Sheriff-MCP
Sheriff-MCP
Sheriff ist ein MCP-Server, der KI-Agenten dabei hilft, statische Analyseprobleme aus SARIF-Berichten effizient zu beheben.
Dokumentation | Installation | Tool-Referenz
Warum Sheriff?
KI-Agenten kämpfen mit großen statischen Analyseberichten:
Kontextüberlastung – 100+ Probleme überfordern Kontextfenster
Verlorener Fortschritt – Arbeit geht bei Kontextkomprimierung oder Sitzungsneustart verloren
Ineffiziente Navigation – Keine Stapelverarbeitung bedeutet wiederholtes Springen zwischen Dateien
Sheriff löst dies, indem er als Work-Queue-Manager fungiert:
Intelligente Stapelverarbeitung – Probleme nach Datei gruppiert für effizientes Beheben
Persistenter Fortschritt – Zustand übersteht Komprimierung, Neustarts und Agentenwechsel
Bereichsfilterung – Fokus auf bestimmte Regeln, Schweregrade oder Dateimuster
Kompakte Antworten – Minimaler Kontextverbrauch mit abgekürzten Feldnamen
Unterstützte statische Analysetools
Sheriff funktioniert mit jedem Tool, das SARIF-Ausgabe erzeugt:
Werkzeug | Sprache | SARIF-Befehl |
Qodana | Java/Kotlin/JS/Python |
|
Semgrep | Mehrsprachig |
|
ESLint | JavaScript/TypeScript |
|
CodeQL | Mehrsprachig | Integrierte SARIF-Ausgabe |
SpotBugs | Java |
|
Bandit | Python |
|
Checkov | IaC |
|
Trivy | Container/IaC |
|
SonarQube | Mehrsprachig | Integrierter SARIF-Export |
Related MCP server: CodePeel MCP Server
Schnellstart
1. Installieren
Laden Sie sheriff-mcp-1.0.2-all.jar von Releases herunter.
docker pull ghcr.io/ryansmith4/sheriff-mcp:latestClients, die die MCP-Registry unterstützen, können direkt per Name installieren: io.github.ryansmith4/sheriff-mcp
Siehe die Installationsanleitung für vollständige Details.
2. Konfigurieren Sie Ihren MCP-Client
Fügen Sie Sheriff zu Ihrem MCP-Client hinzu (Claude Code, Cursor, ChatGPT Desktop usw.):
{
"mcpServers": {
"sheriff": {
"command": "java",
"args": ["-jar", "/path/to/sheriff-mcp-1.0.2-all.jar", "start"]
}
}
}Oder mit Docker:
{
"mcpServers": {
"sheriff": {
"command": "docker",
"args": ["run", "-i", "--rm", "-v", ".:/data", "ghcr.io/ryansmith4/sheriff-mcp:latest"]
}
}
}Siehe die Agent-Setup-Anleitung für clientspezifische Anweisungen und empfohlene Agent-Anweisungen.
3. Verwenden Sie es
1. Run static analysis → qodana scan
2. Load into Sheriff → sheriff load target="results.sarif"
3. Get next file's issues → sheriff next
4. Fix all issues in file → [edit the code]
5. Mark as done → sheriff done fps=[...] status="fixed"
6. Repeat 3-5 → until remaining = 0Sheriff stellt ein einzelnes sheriff-Tool mit 7 Aktionen bereit: load, next, done, progress, summary, reopen und export. Siehe die Tool-Referenz für die vollständige Dokumentation.
Beispielsitzung
User: "Fix all ConstantValue issues in my codebase"
Agent: sheriff load target="build/qodana/qodana.sarif.json"
→ 136 total issues, 22 ConstantValue, 15 unused...
Agent: sheriff next scope={rule: "ConstantValue"}
→ 3 issues in Service.java with code snippets
Agent: [reads Service.java, fixes all 3 issues]
Agent: sheriff done fps=["88d32cab35478753", "ab1c2d3e12345678", "f9e8d7c6a1b2c3d4"] status="fixed"
→ 3 marked fixed, 19 remaining
... continues until remaining = 0Sicherheit
Alle Release-Artefakte sind für die Lieferkettensicherheit mit Sigstore signiert.
JAR verifizieren:
VERSION=1.0.2
cosign verify-blob \
--signature sheriff-mcp-${VERSION}-all.jar.sig \
--certificate sheriff-mcp-${VERSION}-all.jar.pem \
--certificate-identity-regexp "https://github.com/ryansmith4/sheriff-mcp" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
sheriff-mcp-${VERSION}-all.jarDocker-Image verifizieren:
cosign verify ghcr.io/ryansmith4/sheriff-mcp:latest \
--certificate-oidc-issuer=https://token.actions.githubusercontent.com \
--certificate-identity-regexp="github.com/ryansmith4/sheriff-mcp"Siehe SECURITY.md für unsere Sicherheitsrichtlinie.
Mitwirken
Beiträge willkommen! Siehe CONTRIBUTING.md für Richtlinien.
Lizenz
Apache License 2.0 – siehe LICENSE
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
No tool schema history has been recorded yet.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
The issue tracker AI coding agents pull work from: atomic claims, dependency-aware dispatch.
Production-readiness for your AI coding agents.
Task management for teams building with AI agents. Agents claim tasks and report progress.
Give your AI agent a persistent map of your project's structure, dependencies, and bugs.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to scan GitHub repositories for security vulnerabilities, deployment blockers, and code quality issues. It provides detailed findings and auto-generated code patches to help developers ensure their code is production-ready.83MIT

CodePeel MCP Serverofficial
FlicenseAqualityDmaintenanceEnables AI agents to review code diffs for bugs, security issues, and bad patterns, and generate fixes.4-- FlicenseNot gradedqualityBmaintenanceEnables AI agents to scan codebases for TODO/FIXME/XXX patterns and get prioritized results over MCP, supporting CI gates and multiple output formats.-
- AlicenseAqualityBmaintenanceEnables AI agents to scan code for security vulnerabilities using multiple static analysis tools, with support for filtering, deduplication, and CI/CD integration.272MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ryansmith4/sheriff-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server