kasra-mcp
Kasra MCP Server — local code review via the Model Context Protocol.
Reads files on your machine and sends them to the Kasra API for security scanning. Designed to work with AI tools like Claude Desktop, Cursor, Claude Code, and any MCP-compatible client.
Install
pip install kasra-mcp
Requires Python 3.11+.
Quick Start
# Verify installation
python3 -m kasra_mcp.server --help
The server connects to a Kasra API instance (default: http://localhost:8090).
Configuration
Environment variables:
| Variable | Default | Description |
|---|---|---|
KASRA_API_URL |
http://localhost:8090 |
Kasra API base URL |
KASRA_API_KEY |
"" |
API key for authentication |
Tools
kasra_scan_file
Scan a file or directory for security vulnerabilities.
| Parameter | Type | Description |
|---|---|---|
path |
string |
Path to a file or directory to scan |
Supports both single files and directories. Ignores common non-source files (images, binaries, .git, node_modules, etc.).
kasra_get_rules
List all loaded security rules.
| Parameter | Type | Description |
|---|---|---|
severity |
string? |
Filter by severity (P0, P1, P2) |
enabled_only |
boolean? |
Only return enabled rules |
health
Check the Kasra API connection and engine status.
Integration with AI Tools
Claude Desktop
{
"mcpServers": {
"kasra": {
"command": "python3",
"args": ["-m", "kasra_mcp.server"],
"env": {
"KASRA_API_URL": "http://localhost:8090",
"KASRA_API_KEY": "your-api-key-here"
}
}
}
}
Paste this into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows).
Cursor
{
"mcpServers": {
"kasra": {
"command": "python3",
"args": ["-m", "kasra_mcp.server"],
"env": {
"KASRA_API_URL": "http://localhost:8090",
"KASRA_API_KEY": "your-api-key-here"
}
}
}
}
Claude Code
{
"mcpServers": {
"kasra": {
"command": "python3",
"args": ["-m", "kasra_mcp.server"],
"env": {
"KASRA_API_URL": "http://localhost:8090",
"KASRA_API_KEY": "your-api-key-here"
}
}
}
}
How it works
Claude Desktop / Cursor / Claude Code
│
│ stdio (JSON-RPC over stdin/stdout)
▼
┌─────────────────┐ POST /v1/scan/file ┌────────────────┐
│ kasra-mcp │ ─────────────────────────────→ │ Kasra API │
│ │ POST /v1/rules/export │ (Docker) │
│ reads local │ ←───────────────────────────── │ 193 rules │
│ file content │ findings + results │ CR scanning │
└─────────────────┘ └────────────────┘
- Claude Desktop starts
kasra-mcpas a subprocess (stdio transport) - When the user asks to scan a file, Claude calls
kasra_scan_filewith a path kasra-mcpreads the file content from local disk- Sends the content to the Kasra API via
POST /v1/scan/file - Kasra API runs 83 code review rules, returns findings
kasra-mcpreturns the results to Claude
The MCP server never stores your code — it reads, sends, and discards.
License
This project is licensed under the MIT License.
Development
git clone <repo>
cd kasra-mcp
pip install -e .
python3 -m kasra_mcp.server
Metadata
Release files for kasra-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| kasra_mcp-0.1.0.tar.gz | 6.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| kasra_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.0 kB
Release files / kasra_mcp-0.1.0.tar.gz
| Download URL | kasra_mcp-0.1.0.tar.gz |
|---|---|
| Size | 6.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1408ab81f706e17418bd6a1f1ab0988226ae611c2e29ac9ec3619f36b10cd094
|
|
BLAKE2b-256 checksum How to use checksums |
6bb3c5f10fae6e4dcf93c7919ec001407fea2839c4baa6e9efcf858e95ac6e52
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.9
|
Release files / kasra_mcp-0.1.0-py3-none-any.whl
| Download URL | kasra_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 7.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cfa04ae00dffb602d4ad68fb868b97c5f2c8294ffff4b97000822f3580c9863f
|
|
BLAKE2b-256 checksum How to use checksums |
c62648fb8dfebe94ca226ea6f90b04c2c62ae5e8f3653a4efad3841a04eef9b0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.9
|