io.github.rigour-labs/rigour
NPM · @RIGOUR-LABS/MCP · SCANNED SEP 29
Quality gates for AI agents. Lint, test, build checks with memory persistence.
Available components
Recent critical change
CVE-2026-41242 affects this package (23 Sept 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security23
- Malware scan not yet available for this package.Unverified
- CVE check failed: an unpatched critical CVE affects this package; the score is capped at 0. See how to fix → View diagnostics → Fail
- No install/post-install scripts declared.Pass
- 135 of 335 dependencies flagged as unhealthy (10 deprecated). View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to rigour-labs/rigour). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 0 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability86
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2901 tokens (~116/item across 25 items; 24 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 25 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.rigour-labs/rigour MCP server?
io.github.rigour-labs/rigour runs locally as an npm package, launched with npx -y @rigour-labs/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @rigour-labs/mcp
claude mcp add rigour-labs-rigour -- npx -y @rigour-labs/mcp
{
"mcpServers": {
"rigour-labs-rigour": {
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
} {
"servers": {
"rigour-labs-rigour": {
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
} codex mcp add rigour-labs-rigour -- npx -y @rigour-labs/mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"rigour-labs-rigour": {
"type": "local",
"command": [
"npx",
"-y",
"@rigour-labs/mcp"
],
"enabled": true
}
}
} openclaw mcp add rigour-labs-rigour --command npx --arg -y --arg @rigour-labs/mcp
mcp_servers:
rigour-labs-rigour:
command: "npx"
args: ["-y", "@rigour-labs/mcp"] {
"McpServers": {
"rigour-labs-rigour": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@rigour-labs/mcp"
]
}
}
} assistant mcp add rigour-labs-rigour -t stdio -c npx -a -y @rigour-labs/mcp
{
"mcpServers": {
"rigour-labs-rigour": {
"command": "npx",
"args": [
"-y",
"@rigour-labs/mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 0
- Malware scan: pass → unverified ▼ security
- Security disclosure: fail → unverified ▼ functional
- Stability: pass → 0.80 functional
- Package version: 6.2.4 → 6.2.5 functional
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- Package version: 6.2.2 → 6.2.4 functional
- Package version: 6.2.2 → 6.2.3 functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 −91
- CVE-2026-41242 affects this package: high ▼ critical
- Score status: scored → failed ▼ critical
- Known CVEs: CVE check failed: an unpatched critical CVE affects this package; the score is capped at 0. critical
- GHSA-rgj7-g3m4-5g8c no longer affects this package ▲ security
- GHSA-f88m-g3jw-g9cj no longer affects this package ▲ security
- CVE-2026-3449 no longer affects this package ▲ security
- 22 Sept 26 +91
- GHSA-f88m-g3jw-g9cj affects this package: high ▼ security
- GHSA-rgj7-g3m4-5g8c affects this package: high ▼ security
- CVE-2026-3449 affects this package: high ▼ security
- CVE-2026-41242 no longer affects this package ▲ security
- Known CVEs: CVE check failed: a known high-severity CVE affects sharp 0.32.6, reached via @rigour-labs/core > @xenova/transformers > sharp. A fixed version is available. security
- Score status: failed → scored ▲ functional
- Stability: pass → 0.80 functional
- 21 Sept 26 0
- Stability: 0.97 → pass security
- 18 Sept 26 0
- Stability: pass → 0.90 functional
- 17 Sept 26 0
- Stability: 0.97 → pass security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Analysed npm/@rigour-labs/mcp@6.2.5
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | rigour-labs/rigour |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/rigour-labs/rigour/.github/workflows/pipeline.yml@refs/heads/main |
| Rekor log index | 2996675656 |
| Predicate type | SLSA build provenance https://slsa.dev/provenance/v1 |
| Subject digest | sha512:c1b7388c503be1655d801d8e63b2331f0e09b17421d8b501a7c13a38a462c8f27c94be27f477bcb96f48bc41249dbfd2a638c1baed70515fae732f905 |
Background: How many MCP packages publish verified provenance →
Vulnerabilities 26 findings
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-vpq2-c234-7xj6 | CVE-2026-3449 | low | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L | yes |
| GHSA-2pr8-phx7-x9h3 | CVE-2026-44294 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
| GHSA-66ff-xgx4-vchm | CVE-2026-44293 | high | yes | |
| GHSA-685m-2w69-288q | CVE-2026-44289 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-75px-5xx7-5xc7 | CVE-2026-44291 | high | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H | yes |
| GHSA-f38q-mgvj-vph7 | CVE-2026-54269 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
| GHSA-fx83-v9x8-x52w | CVE-2026-44292 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N | yes |
| GHSA-jggg-4jg4-v7c6 | CVE-2026-45740 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
| GHSA-jvwf-75h9-cwgg | CVE-2026-44290 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-q6x5-8v7m-xcrf | CVE-2026-44288 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N | yes |
| GHSA-wcpc-wj8m-hjx6 | CVE-2026-48712 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-xq3m-2v4x-88gg | CVE-2026-41242 | critical | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | yes |
| GHSA-f88m-g3jw-g9cj | high | yes | ||
| GHSA-rgj7-g3m4-5g8c | high | yes | ||
| GHSA-23hp-3jrh-7fpw | CVE-2026-59873 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-34x7-hfp2-rc4v | CVE-2026-24842 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N | yes |
| GHSA-83g3-92jg-28cx | CVE-2026-26960 | high | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N | yes |
| GHSA-8qq5-rm4j-mr97 | CVE-2026-23745 | high | yes | |
| GHSA-8x88-c5mf-7j5w | CVE-2026-59874 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-9ppj-qmqm-q256 | CVE-2026-31802 | high | yes | |
| GHSA-gvwx-54wh-qm9j | CVE-2026-59875 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
| GHSA-qffp-2rhf-9h96 | CVE-2026-29786 | high | yes | |
| GHSA-r292-9mhp-454m | CVE-2026-73566 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-r6q2-hw4h-h46w | CVE-2026-23950 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L | yes |
| GHSA-vmf3-w455-68vh | CVE-2026-53655 | medium | yes | |
| GHSA-w8wr-v893-vjvp | CVE-2026-59871 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
Background: What a vulnerability scan can and cannot prove →
Dependencies 335 packages
| Packages resolved | 335 |
|---|---|
| Deprecated | 10 |
| Stale | 130 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
rigour_agent_deregister ~67
Deregister an agent from the multi-agent session. Use when an agent completes its work or needs to release its scope for another agent.
| Name | Type | Req | Description |
|---|---|---|---|
| agentId | string | yes | ID of the agent to deregister. |
| cwd | string | yes | Absolute path to the project root. |
No output schema declared.
No examples provided.
rigour_agent_register ~116
Register an agent in a multi-agent session. Use this at the START of agent execution to claim task scope and enable cross-agent conflict detection. Required for Agent Team Governance.
| Name | Type | Req | Description |
|---|---|---|---|
| agentId | string | yes | Unique identifier for this agent (e.g., 'agent-a', 'opus-frontend'). |
| cwd | string | yes | Absolute path to the project root. |
| taskScope | array | yes | Glob patterns defining the files/directories this agent will work on (e.g., ['src/api/**', 'tests/api/**']). |
No output schema declared.
No examples provided.
rigour_cache_stats ~53
Returns detailed performance stats across all 4 cache layers (exact hits, semantic hits, partial hits, misses, hit rate, tokens served from cache).
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
No output schema declared.
No examples provided.
rigour_check ~309
Run quality gate checks on the project. MUST be called before declaring any coding task complete. Checks code complexity, file size, required docs, security patterns, and more. Returns PASS or FAIL with details. **Always show the user the headline summary from this tool's output** — it tells them what Rigour caught. If FAIL, call rigour_get_fix_packet for structured fix instructions with exact file locations and step-by-step remediation.
| Name | Type | Req | Description |
|---|---|---|---|
| apiBaseUrl | string | – | Custom API base URL for self-hosted/proxy deep endpoints. |
| apiKey | string | – | Optional cloud API key for deep analysis. |
| cwd | string | yes | Absolute path to the project root. |
| deep | string | – | Deep mode: 'off' (default), 'quick' (deep enabled with lite model), 'full' (deep enabled, combine with pro=true for full deep model). |
| files | array | – | Optional file paths (relative to cwd) to limit scan scope for both deterministic and deep checks. |
| modelName | string | – | Override cloud model name for deep analysis. |
| pro | boolean | – | Use full deep model (Qwen2.5-Coder-1.5B) instead of lite (Qwen2.5-Coder-0.5B) when deep is enabled. |
| provider | string | – | Cloud provider for deep analysis (claude, openai, gemini, groq, mistral, together, deepseek, ollama, etc.). |
No output schema declared.
No examples provided.
rigour_check_pattern ~197
CALL THIS BEFORE creating any new function, component, hook, or class. Checks if it already exists in the codebase (prevents duplication), checks for known security vulnerabilities, and BLOCKS writes to protected paths (.github/, CI/CD configs, rigour.yml). Always pass the target file path.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| file | string | – | Target file path (relative to cwd) where the code will be written. Used to enforce protected path rules — writes to .github/, rigour.yml, etc. will be BLOCKED. |
| intent | string | – | What the code is for (e.g., 'format dates', 'user authentication'). |
| name | string | yes | The name of the function, class, or component you want to create. |
| type | string | – | The type of pattern (e.g., 'function', 'component', 'hook', 'type'). |
No output schema declared.
No examples provided.
rigour_checkpoint ~202
Record a quality checkpoint during long-running agent execution. Use periodically (every 15-30 min) to enable drift detection, quality monitoring, and compact subagent handoffs. Triggers incremental pattern index refresh when filesChanged is provided. Essential for GPT-5.3 coworking mode — call BEFORE rigour_handoff to compress context under 2K tokens.
| Name | Type | Req | Description |
|---|---|---|---|
| agentId | string | – | Optional agent ID for checkpoint packet binding. |
| cwd | string | yes | Absolute path to the project root. |
| filesChanged | array | – | List of files modified since last checkpoint. Triggers incremental index refresh. |
| progressPct | number | yes | Estimated progress percentage (0-100). |
| qualityScore | number | yes | Self-assessed quality score (0-100). Be honest - artificially high scores trigger drift detection. |
| summary | string | yes | Brief description of work done since last checkpoint. |
| taskId | string | – | Optional task ID for checkpoint metrics. |
No output schema declared.
No examples provided.
rigour_context_explain ~83
Audits why specific files/services were included or excluded, cache hit/miss status, invalidation reasons, and prior agent requests.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| target | string | yes | File path, service name, or query term to explain. |
| taskId | string | – | Optional Task ID to restrict audit trace. |
No output schema declared.
No examples provided.
rigour_context_scope ~162
CALL THIS BEFORE reading source files. Returns a minimal editScope (3-10 files) with signatures from the pattern index instead of full file bodies. Uses semantic search when embeddings are available. If index is missing, instructs to call rigour_index first. Highest-impact token saver in the Rigour protocol.
| Name | Type | Req | Description |
|---|---|---|---|
| agentId | string | – | Optional agent ID for context telemetry attribution. |
| cwd | string | yes | Absolute path to the project root. |
| limit | number | – | Maximum number of pattern matches to return (default: 10). |
| query | string | yes | Natural-language description of what you need to work on (e.g. 'add priority field to task service'). |
| taskId | string | – | Optional task ID for context telemetry attribution. |
No output schema declared.
No examples provided.
rigour_context_stats ~71
Returns context retrieval efficiency, candidate tokens vs returned tokens, potential avoided tokens, cache hit rate, and repeated reads prevented.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| taskId | string | – | Optional Task ID (e.g. 'CTP-142') to filter statistics. |
No output schema declared.
No examples provided.
rigour_explain ~59
Explain WHY quality gates failed in human-readable language. Use this to understand the reasoning behind each violation before fixing. For machine-readable fix instructions, use rigour_get_fix_packet instead.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
No output schema declared.
No examples provided.
rigour_forget ~43
Remove a stored memory by key.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| key | string | yes | Key of the memory to remove. |
No output schema declared.
No examples provided.
rigour_get_fix_packet ~118
Call this after rigour_check returns FAIL. Returns a bounded, prioritized page of violations with file locations and fix instructions. Use next_offset from the response to read further pages, then re-run rigour_check. Report only fixes that were actually verified.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| limit | integer | – | Violations per page (default 5, maximum 10). |
| offset | integer | – | Zero-based violation offset. Start at 0, then use the next offset in the response. |
No output schema declared.
No examples provided.
rigour_handoff ~130
Handoff task to another agent in a multi-agent workflow. Use when delegating a subtask or completing your scope. Enables verified handoff governance.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | Additional context for the receiving agent. |
| cwd | string | yes | Absolute path to the project root. |
| filesInScope | array | – | Files relevant to the handoff. |
| fromAgentId | string | yes | ID of the agent initiating the handoff. |
| taskDescription | string | yes | Description of the task being handed off. |
| toAgentId | string | yes | ID of the agent receiving the handoff. |
No output schema declared.
No examples provided.
rigour_handoff_accept ~88
Accept a pending handoff from another agent. Use to formally acknowledge receipt of a task and verify you are the intended recipient.
| Name | Type | Req | Description |
|---|---|---|---|
| agentId | string | yes | ID of the accepting agent (must match toAgentId in the handoff). |
| cwd | string | yes | Absolute path to the project root. |
| handoffId | string | yes | ID of the handoff to accept. |
No output schema declared.
No examples provided.
rigour_hooks_check ~212
Run the fast hook checker on specific files. Same checks that run inside IDE hooks (Claude, Cursor, Cline, Windsurf). Catches: hardcoded secrets, hallucinated imports, command injection, file size. Completes in <100ms. NEW: Pass 'text' param for DLP mode — scans user input for credentials (AWS keys, API tokens, database URLs, private keys, JWTs) before agent processing.
| Name | Type | Req | Description |
|---|---|---|---|
| agent | string | – | Agent name for DLP audit trail (e.g., 'claude', 'cursor'). Only used in DLP mode. |
| cwd | string | yes | Absolute path to the project root. |
| files | array | – | List of file paths (relative to cwd) to check. |
| text | string | – | Text to scan for credentials (DLP mode). When provided, scans text instead of files. Use this to validate user input before agent processing. |
| timeout | number | – | Optional timeout in milliseconds (default: 5000). |
No output schema declared.
No examples provided.
rigour_hooks_init ~155
Generate hook configs for AI coding tools (Claude, Cursor, Cline, Windsurf). Installs real-time quality checks and non-blocking DLP credential warnings by default. Pass dlp=false to disable DLP hooks only.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| dlp | boolean | – | Generate DLP hooks for pre-input credential warnings (default: true). Set false to skip DLP hooks. |
| dryRun | boolean | – | Preview changes without writing files (default: false). |
| force | boolean | – | Overwrite existing hook files (default: false). |
| tool | string | yes | Target tool: 'claude', 'cursor', 'cline', or 'windsurf'. |
No output schema declared.
No examples provided.
rigour_index ~135
Build or update the Rigour pattern index (.rigour/patterns.json). CALL THIS when the index is missing or stale — before rigour_context_scope or rigour_check_pattern. One AST pass extracts functions, classes, routes, and signatures for reuse. Use semantic=true for embedding-based search.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| force | boolean | – | Force a full rebuild instead of incremental update. Default: false. |
| output | string | – | Custom path for the index file. |
| semantic | boolean | – | Generate semantic embeddings for better matching (requires Transformers.js). Default: false. |
No output schema declared.
No examples provided.
rigour_recall ~94
Load project memory and stored conventions. CALL THIS at the START of every coding task (before reading files) to restore team decisions, naming conventions, and architectural preferences. Returns index health status and uses semantic cache on repeat calls — second recall with the same key is served from cache.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| key | string | – | Optional. Key of specific memory to retrieve. |
No output schema declared.
No examples provided.
rigour_remember ~147
Store a persistent instruction or context that the AI should remember across sessions. Use this to persist user preferences, project conventions, or critical instructions. IMPORTANT: You must provide both 'key' (a short snake_case identifier) and 'value' (the full text to remember).
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| key | string | yes | A short snake_case identifier for this memory, e.g. 'api_response_format', 'naming_convention', 'testing_strategy'. This is used to retrieve the memory later. |
| value | string | yes | The full instruction or convention text to persist. This is the content that will be recalled in future sessions. |
No output schema declared.
No examples provided.
rigour_review ~102
Perform a high-fidelity code review on a pull request diff. Analyzes changed files using all active quality gates.
| Name | Type | Req | Description |
|---|---|---|---|
| branch | string | – | The branch containing the changes. |
| cwd | string | yes | Absolute path to the project root. |
| diff | string | yes | The git diff content to analyze. |
| files | array | – | List of filenames that were changed. |
| repository | string | – | Full repository name (e.g., 'owner/repo'). |
No output schema declared.
No examples provided.
rigour_run ~85
Execute a command under Rigour supervision. This tool can be INTERCEPTED and ARBITRATED by the Governance Studio.
| Name | Type | Req | Description |
|---|---|---|---|
| command | string | yes | The command to run (e.g., 'npm test', 'pytest'). |
| cwd | string | yes | Absolute path to the project root. |
| silent | boolean | – | If true, hides the command output from the agent. |
No output schema declared.
No examples provided.
rigour_run_supervised ~137
Run a command under FULL Supervisor Mode. Iteratively executes the command, checks quality gates, and returns fix packets until PASS or max retries reached. Use this for self-healing agent loops.
| Name | Type | Req | Description |
|---|---|---|---|
| command | string | yes | The agent command to run (e.g., 'claude "fix the bug"', 'aider --message "refactor auth"'). |
| cwd | string | yes | Absolute path to the project root. |
| dryRun | boolean | – | If true, simulates the loop without executing the command. Useful for testing gate checks. |
| maxRetries | number | – | Maximum retry iterations (default: 3). |
No output schema declared.
No examples provided.
rigour_security_audit ~39
Runs a live security audit (CVE check) on the project dependencies.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
No output schema declared.
No examples provided.
rigour_task_cost ~75
Returns both verified actual model usage/cost (from Cursor Admin API or imported CSV) and Rigour estimated avoided context/cost USD.
| Name | Type | Req | Description |
|---|---|---|---|
| cwd | string | yes | Absolute path to the project root. |
| taskId | string | – | Optional Task ID (e.g. 'CTP-142') to filter cost stats. |
No output schema declared.
No examples provided.
What is the io.github.rigour-labs/rigour MCP server?
io.github.rigour-labs/rigour is an MCP server listed in the public MCP registry as io.github.rigour-labs/rigour. Quality gates for AI agents. Lint, test, build checks with memory persistence. This page covers its npm package (@rigour-labs/mcp).
What tools does the io.github.rigour-labs/rigour MCP server expose?
io.github.rigour-labs/rigour exposes 24 tools: rigour_check, rigour_explain, rigour_get_fix_packet, rigour_remember, rigour_recall, and 19 more. Their descriptions and schemas cost roughly 2,879 tokens of context every time the server is loaded.
Is the io.github.rigour-labs/rigour MCP server still maintained?
io.github.rigour-labs/rigour is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.rigour-labs/rigour MCP server under?
io.github.rigour-labs/rigour declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.