vakt
Integrations
Connect vakt to MCP clients and run local security scoring in GitHub Actions.
MCP clients
vakt mcp runs a stdio MCP server. Your client starts the process and communicates over stdin and stdout; you do not need to run a separate HTTP service.
For Cursor, merge this entry into .cursor/mcp.json. Claude Desktop uses the same server shape in claude_desktop_config.json. For other hosts, register an equivalent stdio server using their MCP settings:
{
"mcpServers": {
"vakt": {
"command": "vakt",
"args": ["mcp", "--root", "/absolute/path/to/projects"]
}
}
} Replace the root with your projects directory. Omit --root only if the host should be able to select directories outside that tree. Use an absolute executable path if the host does not inherit your shell’s PATH.
Download the model with vakt summon before the host launches the server. Restart or reload the host’s MCP connection after editing its configuration, then confirm that the scan, findings, finding, and families tools are available.
The agent supplies dir for each project. See Coding agents for a review workflow and data-handling considerations.
GitHub Actions
This example installs vakt and the model on a Linux CPU runner, scans the checked-out code, and preserves the JSON report even when findings fail the scan step.
Add an HF_TOKEN repository secret belonging to an account with access to DOM-0.8B.
name: vakt
on:
pull_request:
permissions:
contents: read
jobs:
scan:
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v6
- name: Install vakt and download the model
env:
HF_TOKEN: ${{ secrets.HF_TOKEN }}
run: |
curl -fsSL https://get.vaktex.com/oss-vakt | sh -s -- --yes --summon --no-doctor
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Scan
run: vakt . --no-repo-ignores --fail-on 0.9 --format both
- name: Save report
if: always()
uses: actions/upload-artifact@v4
with:
name: vakt-report
path: vakt-report.json
if-no-files-found: ignore Hosted runners without a GPU use CPU inference. The example scans the checkout, not only the pull request diff. --no-repo-ignores prevents repository ignore files from concealing code from the scanner.
--fail-on 0.9 fails the scan step if a function scores at or above 0.9; it is an example policy, not a universally reliable cut-off. Review results on your codebase before making this a required check.
GitHub does not normally provide repository secrets to pull requests from forks. Such runs cannot use this token to download gated weights. Use a separately designed, trusted workflow for that case; do not expose secrets to untrusted pull request code through pull_request_target.
Scripts
Write a report to a file when both the results and the scanner’s exit status matter:
vakt ./repo --format json --out report.json --fail-on 0.9 Exit 1 means the failure threshold was met; exit 2 means the scan failed. Do not treat all nonzero exits as scanner errors or suppress them indiscriminately. See CLI usage for all exit codes and stdout output.