CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
rigour-labs avatar

Rigour

rigour-labs/rigour
209 toolsSTDIOregistry active
Summary

Runs quality gates on your codebase through MCP, exposing 26 tools that let AI agents check for hardcoded secrets, structural issues, and AI-specific drift like hallucinated imports. Gates fire automatically when agents write code and return Fix Packets with exact line numbers and remediation steps agents can consume directly. The Brain learns your codebase patterns over time, promoting recurring violations to hard rules. Works with TypeScript, JavaScript, Python, Go, Ruby, and more through AST analysis. Includes a live dashboard in Claude Desktop and VS Code that shows real-time pass/fail scores as agents iterate. Add it with npx and point your MCP config at @rigour-labs/mcp to get instant governance without leaving the agent loop.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
inference shell
inference shell
create and run specialised agents in minutes
build now →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
inference shell
inference shell
create and run specialised agents in minutes
build now →

Tools

Public tool metadata for what this MCP can expose to an agent.

9 tools
rigour_checkRun quality gate checks on the project. Matches the CLI 'check' command.1 params

Run quality gate checks on the project. Matches the CLI 'check' command.

Parameters* required
cwdstring
Absolute path to the project root.
rigour_explainExplain the last quality gate failures with actionable bullets. Matches the CLI 'explain' command.1 params

Explain the last quality gate failures with actionable bullets. Matches the CLI 'explain' command.

Parameters* required
cwdstring
Absolute path to the project root.
rigour_statusQuick PASS/FAIL check with JSON-friendly output for polling current project state.1 params

Quick PASS/FAIL check with JSON-friendly output for polling current project state.

Parameters* required
cwdstring
Absolute path to the project root.
rigour_get_fix_packetRetrieves a prioritized 'Fix Packet' (v2 schema) containing detailed machine-readable diagnostic data.1 params

Retrieves a prioritized 'Fix Packet' (v2 schema) containing detailed machine-readable diagnostic data.

Parameters* required
cwdstring
Absolute path to the project root.
rigour_record_failureRecord an operation failure to track retry loops and prompt for documentation consult.3 params

Record an operation failure to track retry loops and prompt for documentation consult.

Parameters* required
categorystring
Optional category (deployment, runtime_error, network, etc.). Auto-classified if omitted.
cwdstring
Absolute path to the project root.
errorMessagestring
The error message or type (e.g., 'Deployment failed').
rigour_clear_failureClear failure history for a category after a successful operation or manual fix.2 params

Clear failure history for a category after a successful operation or manual fix.

Parameters* required
categorystring
The failure category to clear (e.g., 'deployment').
cwdstring
Absolute path to the project root.
rigour_rememberStore a persistent instruction or context that the AI should remember across sessions. Use this to persist user preferences, project conventions, or critical instructions that the agent should always follow.3 params

Store a persistent instruction or context that the AI should remember across sessions. Use this to persist user preferences, project conventions, or critical instructions that the agent should always follow.

Parameters* required
cwdstring
Absolute path to the project root.
keystring
A unique key for this memory (e.g., 'user_preferences', 'coding_style', 'critical_instructions').
valuestring
The instruction or context to remember.
rigour_recallRetrieve stored instructions or context. Call this at the start of each session to restore memory. Returns all stored memories if no key specified.2 params

Retrieve stored instructions or context. Call this at the start of each session to restore memory. Returns all stored memories if no key specified.

Parameters* required
cwdstring
Absolute path to the project root.
keystring
Optional. Key of specific memory to retrieve. If omitted, returns all memories.
rigour_forgetRemove a stored memory by key.2 params

Remove a stored memory by key.

Parameters* required
cwdstring
Absolute path to the project root.
keystring
Key of the memory to remove.

Rigour

npm version cli downloads mcp downloads License: MIT MCP Registry OWASP

Your AI agent just tried to commit an AWS secret. Rigour blocked it in <100ms.

Agent Transaction Firewall (v6): treat the agent as an untrusted proposer. Rigour decides—deterministically—what it may write, run, call, and ship. No AI judge on the allow/deny path.

Try it now (zero config)

npx rigour-scan

Works on any repo. No init, no config, no setup. Instant results in your terminal:

  HARDCODED SECRET DETECTED
  AWS_SECRET_ACCESS_KEY found in src/config.ts:23

  + 22 more violations across 847 files (2.1s)

  Score        ████░░░░░░░░░░░░░░░░  34/100
  AI Health    ███░░░░░░░░░░░░░░░░░░  28/100

  Gates:  ✅ file-size  ❌ security  ❌ ast  ✅ deps

  Brain: learned 12 patterns · trend: improving ↑

Add to your AI IDE (30 seconds)

{ "mcpServers": { "rigour": { "command": "npx", "args": ["-y", "@rigour-labs/mcp@latest"] } } }
IDE / AgentMCP ToolsLive DashboardReal-Time Feed
Claude Desktop✅✅ MCP App✅ Logging
VS Code Copilot✅✅ MCP App✅ Logging
ChatGPT✅✅ MCP App✅ Logging
Goose✅✅ MCP App✅ Logging
Claude Code✅—✅ Logging
Cursor✅—✅ Logging
Cline✅—✅ Logging
Windsurf✅—✅ Logging
Codex✅—✅ Logging

Then install hooks so writes are checked in real time:

npx @rigour-labs/cli hooks init --tool cursor   # or claude, cline, windsurf
# or via MCP: rigour_hooks_init

Does the firewall run automatically?

Short answer: quality gates + DLP + mediated rigour_run paths run when MCP/hooks are installed. It does not yet sit in front of every third-party MCP tool (GitHub/Slack/etc.)—that gateway is designed but not the default proxy.

SurfaceAutomatic once installed?What you get
MCP server (@rigour-labs/mcp)Yes for Rigour tools the agent callsrigour_check, Fix Packets, memory DLP, agent register, Studio events
rigour_run / rigour_run_supervisedYes when those tools are usedTyped argv allowlist (no free-form shell: true), fail-closed human arbitration (timeout = deny), one-time Studio token
IDE hooks (Cursor/Claude/Cline/Windsurf)Yes after hooks initPer-write checks (secrets, imports, size, protected paths). If agents are registered, set RIGOUR_AGENT_ID so scope binds to the writer (fail-closed; no union-allow)
rigour_agent_registerYes when calledRejects **/* / sensitive globs unless operator scopes or RIGOUR_ALLOW_AGENT_SCOPE_AUTHORITY=1
CLI firewallOn demand / CIfirewall adversarial, firewall transact, firewall admit
Third-party MCP proxyNot yetCapability broker + McpGateway interfaces exist; Rigour is not yet a MITM for all MCP servers
Agent proposes action
        ↓
Hooks / MCP mediation (when on the path)
        ↓
Deterministic deny/allow + rule id
        ↓
Studio evidence  ·  CI attestation (admit)

Agent Transaction Firewall

npx @rigour-labs/cli firewall status
npx @rigour-labs/cli firewall adversarial   # deterministic corpus — unexpected allows fail CI
npx @rigour-labs/cli firewall transact --agent <id> --scope 'packages/foo/**'
npx @rigour-labs/cli firewall admit         # CI: valid attestation + PASS + bound git tree
npx @rigour-labs/cli studio                 # Firewall tab: decisions, attestation, mediation health

Guarantees (on mediated paths): fail-closed arbitration · typed commands · per-agent scope · signed attestation bound to commit/tree · adversarial replay as regression fuel—not an AI red-team product.

See ADR 001.

Live governance dashboard (MCP App)

In supported editors, a real-time dashboard appears automatically as your agent works:

┌─ Rigour Governance ──────────────────────────┐
│  Score: 94/100  ✅ PASS                      │
│                                               │
│  14:32:01  rigour_check → FAIL (34/100)       │
│  14:32:03  fix_packet → 8 fixes               │
│  14:32:15  rigour_check → 71/100 (+37)        │
│  14:32:22  rigour_check → ✅ PASS 94/100      │
│                                               │
│  Brain: 47 patterns · trend: improving ↑      │
└───────────────────────────────────────────────┘

No extra commands. The dashboard appears when the agent calls Rigour tools. Watch your agent self-heal in real time. Open Firewall in Studio for allow/deny decisions and mediation status (partial until the MCP gateway is fully wired).

What it catches

CategoryGates
SecurityHardcoded secrets (29+ patterns), SQL injection, XSS, CSRF, prototype pollution, Shannon entropy
StructuralFile size, cyclomatic complexity, method count, parameter count, nesting depth, TODO/FIXME
AI DriftHallucinated imports, phantom APIs, context drift, retry loop detection
GovernanceAgent team isolation, checkpoint supervision, memory DLP
FirewallOut-of-scope writes, undeclared MCP tools, disallowed shell, fail-closed timeouts

AST-based. Not heuristics. TypeScript, JavaScript, Python, Go, Ruby, C#, Java, Kotlin, Rust.

How it works

Agent writes code → Hooks / gates fire → FAIL? → Fix Packet (JSON)
                                           ↓
                                    Agent reads exact instructions
                                           ↓
                                    Agent fixes → PASS ✓

Mediated run (rigour_run) → typed allowlist → human arbitration (fail-closed)
                                           ↓
                                    execute or deny + evidence

Voluntary rigour_check is a quality workflow, not the security boundary. Hard guarantees require installed hooks/MCP mediation and (for CI) firewall admit.

The Brain — learns your codebase

Every scan reinforces patterns. Patterns decay when absent. At strength: 0.9, they promote to hard rules. Your project's own immune system — trained locally, zero telemetry.

First week:  catches 12 violations
First month: catches 8 violations  ← learning your patterns
Third month: catches 3 violations  ← your agents have adapted

How it's different

RigourESLint“AI security agents”
Runs locally, zero telemetry✅✅often ❌
Learns YOUR codebase (Brain)✅❌❌
Agent self-healing (Fix Packets)✅❌❌
Deterministic execution firewall✅❌usually LLM judge
Works offline (GGUF sidecar)✅✅❌
AI-native drift detection✅❌❌
MCP-native✅❌varies

Used in production

  • 19,000+ total installs across CLI and MCP
  • Organically forked by Alibaba iFlow
  • OWASP project — listed
  • Cursor MCP directory — listed

Quick reference

npx rigour-scan                              # zero-config scan
npx @rigour-labs/cli init                    # add gates to your project
npx @rigour-labs/cli hooks init --tool cursor
npx @rigour-labs/cli check                   # run gates
npx @rigour-labs/cli check --deep            # + local AI analysis
npx @rigour-labs/cli check --deep --provider claude -k sk-ant-xxx  # cloud AI
npx @rigour-labs/cli studio                  # monitoring + Firewall tab
npx @rigour-labs/cli firewall adversarial
npx @rigour-labs/cli firewall admit

Architecture

PackagePurpose
@rigour-labs/coreGate engine, AST, Fix Packets, Brain, firewall kernel
@rigour-labs/cliinit, check, scan, run, studio, firewall
@rigour-labs/mcpMCP server — governance tools for agent integration
rigour-scanZero-config shortcut: npx rigour-scan

Stack: TypeScript strict, web-tree-sitter, Zod, Vitest.


Full docs | Technical Spec | Philosophy | Firewall ADR

MIT © Rigour Labs — Built by Ashutosh

If Rigour caught something real in your codebase — tell us.

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
inference shell
inference shell
create and run specialised agents in minutes
build now →
Categories
AI & LLM Tools
Registryactive
Package@rigour-labs/mcp
TransportSTDIO
UpdatedMar 18, 2026
View on GitHub

Related AI & LLM Tools MCP Servers

View all →
kirbah avatar
Kirbah Mcp Youtube

ai.smithery/kirbah-mcp-youtube

Provide token-optimized, structured YouTube data to enhance your LLM applications. Access efficien…
19
delimit-ai avatar
Delimit

delimit-ai/delimit

One workspace for every AI coding assistant. Shared tasks, memory, and governance.
19
mkxultra avatar
Ai Cli Mcp

mkxultra/ai-cli-mcp

Run Claude, Codex, Gemini, Forge, and OpenCode CLIs through MCP with background jobs
18
othervibes avatar
Mcp As A Judge

othervibes/mcp-as-a-judge

MCP as a Judge: a behavioral MCP that strengthens AI coding assistants via explicit LLM evaluations
17
razee4315 avatar
NetLogo MCP

razee4315/netlogo-mcp

Create, run, and analyze NetLogo agent-based models through natural conversation
17
abhigyan-shekhar avatar
Waggle Mcp

abhigyan-shekhar/waggle-mcp

Persistent graph-backed conversational memory for AI agents.
16