This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like [Cursor](https://cursor.sh/) or AI
This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like Cursor or AI agents to interact with CodeQL through structured commands. That is what the codeql mcp server brings to an AI assistant: the same capability, reachable through the Model Context Protocol rather than a separate app or dashboard.
Installation goes through your MCP client rather than a global install: point it at fastmcp on PyPI and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.
The server publishes 3 tools. What each one is for:
File — Purposeserver.py — Main FastMCP server exposing CodeQL toolscodeqlclient.py — CodeQLQueryServer implementation (JSON-RPC handler)Install with uv: or with pip:
Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. CodeQL's toolset — File, server.py, codeqlclient.py — is a fair guide to whether it matches your workflow. It is maintained by JordyZomer; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| File | Purpose |
| server.py | Main FastMCP server exposing CodeQL tools |
| codeqlclient.py | CodeQLQueryServer implementation (JSON-RPC handler) |
{
"mcpServers": {
"codeql": {
"command": "uvx",
"args": ["fastmcp"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Install with uv: or with pip:
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.