", "args": ["-y", "@rigour-labs/mcp@latest"] } } }
IDE / Agent MCP Tools Live Dashboard Real-Time Feed
Claude Desktop βœ… βœ… MCP App βœ… Logging
VS Code Copilot βœ… βœ… MCP App βœ… Logging
ChatGPT βœ… βœ… MCP App βœ… Logging
Goose βœ… βœ… MCP App βœ… Logging
Claude Code βœ… β€” βœ… Logging
Cursor βœ… β€” βœ… Logging
Cline βœ… β€” βœ… Logging
Windsurf βœ… β€” βœ… Logging
Codex βœ… β€” βœ… Logging

Then install hooks so writes are checked in real time:

npx @rigour-labs/cli hooks init --tool cursor   # or claude, cline, windsurf
# or via MCP: rigour_hooks_init

Does the firewall run automatically?

Short answer: quality gates + DLP + mediated rigour_run paths run when MCP/hooks are installed. It does not yet sit in front of every third-party MCP tool (GitHub/Slack/etc.)β€”that gateway is designed but not the default proxy.

Surface Automatic once installed? What you get
MCP server (@rigour-labs/mcp) Yes for Rigour tools the agent calls rigour_check, Fix Packets, memory DLP, agent register, Studio events
rigour_run / rigour_run_supervised Yes when those tools are used Typed argv allowlist (no free-form shell: true), fail-closed human arbitration (timeout = deny), one-time Studio token
IDE hooks (Cursor/Claude/Cline/Windsurf) Yes after hooks init Per-write checks (secrets, imports, size, protected paths). If agents are registered, set RIGOUR_AGENT_ID so scope binds to the writer (fail-closed; no union-allow)
rigour_agent_register Yes when called Rejects **/* / sensitive globs unless operator scopes or RIGOUR_ALLOW_AGENT_SCOPE_AUTHORITY=1
CLI firewall On demand / CI firewall adversarial, firewall transact, firewall admit
Third-party MCP proxy Not yet Capability broker + McpGateway interfaces exist; Rigour is not yet a MITM for all MCP servers
Agent proposes action
        ↓
Hooks / MCP mediation (when on the path)
        ↓
Deterministic deny/allow + rule id
        ↓
Studio evidence  Β·  CI attestation (admit)

Agent Transaction Firewall

npx @rigour-labs/cli firewall status
npx @rigour-labs/cli firewall adversarial   # deterministic corpus β€” unexpected allows fail CI
npx @rigour-labs/cli firewall transact --agent <id> --scope 'packages/foo/**'
npx @rigour-labs/cli firewall admit         # CI: valid attestation + PASS + bound git tree
npx @rigour-labs/cli studio                 # Firewall tab: decisions, attestation, mediation health

Guarantees (on mediated paths): fail-closed arbitration Β· typed commands Β· per-agent scope Β· signed attestation bound to commit/tree Β· adversarial replay as regression fuelβ€”not an AI red-team product.

See ADR 001.

Live governance dashboard (MCP App)

In supported editors, a real-time dashboard appears automatically as your agent works:

β”Œβ”€ Rigour Governance ──────────────────────────┐
β”‚  Score: 94/100  βœ… PASS                      β”‚
β”‚                                               β”‚
β”‚  14:32:01  rigour_check β†’ FAIL (34/100)       β”‚
β”‚  14:32:03  fix_packet β†’ 8 fixes               β”‚
β”‚  14:32:15  rigour_check β†’ 71/100 (+37)        β”‚
β”‚  14:32:22  rigour_check β†’ βœ… PASS 94/100      β”‚
β”‚                                               β”‚
β”‚  Brain: 47 patterns Β· trend: improving ↑      β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

No extra commands. The dashboard appears when the agent calls Rigour tools. Watch your agent self-heal in real time. Open Firewall in Studio for allow/deny decisions and mediation status (partial until the MCP gateway is fully wired).

What it catches

Category Gates
Security Hardcoded secrets (29+ patterns), SQL injection, XSS, CSRF, prototype pollution, Shannon entropy
Structural File size, cyclomatic complexity, method count, parameter count, nesting depth, TODO/FIXME
AI Drift Hallucinated imports, phantom APIs, context drift, retry loop detection
Governance Agent team isolation, checkpoint supervision, memory DLP
Firewall Out-of-scope writes, undeclared MCP tools, disallowed shell, fail-closed timeouts

AST-based. Not heuristics. TypeScript, JavaScript, Python, Go, Ruby, C#, Java, Kotlin, Rust.

How it works

Agent writes code β†’ Hooks / gates fire β†’ FAIL? β†’ Fix Packet (JSON)
                                           ↓
                                    Agent reads exact instructions
                                           ↓
                                    Agent fixes β†’ PASS βœ“

Mediated run (rigour_run) β†’ typed allowlist β†’ human arbitration (fail-closed)
                                           ↓
                                    execute or deny + evidence

Voluntary rigour_check is a quality workflow, not the security boundary. Hard guarantees require installed hooks/MCP mediation and (for CI) firewall admit.

The Brain β€” learns your codebase

Every scan reinforces patterns. Patterns decay when absent. At strength: 0.9, they promote to hard rules. Your project's own immune system β€” trained locally, zero telemetry.

First week:  catches 12 violations
First month: catches 8 violations  ← learning your patterns
Third month: catches 3 violations  ← your agents have adapted

How it's different

Rigour ESLint β€œAI security agents”
Runs locally, zero telemetry βœ… βœ… often ❌
Learns YOUR codebase (Brain) βœ… ❌ ❌
Agent self-healing (Fix Packets) βœ… ❌ ❌
Deterministic execution firewall βœ… ❌ usually LLM judge
Works offline (GGUF sidecar) βœ… βœ… ❌
AI-native drift detection βœ… ❌ ❌
MCP-native βœ… ❌ varies

Used in production

  • 19,000+ total installs across CLI and MCP
  • Organically forked by Alibaba iFlow
  • OWASP project β€” listed
  • Cursor MCP directory β€” listed

Quick reference

npx rigour-scan                              # zero-config scan
npx @rigour-labs/cli init                    # add gates to your project
npx @rigour-labs/cli hooks init --tool cursor
npx @rigour-labs/cli check                   # run gates
npx @rigour-labs/cli check --deep            # + local AI analysis
npx @rigour-labs/cli check --deep --provider claude -k sk-ant-xxx  # cloud AI
npx @rigour-labs/cli studio                  # monitoring + Firewall tab
npx @rigour-labs/cli firewall adversarial
npx @rigour-labs/cli firewall admit

Architecture

Package Purpose
@rigour-labs/core Gate engine, AST, Fix Packets, Brain, firewall kernel
@rigour-labs/cli init, check, scan, run, studio, firewall
@rigour-labs/mcp MCP server β€” governance tools for agent integration
rigour-scan Zero-config shortcut: npx rigour-scan

Stack: TypeScript strict, web-tree-sitter, Zod, Vitest.


Full docs | Technical Spec | Philosophy | Firewall ADR

MIT Β© Rigour Labs β€” Built by Ashutosh

If Rigour caught something real in your codebase β€” tell us.