# Joern (Code Analysis)

> Use this tool when you need to analyze code structure and dependencies, identify vulnerabilities, or perform static code analysis. It provides a Python interface to query and analyze Code Property Graphs (CPGs), allowing for examination of call relationships and execution of custom queries. Ideal for security researchers and developers, it enables AI assistants to access code analysis capabilities through a server implementation.

Canonical page: https://skillsregistry.net/skills/joern-code-analysis  
JSON: https://api.skillsregistry.net/v1/skills/joern-code-analysis

## Description

Joern-MCP is a server implementation that provides AI assistants with access to Joern's code analysis capabilities through a Python interface. This server enables querying and analyzing Code Property Graphs (CPGs) by exposing tools for loading CPGs, retrieving method and class code, examining call relationships, and executing custom queries against the Joern backend. Built on the FastMCP framework, it handles communication with a remote Joern instance via HTTP requests, making it particularly valuable for security researchers and developers who need to perform static code analysis, identify vulnerabilities, or understand code structure and dependencies through AI assistants.

## Trust

- **Trust score (0–1):** 0.64
- **Verification tier:** scanned
- **Last scanned:** 2026-09-02

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-02

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/joern-code-analysis)
- **Repository:** <https://github.com/sfncat/mcp-joern>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "joern-code-analysis"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/joern-code-analysis` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/joern-code-analysis/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
