Sheriff-MCP
Sheriff-MCP
Sheriff es un servidor MCP que ayuda a los agentes de IA a corregir eficientemente problemas de análisis estático a partir de informes SARIF.
Documentación | Instalación | Referencia de herramientas
¿Por qué Sheriff?
Los agentes de IA tienen dificultades con los informes de análisis estático grandes:
Sobrecarga de contexto - Más de 100 problemas abruman las ventanas de contexto
Progreso perdido - El trabajo se pierde en la compactación de contexto o al reiniciar la sesión
Navegación ineficiente - Sin agrupación, se salta entre archivos repetidamente
Sheriff resuelve esto actuando como un gestor de cola de trabajo:
Agrupación inteligente - Problemas agrupados por archivo para una corrección eficiente
Progreso persistente - El estado sobrevive a la compactación, reinicios y cambios de agente
Filtrado por alcance - Enfócate en reglas, severidades o patrones de archivo específicos
Respuestas compactas - Uso mínimo de contexto con nombres de campos abreviados
Herramientas de análisis estático compatibles
Sheriff funciona con cualquier herramienta que produzca salida SARIF:
Herramienta | Lenguaje | Comando SARIF |
Qodana | Java/Kotlin/JS/Python |
|
Semgrep | Multilenguaje |
|
ESLint | JavaScript/TypeScript |
|
CodeQL | Multilenguaje | Salida SARIF integrada |
SpotBugs | Java |
|
Bandit | Python |
|
Checkov | IaC |
|
Trivy | Contenedor/IaC |
|
SonarQube | Multilenguaje | Exportación SARIF integrada |
Related MCP server: CodePeel MCP Server
Inicio rápido
1. Instalar
Descarga sheriff-mcp-1.0.2-all.jar desde Releases.
docker pull ghcr.io/ryansmith4/sheriff-mcp:latestLos clientes que admiten el MCP Registry pueden instalarlo directamente por nombre: io.github.ryansmith4/sheriff-mcp
Consulta la Guía de instalación para obtener todos los detalles.
2. Configura tu cliente MCP
Añade Sheriff a tu cliente MCP (Claude Code, Cursor, ChatGPT Desktop, etc.):
{
"mcpServers": {
"sheriff": {
"command": "java",
"args": ["-jar", "/path/to/sheriff-mcp-1.0.2-all.jar", "start"]
}
}
}O con Docker:
{
"mcpServers": {
"sheriff": {
"command": "docker",
"args": ["run", "-i", "--rm", "-v", ".:/data", "ghcr.io/ryansmith4/sheriff-mcp:latest"]
}
}
}Consulta la Guía de configuración del agente para obtener instrucciones específicas del cliente y recomendaciones de instrucciones para el agente.
3. Úsalo
1. Run static analysis → qodana scan
2. Load into Sheriff → sheriff load target="results.sarif"
3. Get next file's issues → sheriff next
4. Fix all issues in file → [edit the code]
5. Mark as done → sheriff done fps=[...] status="fixed"
6. Repeat 3-5 → until remaining = 0Sheriff expone una única herramienta sheriff con 7 acciones: load, next, done, progress, summary, reopen y export. Consulta la Referencia de herramientas para la documentación completa.
Ejemplo de sesión
User: "Fix all ConstantValue issues in my codebase"
Agent: sheriff load target="build/qodana/qodana.sarif.json"
→ 136 total issues, 22 ConstantValue, 15 unused...
Agent: sheriff next scope={rule: "ConstantValue"}
→ 3 issues in Service.java with code snippets
Agent: [reads Service.java, fixes all 3 issues]
Agent: sheriff done fps=["88d32cab35478753", "ab1c2d3e12345678", "f9e8d7c6a1b2c3d4"] status="fixed"
→ 3 marked fixed, 19 remaining
... continues until remaining = 0Seguridad
Todos los artefactos de lanzamiento están firmados con Sigstore para la seguridad de la cadena de suministro.
Verificar JAR:
VERSION=1.0.2
cosign verify-blob \
--signature sheriff-mcp-${VERSION}-all.jar.sig \
--certificate sheriff-mcp-${VERSION}-all.jar.pem \
--certificate-identity-regexp "https://github.com/ryansmith4/sheriff-mcp" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
sheriff-mcp-${VERSION}-all.jarVerificar imagen de Docker:
cosign verify ghcr.io/ryansmith4/sheriff-mcp:latest \
--certificate-oidc-issuer=https://token.actions.githubusercontent.com \
--certificate-identity-regexp="github.com/ryansmith4/sheriff-mcp"Consulta SECURITY.md para nuestra política de seguridad.
Contribuciones
¡Las contribuciones son bienvenidas! Consulta CONTRIBUTING.md para las pautas.
Licencia
Apache License 2.0 - consulta LICENSE
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
No tool schema history has been recorded yet.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
The issue tracker AI coding agents pull work from: atomic claims, dependency-aware dispatch.
Production-readiness for your AI coding agents.
Task management for teams building with AI agents. Agents claim tasks and report progress.
Give your AI agent a persistent map of your project's structure, dependencies, and bugs.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to scan GitHub repositories for security vulnerabilities, deployment blockers, and code quality issues. It provides detailed findings and auto-generated code patches to help developers ensure their code is production-ready.83MIT

CodePeel MCP Serverofficial
FlicenseAqualityDmaintenanceEnables AI agents to review code diffs for bugs, security issues, and bad patterns, and generate fixes.4-- FlicenseNot gradedqualityBmaintenanceEnables AI agents to scan codebases for TODO/FIXME/XXX patterns and get prioritized results over MCP, supporting CI gates and multiple output formats.-
- AlicenseAqualityBmaintenanceEnables AI agents to scan code for security vulnerabilities using multiple static analysis tools, with support for filtering, deduplication, and CI/CD integration.272MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ryansmith4/sheriff-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server