Inside your AI agent (MCP)

Register the codafort MCP server in your AI agent (Claude Code, Cursor, Codex, OpenCode, Antigravity) and it starts checking every diff.

The server is codafort mcp (stdio transport). Your agent calls codafort inside its own coding loop and gets the same analyses as the CLI.

Install

codafort mcp install                  # every agent installed on this machine (global config)
codafort mcp install --client codex   # just one: claude | cursor | codex | opencode | antigravity
codafort mcp install --scope project  # in the current repo, to commit and share with the team
codafort mcp install --dry-run        # shows what it would write, without writing
AgentGlobal (--scope user, the default)Project (--scope project)
Claude Codeclaude mcp add --scope user (install runs it; without claude on PATH, it prints the command).mcp.json
Cursor~/.cursor/mcp.json.cursor/mcp.json
Codex~/.codex/config.toml (or $CODEX_HOME).codex/config.toml
OpenCode~/.config/opencode/opencode.jsonopencode.json
Antigravity~/.gemini/config/mcp_config.json.agents/mcp_config.json

In the global scope, all registers only with agents whose config folder exists: nothing is created for an agent you don't use. The merge keeps your other servers, and running it again changes nothing. Restart the agent to load the codafort server.

Other MCP clients (Gemini CLI, VS Code, Windsurf, Zed…): register a stdio server whose command is codafort mcp. The server runs locally, with no network dependency. On Windows the command is the same.

The tools

ToolWhat it does
scanscans a directory → prioritised findings with SF-n IDs
scan_diffonly the findings on lines changed vs HEAD, to check the change before committing
sessionlists the SF-n of the last scan again without re-analysing
explainthe why of an SF-n: rule, CWE/OWASP, source→sink path
fix_previewthe patch for an SF-n as data (old_line/new_line); the agent applies it
reviewadvisory maintainability findings and code health
vetblocking verdict for the delta, plus advisories and scope
triagelists suspected findings for judgement
resolveconfirms or dismisses a suspected finding and persists the decision
propose_catalogproposes a source/sink/sanitizer for human ratification
skillreads the skills embedded in the binary (the same ones mcp install writes), for an agent that does not have them installed

The skills are also served as MCP resources (codafort://skills/<skill>/<file>), which Claude Code, Codex and OpenCode let the model read. Each codafort-devsecops role is an MCP prompt (devsecops-dev, devsecops-champion, devsecops-sec, devsecops-ops, devsecops-sre, devsecops-architect, devsecops-supply-chain, devsecops-grc): in Claude Code, /mcp__codafort__devsecops-sre <task>; in Cursor and OpenCode, from the command menu. Codex has no MCP prompts.

fix_preview writes nothing. Editing the file and opening a PR stay with the agent and with you; the server only diagnoses and proposes. Creating the counter-signed declaration (attest), applying a fix to your code and deciding the gate are up to a person.

Teaching the agent to use the suite

On connect, the server already tells the agent what each tool does and where the data boundary is. The Agent Skills teach the agent to pick and run codafort, codacrash, codaprobe and codatrace, read coverage and exit codes, and deliver verifiable artifacts. Five are per tool. The sixth, codafort-devsecops, makes the agent work as a developer, security champion, AppSec analyst, DevOps engineer, SRE, security architect, supply-chain owner or compliance lead, measuring what it claims and leaving risk decisions to a person.

The six folders ship inside the binary. codafort mcp install registers the server and writes the skills into each detected agent's skills folder, at the binary's version:

  • Claude Code: ~/.claude/skills/ (with --scope project, .claude/skills/).
  • Codex, Cursor and OpenCode: ~/.agents/skills/ (in a project, .agents/skills/). Cursor and OpenCode also read Claude Code's folder, so they get no copy of their own when it exists.
  • Antigravity: ~/.gemini/config/skills/.

Reinstalling updates what codafort wrote. Skills are not editable: a skill file you edited goes back to the official version, and the command lists what it restored. codafort mcp install --dry-run shows what is altered without writing anything, and --no-skills registers only the server. The skills also ship in the skills/ folder of the release package (Download). They are written in English and reply in the language of whoever asks.

The typical flow

  1. You ask the agent for a feature. It writes it.
  2. Before committing, it calls scan_diff. codafort returns only what is new and confirmed.
  3. For each SF-n, the agent calls explain then fix_preview, applies the patch and runs scan_diff again.
  4. You approve the clean diff. For the full verdict on the change, see vet.

Limits

The MCP server uses the same engine as the CLI. If a language or category has low recall in the CLI, it has the same recall in the agent.