Vigile MCP Server

MCP server for Vigile AI Security — query trust scores for MCP servers and agent skills from within Claude Code, Cursor, and other AI agents

Local serverstdio

What is the Vigile MCP MCP server?

Connect Vigile MCP to Claude, Cursor or any other MCP client and it stops being a tab you switch to. MCP server for Vigile AI Security — query trust scores for MCP servers and agent skills from within Claude Code, Cursor, and other AI agents. The vigile mcp mcp server is what makes that connection.

Available tools

The toolset is worth reading before you wire it up, because it tells you what the integration is really for:

  • vigile_check_server — Look up trust score for an MCP server by name or package
  • vigile_check_skill — Look up trust score for an agent skill (claude.md, .cursorrules, OpenClaw skills, etc.)
  • vigile_scan_content — Scan raw content from a claude.md, .cursorrules, skill.md, or similar file for security issues
  • vigile_search — Search the Vigile trust registry by keyword
  • vigile_verify_location — Verify whether a skill uses location data safely and check for location-based attack patterns
  • Cursor — The Cursor tool exposed by this server
  • Windsurf — The Windsurf tool exposed by this server

Credentials and setup notes

Configuration is passed through the environment: VIGILE_API_KEY. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.

  • Node.js 18+ - An MCP-compatible client

Installation

Installation goes through your MCP client rather than a global install: point it at vigile-mcp on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

Where it fits

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Vigile MCP's toolset — vigile_check_server, vigile_check_skill, vigile_scan_content and 4 more — is a fair guide to whether it matches your workflow. It is maintained by vigile-ai; worth a glance at recent repository activity before you build anything load-bearing on it.

This entry was verified against Vigile MCP's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.

Worth knowing first

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

Available tools

ToolWhat it does
vigile_check_serverLook up trust score for an MCP server by name or package
vigile_check_skillLook up trust score for an agent skill (claude.md, .cursorrules, OpenClaw skills, etc.)
vigile_scan_contentScan raw content from a claude.md, .cursorrules, skill.md, or similar file for security issues
vigile_searchSearch the Vigile trust registry by keyword
vigile_verify_locationVerify whether a skill uses location data safely and check for location-based attack patterns
CursorThe Cursor tool exposed by this server.
WindsurfThe Windsurf tool exposed by this server.

How to install the Vigile MCP MCP server

{
  "mcpServers": {
    "vigile": {
      "command": "npx",
      "args": ["-y", "vigile-mcp"]
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Configuration

  • Node.js 18+ - An MCP-compatible client
VariableDescriptionRequired
VIGILE_API_KEYCredential the server authenticates with.Yes

Example prompts to try

  • Use Vigile MCP to vigile check server.
  • Use Vigile MCP to vigile check skill.
  • Use Vigile MCP to vigile scan content.

Frequently asked questions

It connects Vigile MCP to MCP-compatible AI assistants such as Claude and Cursor, exposing 7 tools (vigile_check_server, vigile_check_skill, vigile_scan_content, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Vigile MCP directly.