Connect Agnostics MCP to your coding agent

Wire the Agnostics MCP server into Cursor or Claude Desktop for local code scans, scan uploads, and Release Gate checks.

Keep code scans local, then use MCP tools to upload results or run adversarial scans against your Agnostics workspace.

What the MCP server does

The Agnostics MCP server exposes tools your coding agent can call: local code scans, upload to a code scanner project, create targets, launch scans, and read Release Gate status.

Local code scans run through the same CLI as CI. Nothing leaves your machine until you upload or start a cloud adversarial scan.

Install and build

Install `@agnostics/mcp` from the Agnostics repo or package registry, then build the workspace packages if you are running from source.

You need Node 20+ and a built `@agnostics/scan` CLI for local code scan tools.

Set API credentials

Set `AGNOSTICS_API_URL` to your Agnostics API host.

Set `AGNOSTICS_API_KEY` to a workspace API key from the Agnostics app integrations settings.

Code scan tools work offline. Upload, target, scan, findings, and Release Gate tools require both variables.

Cursor configuration

Add an MCP server entry in `.cursor/mcp.json` pointing at the built `agnostics-mcp` binary.

Pass `AGNOSTICS_API_URL` and `AGNOSTICS_API_KEY` in the `env` block. Restart Cursor after saving.

Claude Desktop configuration

Add the same server block to `claude_desktop_config.json` under `mcpServers.agnostics`.

Use absolute paths to the built server file when running from a local checkout.

Suggested workflow

Run `agnostics_code_scan` on your repo before a risky change.

Upload with `agnostics_upload_code_scan` when you want findings tracked in Agnostics.

Use `agnostics_run_scan` and `agnostics_get_release_gate` for adversarial Release Gate checks on live targets.