Rigour

listing.by

Run quality gates on AI coding agent output: catch leaked secrets, fake imports and bugs while the agent writes code.

state.local.long (state.local.title)listing.badge.runs_with

listing.install

listing.local.explain

npx -y @rigour-labs/mcp

listing.local.needs listing.local.note

listing.share.h

listing.share.p_local

mcp.tc/i/rigour

listing.about

Rigour checks the code an AI coding agent writes, while it writes it. It looks for leaked secrets, imports of packages that do not exist and bugs it can prove, and it asks the agent to fix them before moving on. It also keeps lessons from fixed mistakes so agents are told about them before writing similar code.

The MCP server runs locally over stdio through the npm package @rigour-labs/mcp, started with npx. It works with Claude Code, Cursor, Codex, Cline and Windsurf. No sign-in is needed. A model API key is only needed for reviewing code written without an agent and for the pull request bot.

listing.can

  • Catch leaked secrets and nonexistent imports as the agent edits code
  • Run lint, test and build checks on current changes
  • Review a change or branch before opening a pull request
  • Persist lessons from fixed mistakes for future agent sessions
  • Point the agent at risky changes before it reports done

listing.tools

listing.notools.local

listing.prompts

  • Run Rigour on my current changes before I open a pull request

  • Check this branch for leaked secrets and imports that don't exist

  • Review the risky parts of my last edit and fix what Rigour finds

  • Run the quality gates for this repository

listing.setup.h

listing.setup.local

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport stdio rigour -- npx -y @rigour-labs/mcp
  1. Start Claude Code and type /mcp. rigour should show as connected.

Add --scope user to make it available in every project.

Claude Desktop

  1. Open Settings → Developer → Edit Config. It opens claude_desktop_config.json. Add:
claude_desktop_config.json
{
  "mcpServers": {
    "rigour": {
      "command": "npx",
      "args": [
        "-y",
        "@rigour-labs/mcp"
      ]
    }
  }
}
  1. Save the file and restart Claude Desktop.

Needs Node.js on your computer. The file lives in ~/Library/Application Support/Claude/ on macOS and %APPDATA%\Claude\ on Windows.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "rigour": {
      "command": "npx",
      "args": [
        "-y",
        "@rigour-labs/mcp"
      ]
    }
  }
}

Needs Node.js on your computer.

VS Code

Or from a terminal:

code --add-mcp '{"name":"rigour","type":"stdio","command":"npx","args":["-y","@rigour-labs/mcp"]}'

Or commit it to the repo in .vscode/mcp.json:

.vscode/mcp.json
{
  "servers": {
    "rigour": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@rigour-labs/mcp"
      ]
    }
  }
}

Needs Node.js on your computer.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "rigour": {
      "command": "npx",
      "args": [
        "-y",
        "@rigour-labs/mcp"
      ]
    }
  }
}
  1. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf.

Codex

codex mcp add rigour -- npx -y @rigour-labs/mcp

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.rigour]
command = "npx"
args = ["-y", "@rigour-labs/mcp"]

Needs Node.js on your computer.

Gemini CLI

gemini mcp add rigour npx -- -y @rigour-labs/mcp

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients that start local servers accept this shape:

{
  "mcpServers": {
    "rigour": {
      "command": "npx",
      "args": [
        "-y",
        "@rigour-labs/mcp"
      ]
    }
  }
}

Zed puts servers under context_servers in its settings, with the same command, args and env fields.

Needs Node.js on your computer.

listing.faq

Can I paste mcp.tc/i/rigour into my MCP client?

No. Rigour runs on your own computer, started by your client, so it has no web address to connect to. The quick link is the page to share; the install command is npx -y @rigour-labs/mcp.

Does Rigour need an API key?

No. It doesn't declare any keys or environment variables. It runs with your user account's permissions, so check what its tools can reach.

Is Rigour a remote or a local server?

Local. Your client starts it as a process on your computer with npx -y @rigour-labs/mcp, which needs Node.js.

What can Rigour do?

You can catch leaked secrets and nonexistent imports as the agent edits code, run lint, test and build checks on current changes and review a change or branch before opening a pull request.

Which clients can use it?

Any client that starts local servers: Claude Code, Claude Desktop, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. claude.ai and ChatGPT only connect to remote servers.

Who wrote this page?

mcp.tc's robot read Rigour's public metadata (its package and repository pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

listing.em.h

listing.em.lead_local listing.em.how

listing.em.badge

em.prev_lightem.prev_dark
Markdown
[![Rigour on mcp.tc](https://mcp.tc/i/rigour/badge.svg)](https://mcp.tc/i/rigour)
HTML
<a href="https://mcp.tc/i/rigour"><img src="https://mcp.tc/i/rigour/badge.svg" alt="Rigour on mcp.tc" height="20"></a>

listing.em.badge_note

listing.em.widget

HTML
<script src="https://mcp.tc/w/rigour.js" async></script>

listing.em.widget_note

iframe

HTML
<iframe src="https://mcp.tc/embed/rigour" title="Rigour on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

listing.em.iframe_note

JSON

listing.em.json_local

https://mcp.tc/i/rigour.json

listing.em.fields

listing.disclaimer_checked