MCP server for Vigile AI Security — query trust scores for MCP servers and agent skills from within Claude Code, Cursor, and other AI agents
Connect Vigile MCP to Claude, Cursor or any other MCP client and it stops being a tab you switch to. MCP server for Vigile AI Security — query trust scores for MCP servers and agent skills from within Claude Code, Cursor, and other AI agents. The vigile mcp mcp server is what makes that connection.
The toolset is worth reading before you wire it up, because it tells you what the integration is really for:
vigile_check_server — Look up trust score for an MCP server by name or packagevigile_check_skill — Look up trust score for an agent skill (claude.md, .cursorrules, OpenClaw skills, etc.)vigile_scan_content — Scan raw content from a claude.md, .cursorrules, skill.md, or similar file for security issuesvigile_search — Search the Vigile trust registry by keywordvigile_verify_location — Verify whether a skill uses location data safely and check for location-based attack patternsCursor — The Cursor tool exposed by this serverWindsurf — The Windsurf tool exposed by this serverConfiguration is passed through the environment: VIGILE_API_KEY. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
Installation goes through your MCP client rather than a global install: point it at vigile-mcp on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.
This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Vigile MCP's toolset — vigile_check_server, vigile_check_skill, vigile_scan_content and 4 more — is a fair guide to whether it matches your workflow. It is maintained by vigile-ai; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against Vigile MCP's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| vigile_check_server | Look up trust score for an MCP server by name or package |
| vigile_check_skill | Look up trust score for an agent skill (claude.md, .cursorrules, OpenClaw skills, etc.) |
| vigile_scan_content | Scan raw content from a claude.md, .cursorrules, skill.md, or similar file for security issues |
| vigile_search | Search the Vigile trust registry by keyword |
| vigile_verify_location | Verify whether a skill uses location data safely and check for location-based attack patterns |
| Cursor | The Cursor tool exposed by this server. |
| Windsurf | The Windsurf tool exposed by this server. |
{
"mcpServers": {
"vigile": {
"command": "npx",
"args": ["-y", "vigile-mcp"]
}
}
}Configuration as documented by the project. Restart the client after saving.
| Variable | Description | Required |
|---|---|---|
| VIGILE_API_KEY | Credential the server authenticates with. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.