Seaworthy for AI coding agents
Last updated: October 2026
Seaworthy ships a built-in MCP (Model Context Protocol) server. Add it once and your AI coding agent can run a full security scan without leaving its loop — no terminal required, and everything runs locally on your machine.
What the agent gets
The server exposes two tools:
- scan — scan a directory you name explicitly and get compact, agent-readable findings
- get_finding — drill into one finding for its explanation and fix guidance
How it works
Register the server once, then just ask your agent to scan the project. The agent calls scan, reads the findings, fixes the code, and re-scans until it's clean.
Registering the server
Add Seaworthy to your client's MCP config. The free tier works with no setup; Pro tier uses the license key and LLM provider already stored in ~/.seaworthy/config.
Claude Code (.mcp.json), Cursor (.cursor/mcp.json), and Claude Desktop (claude_desktop_config.json)
{
"mcpServers": {
"seaworthy": {
"command": "npx",
"args": ["-y", "seaworthycode", "mcp"]
}
}
}VS Code (.vscode/mcp.json)
{
"servers": {
"seaworthy": {
"command": "npx",
"args": ["-y", "seaworthycode", "mcp"]
}
}
}Version pinning
npx resolves the newest published version each time your client spawns the server. To keep agent behaviour reproducible, pin the version (1.3.0 is the first release that ships the mcp subcommand):
"args": ["-y", "[email protected]", "mcp"]Plans and licensing
The MCP server is included in every plan. The free tier runs the core security checks with no account. Pro unlocks the full catalog plus LLM-assisted analysis with your own API key.
Privacy
The server runs locally over stdio. Scans read only the directory your agent names — never writing, never crawling outside it. The only outbound request is the license check; no code, paths, or findings ever reach Seaworthy servers.