Seaworthy for AI coding agents

Last updated: October 2026

Seaworthy ships a built-in MCP (Model Context Protocol) server. Add it once and your AI coding agent can run a full security scan without leaving its loop — no terminal required, and everything runs locally on your machine.

What the agent gets

The server exposes two tools:

  • scan — scan a directory you name explicitly and get compact, agent-readable findings
  • get_finding — drill into one finding for its explanation and fix guidance

How it works

Register the server once, then just ask your agent to scan the project. The agent calls scan, reads the findings, fixes the code, and re-scans until it's clean.

Registering the server

Add Seaworthy to your client's MCP config. The free tier works with no setup; Pro tier uses the license key and LLM provider already stored in ~/.seaworthy/config.

Claude Code (.mcp.json), Cursor (.cursor/mcp.json), and Claude Desktop (claude_desktop_config.json)

{
  "mcpServers": {
    "seaworthy": {
      "command": "npx",
      "args": ["-y", "seaworthycode", "mcp"]
    }
  }
}

VS Code (.vscode/mcp.json)

{
  "servers": {
    "seaworthy": {
      "command": "npx",
      "args": ["-y", "seaworthycode", "mcp"]
    }
  }
}

Version pinning

npx resolves the newest published version each time your client spawns the server. To keep agent behaviour reproducible, pin the version (1.3.0 is the first release that ships the mcp subcommand):

"args": ["-y", "[email protected]", "mcp"]

Plans and licensing

The MCP server is included in every plan. The free tier runs the core security checks with no account. Pro unlocks the full catalog plus LLM-assisted analysis with your own API key.

Privacy

The server runs locally over stdio. Scans read only the directory your agent names — never writing, never crawling outside it. The only outbound request is the license check; no code, paths, or findings ever reach Seaworthy servers.