vakt

Coding Agents

Give a coding agent local security scores and function-level findings through vakt's MCP server.

How it works

vakt exposes its scanner through the Model Context Protocol (MCP). A coding agent can scan a project, list flagged functions, and inspect the source and scores of an individual finding.

vakt is the scanner, not a standalone conversational agent. There is no vakt agent command. Your MCP host supplies the reasoning, proposed edits, and approval flow. Connecting an external agent does not make that agent local: source returned by MCP may be sent to the host’s model provider under its own data policy.

Connect your agent

Install vakt and download the model first, following the quick start. Then register vakt mcp in your host’s MCP settings:

{
	"mcpServers": {
		"vakt": {
			"command": "vakt",
			"args": ["mcp"]
		}
	}
}

If the host cannot find the executable, use the absolute path to your installed binary. See Integrations for configuration locations and root restrictions.

Available tools

scan

Scan a project and return a summary with the worst findings. The agent supplies the project directory as dir. This runs model inference and is the expensive operation; reuse its results instead of rescanning for every question.

findings

List flagged functions from the last scan, with pagination and filters for severity, CWE family, or file. Use this to narrow a large report before retrieving full function source.

finding

Read one finding in detail, including its score, CWE family, and function source. The agent should inspect the surrounding code and callers before deciding whether the result is actionable.

families

List the 18 CWE families and the issues they describe. Use this when interpreting a family score or choosing a filter.

Suggested workflow

Ask your agent to:

Scan this project’s absolute directory with vakt. Inspect the highest-scoring findings, check each against its callers and existing validation, and explain which look actionable. Propose fixes for review before editing code.

After approving an edit, run the relevant tests and ask the agent to rescan the project. Cached scores can be reused for unchanged functions.

A lower score after a change is not proof that the issue is fixed. Confirm the behavior with tests and review; DOM-0.8B returns classification scores rather than an exploit demonstration or written security analysis.

Limit filesystem scope

By default, a single server can accept different project directories. Restrict it to one tree with --root:

{
	"mcpServers": {
		"vakt": {
			"command": "vakt",
			"args": ["mcp", "--root", "/absolute/path/to/projects"]
		}
	}
}

Use a root containing only the projects the host should access. This scopes the vakt server, not the host’s other tools or filesystem permissions.

Improve team velocity with
better security and privacy.