Joern Code Analysis
HTTP-SSEMCP Server based on Joern for code review and security analysis.
MCP Server based on Joern for code review and security analysis.
A simple MCP Server for Joern.
This project is an MCP Server based on Joern, providing a series of features to help developers with code review and security analysis.
Clone the project locally:
git clone https://github.com/sfncat/mcp-joern.git cd mcp-joern
Install Python dependencies:
uv venv .venv source .venv/bin/activate uv sync
├── server.py # MCP Server main program
├── test_mcp_client.py # Test program for joern server and mcp tool
├── test_sc_tools.py # Direct test program for sc tools
├── common_tools.py # Common utility functions
├── server_tools.py # Server utility functions
├── server_tools.sc # Scala implementation of server utility functions
├── server_tools_source.sc # Scala implementation of server utility functions,use sourceCode to get the source code of method
├── requirements.txt # Python dependency file
├── sample_cline_mcp_settings.json # Sample cline mcp configuration file
└── env_example.txt # Environment variables example file
Start the Joern server:
joern -J-Xmx40G --server --server-host 127.0.0.1 --server-port 16162 --server-auth-username user --server-auth-password password --import server_tools.sc Or joern -J-Xmx40G --server --server-host 127.0.0.1 --server-port 16162 --server-auth-username user --server-auth-password password --import server_tools_source.sc
Copy env_example.txt to .env Modify the configuration information to match the joern server startup configuration
Run the test connection:
Modify the information in test_mcp_client.py
to confirm the joern server is working properly
uv run test_mcp_client.py Starting MCP server test... ================================================== Testing server connection... [04/16/25 20:38:54] INFO Processing request of type CallToolRequest server.py:534 Connection test result: Successfully connected to Joern MCP, joern server version is XXX
Configure MCP server
Configure the mcp server in cline, refer to sample_cline_mcp_settings.json
.
Use MCP server
Ask questions to the large language model, refer to prompts_en.md
.env
file is used to store environment variables.gitignore
file defines files to be ignored by Git version controlpyproject.toml
defines the Python configuration for the projectserver_tools.sc
, add definitions in server_tools.py
, and add tests in test_mcp_client.py
Welcome to submit Issues and Pull Requests to help improve the project.
Welcome to add more tools.