trackmcp
Back to directory
JordyZomer

codeql-mcp

View on GitHub

This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like [Cursor](https://cursor.

119 stars PythonAI & Machine Learning Updated Oct 29, 2025

Documentation

CodeQL MCP Server

This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like Cursor or AI agents to interact with CodeQL through structured commands and doc search.


Features

  • ✅ Register CodeQL databases
  • ✅ Run full queries or quick-evaluate a symbol
  • ✅ Decode `.bqrs` files into JSON
  • ✅ Locate predicate/class symbol positions

File Structure

FilePurpose
`server.py`Main FastMCP server exposing CodeQL tools
`codeqlclient.py`CodeQLQueryServer implementation (JSON-RPC handler)

Requirements

Install with `uv`:

bash
uv pip install -r requirements.txt

or with `pip`:

bash
pip install fastmcp httpx

Running the MCP Server

bash
uv run mcp run server.py -t sse
  • Starts the server at http://localhost:8000/sse
  • Required for Cursor or AI agent use

Cursor Config

Make sure your `.cusor/config.json` contains:

code
{
  "mcpServers": {
    "CodeQL": {
      "url": "http://localhost:8000/sse"
    }
  }
}

Notes

  • Tools like Cursor will invoke these commands directly via natural language.
  • You must have a codeql binary in your $PATH, or hardcode its path in codeqlclient.py.
  • You should probably specify query locations, query write locations and database paths in your prompts.

Frequently asked questions

What is codeql-mcp?

codeql-mcp is This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like [Cursor](https://cursor.

How do I install codeql-mcp?

Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

Is codeql-mcp open source?

Yes — it is hosted on GitHub at https://github.com/JordyZomer/codeql-mcp and has 119 stars.

Related MCP tools

Run your own MCP server? See who uses it and what to fix.

Measure it with TrackMCP