PluginBench
MCP Server
Active
MIT

io.github.rigour-labs/rigour MCP Server

io.github.rigour-labs/rigour

Quality gates and memory persistence for AI coding agents—lint, test, and build checks with evidence-backed learning.

What is the io.github.rigour-labs/rigour MCP server?

Rigour is a local-first engineering intelligence layer that gives AI coding agents deterministic quality gates, structural code context, and persistent learning from verified outcomes. It connects code, agent actions, decisions, proof, and lessons into one evidence-backed system, turning agent work into reusable knowledge for future tasks.

Rigour enforces quality boundaries around agent work through lint, test, and build checks while maintaining a persistent memory of verified outcomes. It provides agents with minimal, explainable context; records evidence from hooks and MCP calls; and learns rules only after deterministic verification. Teams can use local SQLite or PostgreSQL for shared knowledge, and agents receive Fix Packets when work fails checks.

How to install io.github.rigour-labs/rigour

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "rigour": {
      "command": "npx",
      "args": [
        "-y",
        "@rigour-labs/mcp"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • rigour-context — Requests the smallest explainable scope before an agent reads code.
  • rigour-verify — Closes a change with proof and a Fix Packet repair loop.
  • rigour-handoff — Transfers verified state without replaying an entire session.
  • rigour-review — Sends agents back on proven or security findings for review.
  • rigour-scan — Runs local quality, security, and AI-drift checks on a repository.
  • rigour-learn — Turns a fix commit into a rule for the same bug class.
  • Agent Transaction Firewall — Mediates high-impact MCP tools with per-agent scopes, typed allowlists, and signed execution receipts.

Use cases

  • Prevent agents from rediscovering the codebase on every task by providing structural retrieval and validated lessons
  • Enforce deterministic quality gates (lint, test, build checks) before agent changes are accepted
  • Learn and enforce rules from bug fixes to catch the same issues automatically in future work
  • Trace agent decisions from context recommendation through code change, verification, and outcome
  • Set up team knowledge sharing with PostgreSQL while maintaining local-first SQLite operation

io.github.rigour-labs/rigour MCP server FAQ

What is Rigour?

Rigour is a local-first engineering intelligence layer that gives AI agents deterministic quality gates, minimal explainable context, and persistent learning from verified outcomes. It records evidence from agent work and turns verified lessons into reusable knowledge.

Is Rigour free?

Yes. Rigour works fully in local-only mode with SQLite and requires no account or hosted service. PostgreSQL and pgvector are optional for team features.

How do I install Rigour in Cursor or Claude?

Add Rigour as an MCP server in your config: {"mcpServers": {"rigour": {"command": "npx", "args": ["-y", "@rigour-labs/mcp@latest"]}}}. For Cursor, run `npx @rigour-labs/cli hooks init --tool cursor` to add focused slash commands.

What authentication is required?

None for local-only mode. Team features with PostgreSQL require a database URL; no external account is needed.

What checks does Rigour run?

Rigour runs local quality, security, and AI-drift checks. The semantic_bugs gate traces values across files to prove bugs. Learned rules are created from verified fixes and appear in .rigour/rules/.

Can Rigour work offline?

Yes. Local enforcement and evidence capture continue when team storage is unavailable; changes are queued for sync when the database returns.

README (reference)

Source of truth, from the repository.

Rigour

npm version npm downloads License: MIT MCP Registry

Your coding agents write code. Rigour makes the codebase learn.

Rigour is a local-first engineering intelligence layer for coding agents. It gives agents the smallest useful context, enforces deterministic boundaries around observable work, and turns verified outcomes into reusable knowledge for the next task.

It is not another chat wrapper or a prettier linter dashboard. Rigour connects code, agent actions, decisions, proof, and learning into one evidence-backed system.

npx rigour-scan

▶ Watch Rigour in action

Run this in any repository to see the first signal. No account or hosted service required.

Why teams use Rigour

PainRigour’s answerWhat you can see
Agents rediscover the codebase every taskStructural retrieval, patterns, memory, and validated lessons narrow the contextWhy files were selected, excluded, reused, or invalidated
Agents move quickly without enough proofDeterministic gates, hooks, DLP, scoped execution, and Fix PacketsThe decision, rule, evidence, and resulting repair loop
Good work disappears between sessionsEvidence from observable agent work becomes candidate learning, then only promotes after proofPersonal and team knowledge with state, owner, scope, and provenance

See how agent work improves the codebase

Rigour Studio is an evidence map for engineering work—not just a dependency graph.

intent → context → policy → agent action → verification → outcome → learning
                    │                         │               │
                    └──── advice + impact ────┴───────────────┘

Open Studio to trace an agent run from the recommendation it received to the code it changed, the checks that ran, the risk it prevented, and the knowledge it left behind.

npx @rigour-labs/cli init
npx @rigour-labs/cli hooks init
npx @rigour-labs/cli studio

The five product areas stay simple:

  • Map — connect code structure, agent activity, decisions, proof, and outcomes.
  • Agents — inspect scopes, run history, handoffs, and the guidance each agent received.
  • Review — understand gates, policy decisions, conflicts, and Fix Packets.
  • Knowledge — explore patterns, memory, lessons, semantic recall, drift, and cost evidence.
  • Settings — see index, graph, cache, learning, storage, and connectivity health.

Start in three minutes

1. Scan a repository

npx rigour-scan

Rigour runs local quality, security, and AI-drift checks and returns an actionable result.

2. Add the Rigour loop

npx @rigour-labs/cli init
npx @rigour-labs/cli hooks init --tool cursor
npx @rigour-labs/cli skills install --target codex,cursor
npx @rigour-labs/cli check

hooks init supports Cursor, Claude Code, Cline, and Windsurf. It checks observable writes as agents work; check is the full project verification step.

3. Give every agent the same good workflow

rigour skills install --target codex,cursor

Rigour Skills turn its evidence loop into small, reusable agent workflows:

  • rigour-context asks for the smallest explainable scope before an agent reads code.
  • rigour-verify closes a change with proof and a Fix Packet repair loop.
  • rigour-handoff transfers verified state without replaying an entire session.

Codex receives native repository skills in .agents/skills. Cursor receives focused slash commands in .cursor/commands. Portable copies land in docs/rigour-skills for other MCP-capable agents. Existing files are preserved unless --force is explicitly used.

4. Give your agent Rigour through MCP

{
  "mcpServers": {
    "rigour": {
      "command": "npx",
      "args": ["-y", "@rigour-labs/mcp@latest"]
    }
  }
}

Agents can ask Rigour for scoped context, register their work, receive Fix Packets, record checkpoints and handoffs, and leave evidence for Studio.

5. Mediate high-impact MCP tools (6.2)

Rigour can sit in front of selected MCP servers, expose only approved tools, normalize every call into a common action record, and issue a signed execution receipt. Start in observe mode to see what policy would block without interrupting work; switch to enforce only after reviewing the evidence.

rigour firewall gateway-configure --config ~/rigour-gateway.json
rigour firewall status
rigour firewall grant --agent coding-agent --task TASK-123 \
  --tool github__create_issue --ttl 300
rigour firewall receipts

Trusted state and canonical receipts live outside the repository. Studio reads them server-side and receives only safe evidence summaries for its Review panel and execution map—never keys, environment secrets, downstream commands, or receipt signatures. Follow MCP Integration for the configuration and exact security boundary.

What Rigour does differently

Context that can explain itself

Rigour builds a structural index immediately and enriches semantic retrieval in the background. When an agent asks for help, it returns the smallest evidence-backed scope it can justify—not a repository dump. Each recommendation records its sources, exclusions, cache reuse, and estimated context savings.

Learning with a proof boundary

Rigour records evidence from its hooks, MCP calls, context retrieval, Fix Packets, accepted changes, checkpoints, handoffs, tests, and human feedback. A lesson starts as a candidate. It becomes reusable only after deterministic verification, repeated successful outcomes, or explicit confirmation.

Model text, vector similarity, rejected fixes, and failed tests can inform investigation. They do not become enforcement rules on their own.

Bugs it can prove, and rules learned from your fixes

The semantic_bugs gate builds a TypeScript program and traces values across files. It reports a bug only when it can show where the risky value enters and where it does harm: a credential header sent by a request that follows redirects, rows from a paged read loaded into memory just to be counted, or a cached response that can carry a failure fallback. It runs locally, with no model.

rigour learn <fix-commit> turns a fix into a rule for the same bug. The rule is kept only if it fires on the code before the fix, is silent on the fixed code, and hits few other places in the repository; those places are listed for review. Learned rules live in .rigour/rules/, are reviewed like code, and appear in Studio with the fix they came from.

rigour learn a1b2c3d --dry-run   # what would be learned, and why
rigour learn a1b2c3d             # save validated rules to .rigour/rules/
rigour learn --agent-fixes       # rules from fixes your agents made to Rigour findings

Agents are asked to review before they finish: rigour_review over MCP, and a stop hook for Claude Code and Cursor that sends the agent back on proven or security findings. rigour review-stats shows whether that loop works in your repository.

Governance agents can work with

Rigour’s deterministic checks catch security issues, structural regressions, hallucinated imports, phantom APIs, context drift, and more. On supported mediated paths, the Agent Transaction Firewall applies per-agent scopes, typed command allowlists, fail-closed arbitration, and signed attestations.

When work fails a check, Rigour gives the agent a Fix Packet: the rule, affected files, evidence, and concrete next action.

Local first. Team-ready when you are.

Rigour works fully in local-only mode with SQLite. Nothing requires an account.

For teams, PostgreSQL becomes the durable source for private-user and approved shared knowledge; encrypted SQLite remains the local cache and offline outbox. If pgvector is enabled, Rigour can use semantic recall as advisory input while repository scope and lesson state continue to control what applies.

rigour team init-schema --database-url 'postgresql://…' --pgvector
rigour team configure --database-url 'postgresql://…' \
  --organization acme --team platform --actor ashutosh --pgvector
rigour team import-local /path/to/repository --dry-run
rigour team import-local /path/to/repository
rigour team sync
rigour team doctor

team import-local safely adopts personal lessons created before team mode was configured. It is repository-scoped, dry-runnable, idempotent, and never promotes candidate knowledge or publishes it to the team.

When team storage is unavailable, local enforcement and evidence capture continue. Studio reports the state as offline — changes queued.

Guarantees and boundaries

Rigour is deliberately precise about what it does and does not claim.

  • Core checks and storage are local-first; cloud deep analysis is opt-in.
  • A model is asked only what code cannot answer, and only where its answer is measured. Intent checks stay off until a model reports zero false findings on the labelled set (Deep Analysis).
  • Rigour can enforce work that passes through its installed hooks or MCP gateway. A directly configured parallel MCP server bypasses that gateway unless the host or administrator removes that route.
  • Advice is evidence of what Rigour recommended, not proof that an agent followed it or that it caused an outcome.
  • Observed spend, measured estimates, and modelled savings are shown separately so cost numbers do not over-promise.

Read the architectural decisions behind these boundaries: Agent Transaction Firewall, Evidence Learning & Team Storage, Adaptive Execution Graph, and Trusted MCP Gateway.

Documentation

If you want to…Start here
Install and run RigourQuick Start
Connect a coding agentAgent Integration · MCP Integration
Understand a failed checkFix Packets · AST Gates
Configure policies and deep analysisConfiguration · Deep Analysis
Set up PostgreSQL, pgvector, and team knowledgeEnterprise & Teams
Review the product philosophyPhilosophy

Build from source

pnpm install
pnpm build
pnpm test
node packages/rigour-cli/dist/cli.js studio

If a fresh clone reports ignored native build scripts, review and approve the required builds with pnpm approve-builds, then rerun the commands.


Documentation · Discussions · Issues

MIT © Rigour Labs · Built by Ashutosh

Related MCP servers

MCP server for Alert Logic MDR — incident response, log search, SOAR, and SOC workflows

0
Python
MIT
View repository →

Community extension of CrowdStrike falcon-mcp with near-complete Falcon API coverage

0
Python
MIT
View repository →

Full Qualys portal management over MCP: VMDR, PC, WAS, Cloud Agent, Container Security & more

0
Python
MIT
View repository →

MCP server for Sophos Central — endpoint security, XDR/MDR, and MSSP multi-tenant ops

0
TypeScript
MIT
View repository →
PRProlog Reasoner logo

Prolog Reasoner

Maintained

SWI-Prolog logic solver for LLMs—bridge natural language reasoning with formal symbolic computation.

11
Python
MIT
View repository →

Audit GitHub repos for security, compliance, and EU AI Act exposure from Claude or Cursor.

View repository →