Skip to main content

kasra-mcp

Kasra MCP Server — local code review via the Model Context Protocol.

Reads files on your machine and sends them to the Kasra API for security scanning. Designed to work with AI tools like Claude Desktop, Cursor, Claude Code, and any MCP-compatible client.


Install

pip install kasra-mcp

Requires Python 3.11+.


Quick Start

# Verify installation
python3 -m kasra_mcp.server --help

The server connects to a Kasra API instance (default: http://localhost:8090).


Configuration

Environment variables:

Variable Default Description
KASRA_API_URL http://localhost:8090 Kasra API base URL
KASRA_API_KEY "" API key for authentication

Tools

kasra_scan_file

Scan a file or directory for security vulnerabilities.

Parameter Type Description
path string Path to a file or directory to scan

Supports both single files and directories. Ignores common non-source files (images, binaries, .git, node_modules, etc.).

kasra_get_rules

List all loaded security rules.

Parameter Type Description
severity string? Filter by severity (P0, P1, P2)
enabled_only boolean? Only return enabled rules

health

Check the Kasra API connection and engine status.


Integration with AI Tools

Claude Desktop

{
  "mcpServers": {
    "kasra": {
      "command": "python3",
      "args": ["-m", "kasra_mcp.server"],
      "env": {
        "KASRA_API_URL": "http://localhost:8090",
        "KASRA_API_KEY": "your-api-key-here"
      }
    }
  }
}

Paste this into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).

Cursor

{
  "mcpServers": {
    "kasra": {
      "command": "python3",
      "args": ["-m", "kasra_mcp.server"],
      "env": {
        "KASRA_API_URL": "http://localhost:8090",
        "KASRA_API_KEY": "your-api-key-here"
      }
    }
  }
}

Claude Code

{
  "mcpServers": {
    "kasra": {
      "command": "python3",
      "args": ["-m", "kasra_mcp.server"],
      "env": {
        "KASRA_API_URL": "http://localhost:8090",
        "KASRA_API_KEY": "your-api-key-here"
      }
    }
  }
}

How it works


 Claude Desktop / Cursor / Claude Code
        │
        │  stdio (JSON-RPC over stdin/stdout)
        ▼
 ┌─────────────────┐        POST /v1/scan/file     ┌────────────────┐
 │   kasra-mcp     │ ─────────────────────────────→ │  Kasra API     │
 │                 │        POST /v1/rules/export   │  (Docker)      │
 │  reads local    │ ←───────────────────────────── │  193 rules     │
 │  file content   │        findings + results      │  CR scanning    │
 └─────────────────┘                                └────────────────┘
  1. Claude Desktop starts kasra-mcp as a subprocess (stdio transport)
  2. When the user asks to scan a file, Claude calls kasra_scan_file with a path
  3. kasra-mcp reads the file content from local disk
  4. Sends the content to the Kasra API via POST /v1/scan/file
  5. Kasra API runs 83 code review rules, returns findings
  6. kasra-mcp returns the results to Claude

The MCP server never stores your code — it reads, sends, and discards.


License

This project is licensed under the MIT License.


Development

git clone <repo>
cd kasra-mcp
pip install -e .
python3 -m kasra_mcp.server

Metadata

Release files for kasra-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for kasra-mcp 0.1.0
File Size Uploaded
kasra_mcp-0.1.0.tar.gz 6.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for kasra-mcp 0.1.0
File Interpreter ABI Platform
kasra_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 14.0 kB

Release files / kasra_mcp-0.1.0.tar.gz

Download URL kasra_mcp-0.1.0.tar.gz
Size 6.7 kB
Tags Source
SHA-256 checksum
How to use checksums
1408ab81f706e17418bd6a1f1ab0988226ae611c2e29ac9ec3619f36b10cd094
BLAKE2b-256 checksum
How to use checksums
6bb3c5f10fae6e4dcf93c7919ec001407fea2839c4baa6e9efcf858e95ac6e52
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.9

Release files / kasra_mcp-0.1.0-py3-none-any.whl

Download URL kasra_mcp-0.1.0-py3-none-any.whl
Size 7.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cfa04ae00dffb602d4ad68fb868b97c5f2c8294ffff4b97000822f3580c9863f
BLAKE2b-256 checksum
How to use checksums
c62648fb8dfebe94ca226ea6f90b04c2c62ae5e8f3653a4efad3841a04eef9b0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.9

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page