Joern MCP
About
A Model Context Protocol (MCP) server that provides AI assistants with static code analysis capabilities using Joern's Code Property Graph (CPG) technology.
Explore
- Multi-Language Support: Java, C/C++, JavaScript, Python, Go, Kotlin, C#, Ghidra, Jimple, PHP, Ruby, Swift
- Docker Isolation: Each analysis session runs in a secure container
- GitHub Integration: Analyze repositories directly from GitHub URLs
- Session-Based: Persistent CPG sessions with automatic cleanup
- Redis-Backed: Fast caching and session management
- Async Queries: Non-blocking CPG generation and query execution
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Joern MCPCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
- Python 3.8+
- Docker
- Redis
- Git
4. Run the server:
bash
python main.py
bash
pip install -r requirements.txt
./setup.sh
Docker issues:
bash
docker ps
curl http://localhost:4242/health
- create_cpg_session: Initialize analysis session from local path or GitHub URL
- run_cpgql_query: Execute synchronous CPGQL queries with JSON output
- run_cpgql_query_async: Execute asynchronous queries with status tracking
- get_query_status: Check status of asynchronously running queries
- get_query_result: Retrieve results from completed queries
- cleanup_queries: Clean up old completed query results
- get_session_status: Check session state and metadata
- list_sessions: View active sessions with filtering
- close_session: Clean up session resources
- cleanup_all_sessions: Clean up multiple sessions and containers
- get_codebase_summary: Get high-level overview of codebase (file count, method count, language)
- list_files: List all source files with optional regex filtering
- list_methods: Discover all methods/functions with filtering by name, file, or external status
- get_method_source: Retrieve actual source code for specific methods
- list_calls: Find function call relationships and dependencies
- get_call_graph: Build call graphs (outgoing callees or incoming callers) with configurable depth
- list_parameters: Get detailed parameter information for methods
- find_literals: Search for hardcoded values (strings, numbers, API keys, etc)
- get_code_snippet: Retrieve code snippets from files with line range
- find_taint_sources: Locate likely external input points (taint sources)
- find_taint_sinks: Locate dangerous sinks where tainted data could cause vulnerabilities
- find_taint_flows: Find dataflow paths from sources to sinks using Joern dataflow primitives
- find_argument_flows: Find flows where the exact same expression is passed to both source and sink calls
- check_method_reachability: Check if one method can reach another through the call graph
- list_taint_paths: List detailed taint flow paths from sources to sinks
- get_program_slice: Build a program slice from a specific line or call
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"joern mcp": {
"joern-mcp": {
"url": "https://0.0.0.0:4242/mcp"
}
}
}
}
McpServers
{
"joern-mcp": {
"url": "https://0.0.0.0:4242/mcp"
}
}
A Model Context Protocol (MCP) server that provides AI assistants with static code analysis capabilities using Joern's Code Property Graph (CPG) technology.
Features
- Multi-Language Support: Java, C/C++, JavaScript, Python, Go, Kotlin, C#, Ghidra, Jimple, PHP, Ruby, Swift
- Docker Isolation: Each analysis session runs in a secure container
- GitHub Integration: Analyze repositories directly from GitHub URLs
- Session-Based: Persistent CPG sessions with automatic cleanup
- Redis-Backed: Fast caching and session management
- Async Queries: Non-blocking CPG generation and query execution
Quick Start
Prerequisites
- Python 3.8+
- Docker
- Redis
- Git
Installation
1. Clone and install dependencies:
git clone https://github.com/Lekssays/joern-mcp.git
cd joern-mcp
pip install -r requirements.txt
2. Setup (builds Joern image and starts Redis):
./setup.sh
3. Configure (optional):
```bash
cp config.example.yaml config.yaml
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



