# CodeQL

> Use this tool when you need to analyze codebases for security vulnerabilities and quality issues, and integrate static analysis capabilities into AI-powered development workflows. It solves problems such as identifying potential security threats and code quality issues, and provides inputs including codebases and queries, with outputs of structured analysis results. It is particularly useful in contexts where security researchers and developers require automated code analysis and insights without manual CLI interactions.

Canonical page: https://skillsregistry.net/skills/jordyzomer-codeql  
JSON: https://api.skillsregistry.net/v1/skills/jordyzomer-codeql

## Description

CodeQL MCP Server provides a bridge to the CodeQL static analysis engine, enabling AI assistants to analyze codebases for security vulnerabilities and quality issues. The implementation offers tools for registering CodeQL databases, evaluating queries against codebases, decoding query results, and performing quick evaluations of specific classes or predicates. Built with Python using the FastMCP framework, it exposes a simple API that handles the complexities of CodeQL operations while providing structured results that can be easily interpreted by language models. This server is particularly valuable for security researchers and developers who want to leverage AI assistants for code analysis without directly interacting with the CodeQL CLI.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/jordyzomer-codeql)
- **Repository:** <https://github.com/jordyzomer/codeql-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "jordyzomer-codeql"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/jordyzomer-codeql` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/jordyzomer-codeql/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
