Offline deterministic engineering-trust certificates for repositories, with no telemetry.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag — we're steadily working through the catalog.
💡 Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Cejel ("SEH-jel") — a trust certificate for your codebase.
Free, offline, no-signup CLI that scores the engineering signals that tell you whether to trust a repo — tests, secrets, isolation, claim-vs-reality, CI/audit discipline — and prints a trust certificate + badge. Especially valuable when AI wrote a lot of the code: that's exactly when you can't eyeball trust. Built on a deterministic, no-LLM scoring core — the free path makes zero network calls and requires no account.
Claim boundary: Cejel scores engineering-trust signals; it does not claim to detect software defects or prove that code is safe. Defect and vulnerability scanners remain evidence producers that Cejel can aggregate into a trust certificate.
Cejel is not another point scanner competing with the one you already run — it's the open, portable, offline trust certificate that aggregates them. Pipe in SARIF-compatible output (MunaTrust, Snyk, Semgrep, CodeQL, Codex) plus OpenSSF Scorecard, and get one shareable certificate + badge over all of them. See "Aggregate your scanners" below.
Cejel is used on Barg Labs’ own code. The public board labels publisher-owned snapshots separately from the ranked public repositories.
The public CLI default is witan-rubric-v17-2026-07-24, the last rubric to clear Cejel's
preregistered 200-repository untouched holdout. Published calibration figures apply only to that
exact rubric and frozen evaluation population. Later rubrics—including the current v18 through
v23 prospective series—are available only to explicit evaluation harnesses. Prospective rubrics
inherit none of v17's calibration figures; a bounded paired repair or corpus-delta result can
validate its stated construction without transferring precision, recall, or false-positive-rate
claims. Promoting a prospective rubric to the public default requires a fresh authenticated
untouched holdout, every preregistered gate to pass, and a separately recorded promotion decision.
Measured recall (bounded). Cejel publishes one cohort-level in-scope detection-recall figure, for the prospective v22 rubric, in
docs/calibration/v22-detection-recall/; no general figure exists, and the three quantities called recall are set side by side on cejel.dev/methodology. On a frozen, preregistered, in-scope held-out fixture set of 30 named defects, the released public default (v17, treea857f0b3) cited 16/30, two-sided 95% Wilson interval [36.1%, 69.8%]; the prospective v22 detector (commit8a289ea, tree10960a03) cited 24/30, two-sided 95% Wilson interval [62.7%, 90.5%]. Same fixtures, same partition, same controls in both runs. v22 is prospective and not the shipped default. Full preregistrations and results:docs/experiments/in-scope-detection-recall-v3-result-2026-08-09.mdanddocs/experiments/in-scope-detection-recall-v4-result-2026-08-11.md.
The defect-class census publishes the coverage-breadth boundary—which defect classes any shipped rule targets—and is explicitly not a recall claim.
No account, no key, no signup.
Single-file binary. One file. No Node, no npm, no node_modules, nothing installed.
Windows x86_64 (PowerShell).
Windows signing status:
cejel-Windows-x86_64.exeis intentionally unsigned in 0.4.10 and may trigger Microsoft SmartScreen. The release build removes Node's inherited signature before SEA injection and fails unless Windows reports the result asNotSigned; it does not ship an invalid signature. Before running it, verifySHA256SUMSand the GitHub build-provenance attestation. Each binary also has an attached SPDX SBOM and an own-platform verification receipt covering--version,--help, a real scan, source/binary parity, and a network-denied scan. If your policy requires Authenticode, use the npm package or the OCI image until a human-approved signing path is available.
Don't take the offline claim on trust — check it. Turn your network off, then run the binary. It will score your repository and write you a certificate anyway. That is the whole product, and you can falsify it in ten seconds:
npm.
Distribution note: Cejel
0.4.10is the coordinated release version for npm, standalone binaries, Docker/OCI, GitHub Action, Homebrew, and MCP Registry.
npx can reuse a stale cached package. Force the current npm release with the @latest
specifier above, and check the version that will run before comparing certificates:
If a root package.json still carries a template name, override only the certificate display
name while keeping the repository-derived stable slug:
From 0.4.5, use --product-name when two checkout directories must emit the
same identity fields. The supplied value sets both the display name and its slugified stable ID:
Product identity is caller context, not scored repository evidence, and is excluded from certificate byte-comparison claims.
The npm package is scoped as @cejel/cejel; its executable remains the short command cejel.
GitHub Action — score every PR and publish the badge:
For an executed public example that binds a release artifact to the same commit named by its Cejel certificate, see Certified releases with GitHub build provenance.
From source — it is AGPL and it runs offline, so reading it is rather the point:
Released binaries: cejel-Darwin-arm64, cejel-Darwin-x86_64, cejel-Linux-aarch64,
cejel-Linux-x86_64, and cejel-Windows-x86_64.exe. The release also carries
SHA256SUMS, a per-binary SPDX SBOM, and an own-platform verification receipt. Each binary
is executed against the source build and with networking denied before attachment. Releases
from v0.1.6 also carry a Sigstore bundle containing GitHub's signed build-provenance
attestation for the release set. Verify a downloaded binary with:
This is cryptographically signed provenance. It is distinct from Apple Developer ID or Microsoft Authenticode code-signing.
Docker / OCI. The current container release is 0.4.10:
The image defaults to cejel-mcp over stdio. To use the CLI instead:
The OCI image carries an SBOM, maximum-mode build provenance, and a signed registry attestation.
The Cejel OSS trust leaderboard is hosted on cejel.dev, which is the single current board. This repository no longer distributes a second copy of its scores or certificates. The board records its producing package version, rubric, run date, pinned public revisions, and reproduction instructions for that particular run. The private Alfred transparency snapshot is not independently reproducible.
The site's History section preserves the 2026-08-18 withdrawal: the earlier sealed-public-scorer reproducibility claim was false. The stale prospective-rubric copy previously linked here has been removed; it must not be treated as current evidence.
Factual signals from GitHub, npm, and our automated checks — not a rating.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/cejel)<a href="https://allmcps.com/mcp/cejel"><img src="https://allmcps.com/api/badge/cejel?style=directory" alt="Cejel on AllMCPs" /></a>