# Joern

> Use this tool when you need to analyze codebases for security vulnerabilities, assess code quality, and calculate metrics, as it provides AI assistants with static code analysis capabilities through automated generation of Code Property Graphs (CPGs) from GitHub repositories or local paths. It supports multiple programming languages and executes custom queries for deep code structure analysis, making it ideal for automated code review workflows and security auditing. The tool outputs comprehensive analysis results, including security vulnerability detection and code quality assessments, through a Python and Docker integrated interface.

Canonical page: https://skillsregistry.net/skills/lekssays-joern  
JSON: https://api.skillsregistry.net/v1/skills/lekssays-joern

## Description

Joern MCP Server provides AI assistants with static code analysis capabilities using Joern's Code Property Graph (CPG) technology in isolated Docker environments. Built with Python and Docker integration, it supports loading projects from GitHub repositories or local paths, automatically detects programming languages (C/C++, Java, JavaScript, Python, Go, Kotlin, Scala, C#), generates CPGs for deep code structure analysis, and executes Joern queries for security vulnerability detection, code quality assessment, and metrics calculation. The server includes comprehensive caching, resource management, and pre-built query templates for common security patterns like SQL injection and XSS vulnerabilities, making it valuable for automated code review workflows, security auditing, and building AI assistants that need to understand and analyze codebases at scale.

## Trust

- **Trust score (0–1):** 0.59
- **Verification tier:** scanned
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/lekssays-joern)
- **Repository:** <https://github.com/lekssays/codebadger>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "lekssays-joern"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/lekssays-joern` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/lekssays-joern/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
