Sheriff-MCP
Enables loading, batching, and tracking of static analysis issues from ESLint SARIF reports, allowing agents to efficiently fix JavaScript code quality problems.
Enables loading, batching, and tracking of static analysis issues from SonarQube SARIF reports, facilitating systematic resolution of code quality and security problems.
Enables loading, batching, and tracking of security vulnerabilities and infrastructure issues from Trivy SARIF reports, helping agents focus on fixing high-priority findings.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Sheriff-MCPLoad the SARIF report and show me the next batch of issues to fix"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Sheriff-MCP
Sheriff is an MCP server that helps AI agents efficiently fix static analysis issues from SARIF reports.
Documentation | Installation | Tool Reference
Why Sheriff?
AI agents struggle with large static analysis reports:
Context overload - 100+ issues overwhelm context windows
Lost progress - Work is lost on context compaction or session restart
Inefficient navigation - No batching means jumping between files repeatedly
Sheriff solves this by acting as a work queue manager:
Intelligent batching - Issues grouped by file for efficient fixing
Persistent progress - State survives compaction, restarts, and agent switches
Scope filtering - Focus on specific rules, severities, or file patterns
Compact responses - Minimal context usage with abbreviated field names
Supported Static Analysis Tools
Sheriff works with any tool that produces SARIF output:
Tool | Language | SARIF Command |
Qodana | Java/Kotlin/JS/Python |
|
Semgrep | Multi-language |
|
ESLint | JavaScript/TypeScript |
|
CodeQL | Multi-language | Built-in SARIF output |
SpotBugs | Java |
|
Bandit | Python |
|
Checkov | IaC |
|
Trivy | Container/IaC |
|
SonarQube | Multi-language | Built-in SARIF export |
Related MCP server: CodePeel MCP Server
Quick Start
1. Install
Download sheriff-mcp-1.0.2-all.jar from Releases.
docker pull ghcr.io/ryansmith4/sheriff-mcp:latestClients that support the MCP Registry can install directly by name: io.github.ryansmith4/sheriff-mcp
See the Installation Guide for full details.
2. Configure Your MCP Client
Add Sheriff to your MCP client (Claude Code, Cursor, ChatGPT Desktop, etc.):
{
"mcpServers": {
"sheriff": {
"command": "java",
"args": ["-jar", "/path/to/sheriff-mcp-1.0.2-all.jar", "start"]
}
}
}Or with Docker:
{
"mcpServers": {
"sheriff": {
"command": "docker",
"args": ["run", "-i", "--rm", "-v", ".:/data", "ghcr.io/ryansmith4/sheriff-mcp:latest"]
}
}
}See the Agent Setup Guide for client-specific instructions and recommended agent instructions.
3. Use It
1. Run static analysis → qodana scan
2. Load into Sheriff → sheriff load target="results.sarif"
3. Get next file's issues → sheriff next
4. Fix all issues in file → [edit the code]
5. Mark as done → sheriff done fps=[...] status="fixed"
6. Repeat 3-5 → until remaining = 0Sheriff exposes a single sheriff tool with 7 actions: load, next, done, progress, summary, reopen, and export. See the Tool Reference for full documentation.
Example Session
User: "Fix all ConstantValue issues in my codebase"
Agent: sheriff load target="build/qodana/qodana.sarif.json"
→ 136 total issues, 22 ConstantValue, 15 unused...
Agent: sheriff next scope={rule: "ConstantValue"}
→ 3 issues in Service.java with code snippets
Agent: [reads Service.java, fixes all 3 issues]
Agent: sheriff done fps=["88d32cab35478753", "ab1c2d3e12345678", "f9e8d7c6a1b2c3d4"] status="fixed"
→ 3 marked fixed, 19 remaining
... continues until remaining = 0Security
All release artifacts are signed with Sigstore for supply chain security.
Verify JAR:
VERSION=1.0.2
cosign verify-blob \
--signature sheriff-mcp-${VERSION}-all.jar.sig \
--certificate sheriff-mcp-${VERSION}-all.jar.pem \
--certificate-identity-regexp "https://github.com/ryansmith4/sheriff-mcp" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
sheriff-mcp-${VERSION}-all.jarVerify Docker image:
cosign verify ghcr.io/ryansmith4/sheriff-mcp:latest \
--certificate-oidc-issuer=https://token.actions.githubusercontent.com \
--certificate-identity-regexp="github.com/ryansmith4/sheriff-mcp"See SECURITY.md for our security policy.
Contributing
Contributions welcome! See CONTRIBUTING.md for guidelines.
License
Apache License 2.0 - see LICENSE
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
No tool schema history has been recorded yet.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
The issue tracker AI coding agents pull work from: atomic claims, dependency-aware dispatch.
Production-readiness for your AI coding agents.
Task management for teams building with AI agents. Agents claim tasks and report progress.
Give your AI agent a persistent map of your project's structure, dependencies, and bugs.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to scan GitHub repositories for security vulnerabilities, deployment blockers, and code quality issues. It provides detailed findings and auto-generated code patches to help developers ensure their code is production-ready.83MIT

CodePeel MCP Serverofficial
FlicenseAqualityDmaintenanceEnables AI agents to review code diffs for bugs, security issues, and bad patterns, and generate fixes.4-- FlicenseNot gradedqualityBmaintenanceEnables AI agents to scan codebases for TODO/FIXME/XXX patterns and get prioritized results over MCP, supporting CI gates and multiple output formats.-
- AlicenseAqualityAmaintenanceEnables AI agents to scan code for security vulnerabilities using multiple static analysis tools, with support for filtering, deduplication, and CI/CD integration.272MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/ryansmith4/sheriff-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server