Skip to main content
Glama

Sheriff-MCP

CI OpenSSF Scorecard OpenSSF Best Practices License Java 21+ GitHub release

Sheriff es un servidor MCP que ayuda a los agentes de IA a corregir eficientemente problemas de análisis estático a partir de informes SARIF.

Documentación | Instalación | Referencia de herramientas


¿Por qué Sheriff?

Los agentes de IA tienen dificultades con los informes de análisis estático grandes:

  • Sobrecarga de contexto - Más de 100 problemas abruman las ventanas de contexto

  • Progreso perdido - El trabajo se pierde en la compactación de contexto o al reiniciar la sesión

  • Navegación ineficiente - Sin agrupación, se salta entre archivos repetidamente

Sheriff resuelve esto actuando como un gestor de cola de trabajo:

  • Agrupación inteligente - Problemas agrupados por archivo para una corrección eficiente

  • Progreso persistente - El estado sobrevive a la compactación, reinicios y cambios de agente

  • Filtrado por alcance - Enfócate en reglas, severidades o patrones de archivo específicos

  • Respuestas compactas - Uso mínimo de contexto con nombres de campos abreviados

Herramientas de análisis estático compatibles

Sheriff funciona con cualquier herramienta que produzca salida SARIF:

Herramienta

Lenguaje

Comando SARIF

Qodana

Java/Kotlin/JS/Python

qodana scan

Semgrep

Multilenguaje

semgrep --sarif -o results.sarif

ESLint

JavaScript/TypeScript

eslint --format @microsoft/sarif

CodeQL

Multilenguaje

Salida SARIF integrada

SpotBugs

Java

spotbugs -sarif

Bandit

Python

bandit -f sarif

Checkov

IaC

checkov -o sarif

Trivy

Contenedor/IaC

trivy --format sarif

SonarQube

Multilenguaje

Exportación SARIF integrada


Related MCP server: CodePeel MCP Server

Inicio rápido

1. Instalar

Descarga sheriff-mcp-1.0.2-all.jar desde Releases.

docker pull ghcr.io/ryansmith4/sheriff-mcp:latest

Los clientes que admiten el MCP Registry pueden instalarlo directamente por nombre: io.github.ryansmith4/sheriff-mcp

Consulta la Guía de instalación para obtener todos los detalles.

2. Configura tu cliente MCP

Añade Sheriff a tu cliente MCP (Claude Code, Cursor, ChatGPT Desktop, etc.):

{
  "mcpServers": {
    "sheriff": {
      "command": "java",
      "args": ["-jar", "/path/to/sheriff-mcp-1.0.2-all.jar", "start"]
    }
  }
}

O con Docker:

{
  "mcpServers": {
    "sheriff": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "-v", ".:/data", "ghcr.io/ryansmith4/sheriff-mcp:latest"]
    }
  }
}

Consulta la Guía de configuración del agente para obtener instrucciones específicas del cliente y recomendaciones de instrucciones para el agente.

3. Úsalo

1. Run static analysis     →  qodana scan
2. Load into Sheriff       →  sheriff load target="results.sarif"
3. Get next file's issues  →  sheriff next
4. Fix all issues in file  →  [edit the code]
5. Mark as done            →  sheriff done fps=[...] status="fixed"
6. Repeat 3-5              →  until remaining = 0

Sheriff expone una única herramienta sheriff con 7 acciones: load, next, done, progress, summary, reopen y export. Consulta la Referencia de herramientas para la documentación completa.


Ejemplo de sesión

User: "Fix all ConstantValue issues in my codebase"

Agent: sheriff load target="build/qodana/qodana.sarif.json"
       → 136 total issues, 22 ConstantValue, 15 unused...

Agent: sheriff next scope={rule: "ConstantValue"}
       → 3 issues in Service.java with code snippets

Agent: [reads Service.java, fixes all 3 issues]

Agent: sheriff done fps=["88d32cab35478753", "ab1c2d3e12345678", "f9e8d7c6a1b2c3d4"] status="fixed"
       → 3 marked fixed, 19 remaining

       ... continues until remaining = 0

Seguridad

Todos los artefactos de lanzamiento están firmados con Sigstore para la seguridad de la cadena de suministro.

Verificar JAR:

VERSION=1.0.2
cosign verify-blob \
  --signature sheriff-mcp-${VERSION}-all.jar.sig \
  --certificate sheriff-mcp-${VERSION}-all.jar.pem \
  --certificate-identity-regexp "https://github.com/ryansmith4/sheriff-mcp" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  sheriff-mcp-${VERSION}-all.jar

Verificar imagen de Docker:

cosign verify ghcr.io/ryansmith4/sheriff-mcp:latest \
  --certificate-oidc-issuer=https://token.actions.githubusercontent.com \
  --certificate-identity-regexp="github.com/ryansmith4/sheriff-mcp"

Consulta SECURITY.md para nuestra política de seguridad.


Contribuciones

¡Las contribuciones son bienvenidas! Consulta CONTRIBUTING.md para las pautas.

Licencia

Apache License 2.0 - consulta LICENSE

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

No tool schema history has been recorded yet.

Maintenance

ActivityNo data
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI agents to scan GitHub repositories for security vulnerabilities, deployment blockers, and code quality issues. It provides detailed findings and auto-generated code patches to help developers ensure their code is production-ready.
    83
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to scan codebases for TODO/FIXME/XXX patterns and get prioritized results over MCP, supporting CI gates and multiple output formats.
    -
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to scan code for security vulnerabilities using multiple static analysis tools, with support for filtering, deduplication, and CI/CD integration.
    27
    2
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/ryansmith4/sheriff-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server