PluginBench
MCP Server
Active
MIT

argot MCP Server

io.github.get-tmonier/argot

Lint your code against patterns learned from your own git history—100% local, no LLM.

What is the argot MCP server?

The argot MCP server is a read-only code-review tool that learns patterns from your repository's git history and flags deviations in new code. It runs entirely locally without requiring an LLM, using statistical analysis and an embedded code-embedding model to surface issues like foreign imports, unfamiliar callees, redundant functions, and test weakening.

argot harnesses your repository's own history as a linting baseline. Instead of generic rules, it learns what's idiomatic in your codebase—imports you use, calling patterns, code style, architecture layers—then flags pull requests that diverge from those learned patterns. It surfaces probabilistic findings (foreign imports, rare tokens, misplaced functions, layering violations, test integrity issues) with repository evidence, letting you decide what to accept. Fully offline, no cloud, no account required.

How to install argot

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "argot": {
      "command": "npx",
      "args": [
        "-y",
        "@tmonier/argot",
        "mcp",
        "--repo",
        "."
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • read_context — Retrieve read-only context about the repository's learned patterns and baseline.
  • complete_checks — Run complete checks against patterns learned from git history on a changeset or hunk.

Use cases

  • Flag imports or dependencies your repository has never used before
  • Detect functions that duplicate existing code or belong in different modules
  • Catch test weakening, disabling, or deletion alongside production changes
  • Identify code that breaks learned conventions or architectural layering rules
  • Review pull requests for patterns foreign to your repository's voice and style

argot MCP server FAQ

What is argot?

argot is a code-review tool that learns patterns from your repository's git history and flags deviations in new code. It uses statistical analysis and an embedded code-embedding model to surface issues like foreign imports, unfamiliar callees, redundant functions, and test weakening—all locally, without an LLM.

Is argot free?

Yes. The core is MIT-licensed open source and free to use. It requires no account, cloud service, or subscription.

How do I install argot as an MCP server?

Install via npm: `npm install -g @tmonier/argot`. Then configure your MCP client to use the argot server. The server provides read-only context and complete-check tools for fitted repositories.

Does argot require authentication or internet?

No. argot runs entirely offline and requires no authentication. Set `ARGOT_OFFLINE=1` to prevent any network use; all analysis happens locally with an embedded model.

What languages does argot support?

argot supports 12 languages, including Python, JavaScript, TypeScript, Rust, Go, Java, C#, and others. See the documentation for the complete list.

How do I set up argot in my repository?

Run `argot init` to fit your repository's history locally, then `argot check` to score changes. Commit the generated `argot.toml` and `.argot/` snapshot to your repository so CI and local tools use the same baseline.

README (reference)

Source of truth, from the repository.

<p align="center"> <img src="docs/argot-logo.svg" alt="argot" width="200" /> </p> <p align="center"> <strong>Lint the rules you never wrote down.</strong> </p> <p align="center"> <em>AI writes the code. argot harnesses it with the one thing that can’t hallucinate: <strong>your repo’s own history</strong>.<br/> Statistics, not a second LLM. 100% local. It surfaces the divergence — you decide what to accept.</em> </p> <p align="center"> <a href="https://argot.tmonier.com"><strong>argot.tmonier.com</strong></a> &nbsp;·&nbsp; <a href="https://argot.tmonier.com/docs/">Documentation</a> &nbsp;·&nbsp; <a href="https://argot.tmonier.com/benchmarks">Evidence</a> &nbsp;·&nbsp; <a href="docs/research/README.md">Research log</a> </p> <p align="center"> <a href="https://github.com/get-tmonier/argot/releases/latest"><img src="https://img.shields.io/github/v/release/get-tmonier/argot?color=E67E45" alt="Release" /></a> <a href="https://www.npmjs.com/package/@tmonier/argot"><img src="https://img.shields.io/npm/v/@tmonier/argot?logo=npm" alt="npm" /></a> <a href="https://github.com/get-tmonier/argot/blob/main/LICENSE"><img src="https://img.shields.io/github/license/get-tmonier/argot?color=E67E45" alt="License" /></a> </p> <p align="center"> <img src="https://img.shields.io/badge/rust-single%20static%20binary-DEA584?logo=rust&logoColor=white" alt="One statically-linked Rust binary" /> <img src="https://img.shields.io/badge/100%25-local%20%C2%B7%20no%20cloud%20%C2%B7%20no%20account-2EA043" alt="100% local, no cloud, no account" /> <a href="https://argot.tmonier.com/docs/languages/"><img src="https://img.shields.io/badge/supported%20languages-12-E67E45" alt="12 supported languages" /></a> <a href="https://argot.tmonier.com/benchmarks"><img src="https://img.shields.io/badge/benchmarked%20on-36%20real%20repositories-8B5CF6" alt="Benchmarked on 36 real repositories" /></a> </p> <table align="center"> <tr> <td align="center" valign="middle"> <a href="https://glama.ai/mcp/servers/get-tmonier/argot"><img src="https://glama.ai/mcp/servers/get-tmonier/argot/badges/card.svg" alt="argot MCP server on Glama" width="340" /></a> </td> <td align="center" valign="middle"> <a href="https://argot.tmonier.com/#film"><img src="landing/public/argot-film-poster.jpg" alt="Watch the argot launch film" width="180" /></a> <br/> <em>🎬 <a href="https://argot.tmonier.com/#film">Watch the 45-second launch film</a></em> </td> </tr> </table>

Start with an audit

argot audit needs no prior Argot fit or configuration. It fits a historical base in a temporary worktree, then evaluates the surviving base-to-HEAD net diff. Your working tree is left untouched. It is a review prompt—not a census of who wrote code, or proof that a finding is a defect.

# macOS / Linux
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/get-tmonier/argot/releases/latest/download/argot-installer.sh | sh

cd your-repository
argot audit

Windows: powershell -c "irm https://github.com/get-tmonier/argot/releases/latest/download/argot-installer.ps1 | iex". The npm package is also available as npm install -g @tmonier/argot.

Audit needs usable Git history and supported source. It has no fixed runtime promise. It runs fully offline — the code-embedding model behind the semantic findings ships inside the binary. See Getting started for install and fit details.

If the audit gives you a useful lead, fit the current repository and score the changes you intend to review:

argot init
argot check

Review and commit the generated argot.toml and .argot/ fit snapshot, then merge it into the branch future PRs target before adding a CI workflow. Local tools and CI then use the same learned baseline. CI only reads the base branch snapshot; it never fits, so the initial snapshot PR must be separate from the CI-workflow PR. argot status later recommends a local fit-and-commit refresh only when accepted source, function, or layout surfaces have materially changed. Commit count and age are not refresh triggers by default; [fit] refresh-after is available only as an explicit team backstop. The argot-refresh skill re-audits exclusions, structural paths, and mutes before fitting, so a reorganized repository does not blindly relearn old scope.

flowchart LR
    A["argot init<br/>learn locally"] --> B["review + commit<br/>argot.toml · .argot/"]
    B --> C["local tools + CI<br/>read one baseline"]
    C --> D{"material accepted drift?"}
    D -- no --> C
    D -- yes --> E["argot-refresh<br/>review scope · fit locally"]
    E --> B

The embedding model itself ships inside the binary. Git stores only the repository-specific learned snapshot—typically a few MB to a few tens of MB—so every clone can reproduce the check without retraining or operating a service.

check reports patterns worth reviewing on the selected changeset; a clean result does not prove the change correct or fully idiomatic. Read the Audit, Init and Fit, and Check guides for the exact contracts.

What it surfaces

Type checkers ask if it compiles. argot asks if it’s yours. A clean, type-correct, well-reviewed pull request can still be foreign to the repository it lands in. These are the rules argot ships, every one of them learned from your own history rather than configured by hand:

RuleGroupWhat it flags
foreign-importvoicean import of a dependency the repo has never used
unfamiliar-calleevoicea call to a receiver or callee the repo's code never calls
rare-tokensvoicea token sequence statistically foreign to the repo's voice
conventionvoicea construction that breaks a convention learned from the repo
supersededvoicea pattern this repo has been replacing, or declared migrated away
redundantsemantica new function that duplicates one the repo already has
misplacedsemantica function that looks like it belongs in another module area
layeringarchitecturean internal import that reverses the repo's layer direction
test-deletedintegritya test removed while the code it exercised still exists
test-disabledintegritya skip marker added, or a test gutted, as production changes
test-weakenedintegrityassertions removed, tautologized, or loosened alongside a change
rule-tamperedgovernancea change that removes or weakens a locked rule

Repositories add their own on top — a TOML manifest plus a sandboxed Rhai script under .argot/rules/, with working ones to copy in examples/rules/. No recompilation.

argot is a probabilistic review guardrail, not a correctness oracle. Each finding carries repository evidence. Treat it as a prompt to inspect and make the human decision explicit—never as proof that the code is wrong.

Choose how to run it

The CLI is the complete, explicit changeset check. Other routes have narrower triggers and coverage; none provides a universal acceptance-time check.

RouteExecution classPrerequisites and coverageEvidence status
CLIInvoked by a user or agentRun audit, init, or the full check; fitting is required where the command needs it.CLI/source inventory, 2026-07-22
SkillsInvokedSeven on-demand workflows for a compatible skill host; installation does not schedule commands, configure MCP, or add a hook.Manifest/source inventory, 2026-07-30
MCPPassiveA configured client selects read-only context, hunk, or complete-changeset tools; a fitted repository is required for model-dependent tools. Fitting remains an explicit local CLI/skill workflow.Focused test and source inspection, 2026-07-30
Claude Code pluginAutomatic when configured, plus invoked/passive surfacesIts opt-in pre-write hook, in a fitted repository, asks only when a Write, Edit, or MultiEdit introduces a foreign import. It never blocks and is not a full or end-of-turn check.Manifest/source inspection, 2026-07-22
pre-commitAutomatic when user-configuredScores staged supported files in a fitted repository. The argot-check hook is advisory for findings; argot-check-gate is opt-in for error-severity exits.Manifest inspection, 2026-07-22
GitHub ActionAutomatic when user-configuredScores the configured ref/range in a workflow; it needs checkout history and release-download access. fail-on-hits defaults to false.Action manifest inspection, 2026-07-22

Canonical setup and host details: Claude Code, other agents and MCP, and CI and pre-commit.

Evidence and limits

Current public measurements are detector-specific, not a product-wide accuracy or combined-brief claim. The approved claim manifest records:

  • visible foreign-symbol fixtures: 620/637 — 97.3% across 36 corpora and 12 languages;
  • reinvention fixtures: 545/584 — 93.3% across 31 corpora and 11 languages;
  • placement transplants: 12,899/13,456 — 95.9% across the 22 evaluable corpora and 11 languages (the other nine abstain because their layouts have no separable architecture);
  • layering fixtures: 264/272 — 97.1% across 25 corpora and 12 languages;
  • test-integrity fixtures: 154/164 — 93.9% across 23 corpora and 12 languages.

A catch rate means little without the noise it costs, so both are published. On the same 36 corpora, the voice detectors flag 0.25% of ordinary accepted edits — and 0.00% of the hunks in newly added files, where a repository has the least to say about what belongs.

Each number has a distinct corpus, denominator, and qualifier. The combined briefing/noise result and ordinary-repository timing are not yet measured public claims. See the benchmark methodology and sources.

Argot ships adapters for 12 languages. The five tested release targets are macOS arm64/x64, Linux x64/arm64, and Windows x64. The local analysis path uses statistical, graph, scripted, and embedding evidence; no generative or opinion-forming model decides a finding.

Fit health matters. A repository with shallow, generated, vendored, or otherwise unsuitable history may not produce a useful model. Argot is also least reliable for an incorrect choice made entirely with familiar vocabulary, masked prose, and code outside the selected range. Read Limitations before relying on a specific detector.

Reproducible authored proof

Authored two-commit fixture: argot audit --commits 1 reports one foreign token sequence in an introduced Django-style import. Semantic, architecture, and integrity are unavailable in this development build.

This is an authored fixture, not a wild-case corpus. Its pinned command, version, receipts, checksums, regeneration procedure, and the visual’s non-byte-stable GIF qualification are documented in the proof receipt. The image is a reproducible companion to the auditable Markdown receipt.

Privacy and open source

Argot analyzes source, history, and findings locally. The individual local core is free, MIT-licensed open source, and requires no account or cloud service. Argot has no default telemetry and does not upload source code. No analysis it performs needs a network at all — the code-embedding model behind the semantic findings is compiled into the binary. It can still use network paths for update/version checks, release downloads, or an explicitly configured review/update/CI integration. Set ARGOT_OFFLINE=1 to prevent network use; nothing analytical is lost.

Read the complete privacy and security boundary, security policy, and MIT license.

Contribute

Contributions are welcome. Start with CONTRIBUTING.md, then see the product strategy for the maintained decision record and research log for evidence.

Acknowledgements

Every number argot publishes is measured against the real history of 36 open-source projects, across the twelve supported languages — fastapi, rich, faker, saleor, wagtail, scrapy, hono, ink, faker-js, excalidraw, outline, express, commander, eslint, gh-cli, hugo, ripgrep, bat, guava, junit5, powershell, jellyfin, redis, curl, rocksdb, fmt, homebrew, rubocop, laravel, composer, castle-engine, mORMot2, uos, ideU, MSEide/MSEgui, and dagster.

The benchmark would not exist without them, and we are grateful to their maintainers and contributors. Argot vendors and redistributes none of their code: the harness clones each repository at a pinned SHA, reads its history locally, and ships nothing from it. Each project remains under its own license, held by its own authors. Full list with links, and what argot does commit: benchmarks/README.md.

argot does redistribute one thing. The model behind redundant and misplaced is a 15.6M-parameter static table distilled from jina-embeddings-v2-base-code (Jina AI, Apache-2.0) using the model2vec technique (MinishLab, MIT). Its weights are compiled into the binary and redistributed under Apache-2.0; full terms in NOTICE. argot is not affiliated with either project.

Related MCP servers

DYDynamoi logo

Dynamoi

Active

Music marketing for AI agents: free Smart Links, promotion campaigns, analytics, and distribution.

3
TypeScript
MIT
View repository →

Credential isolation proxy for AI agents — inject secrets at the network boundary, never expose API keys.

13
TypeScript
Apache-2.0
View repository →

Ricardian contracts for AI agents — dual-format, SHA-256 bound, legible by construction.

View repository →

Headless Ghidra MCP server with P-code emulation and multi-console ROM triage.

0
Python
Apache-2.0
View repository →
ANAnyAPI logo

AnyAPI

Active

Hundreds of scraping & data APIs through one key. USD pay-per-request, normalized schemas, failover.

1
Python
Apache-2.0
View repository →
GEGetBirthChart MCP logo

Official MCP server for GetBirthChart astrology calculations.

0
TypeScript
MIT
View repository →