Skip to main content
Glama

Sheriff-MCP

CI OpenSSF Scorecard OpenSSF Best Practices License Java 21+ GitHub release

Sheriff is an MCP server that helps AI agents efficiently fix static analysis issues from SARIF reports.

Documentation | Installation | Tool Reference


Why Sheriff?

AI agents struggle with large static analysis reports:

  • Context overload - 100+ issues overwhelm context windows

  • Lost progress - Work is lost on context compaction or session restart

  • Inefficient navigation - No batching means jumping between files repeatedly

Sheriff solves this by acting as a work queue manager:

  • Intelligent batching - Issues grouped by file for efficient fixing

  • Persistent progress - State survives compaction, restarts, and agent switches

  • Scope filtering - Focus on specific rules, severities, or file patterns

  • Compact responses - Minimal context usage with abbreviated field names

Supported Static Analysis Tools

Sheriff works with any tool that produces SARIF output:

Tool

Language

SARIF Command

Qodana

Java/Kotlin/JS/Python

qodana scan

Semgrep

Multi-language

semgrep --sarif -o results.sarif

ESLint

JavaScript/TypeScript

eslint --format @microsoft/sarif

CodeQL

Multi-language

Built-in SARIF output

SpotBugs

Java

spotbugs -sarif

Bandit

Python

bandit -f sarif

Checkov

IaC

checkov -o sarif

Trivy

Container/IaC

trivy --format sarif

SonarQube

Multi-language

Built-in SARIF export


Related MCP server: CodePeel MCP Server

Quick Start

1. Install

Download sheriff-mcp-1.0.2-all.jar from Releases.

docker pull ghcr.io/ryansmith4/sheriff-mcp:latest

Clients that support the MCP Registry can install directly by name: io.github.ryansmith4/sheriff-mcp

See the Installation Guide for full details.

2. Configure Your MCP Client

Add Sheriff to your MCP client (Claude Code, Cursor, ChatGPT Desktop, etc.):

{
  "mcpServers": {
    "sheriff": {
      "command": "java",
      "args": ["-jar", "/path/to/sheriff-mcp-1.0.2-all.jar", "start"]
    }
  }
}

Or with Docker:

{
  "mcpServers": {
    "sheriff": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "-v", ".:/data", "ghcr.io/ryansmith4/sheriff-mcp:latest"]
    }
  }
}

See the Agent Setup Guide for client-specific instructions and recommended agent instructions.

3. Use It

1. Run static analysis     →  qodana scan
2. Load into Sheriff       →  sheriff load target="results.sarif"
3. Get next file's issues  →  sheriff next
4. Fix all issues in file  →  [edit the code]
5. Mark as done            →  sheriff done fps=[...] status="fixed"
6. Repeat 3-5              →  until remaining = 0

Sheriff exposes a single sheriff tool with 7 actions: load, next, done, progress, summary, reopen, and export. See the Tool Reference for full documentation.


Example Session

User: "Fix all ConstantValue issues in my codebase"

Agent: sheriff load target="build/qodana/qodana.sarif.json"
       → 136 total issues, 22 ConstantValue, 15 unused...

Agent: sheriff next scope={rule: "ConstantValue"}
       → 3 issues in Service.java with code snippets

Agent: [reads Service.java, fixes all 3 issues]

Agent: sheriff done fps=["88d32cab35478753", "ab1c2d3e12345678", "f9e8d7c6a1b2c3d4"] status="fixed"
       → 3 marked fixed, 19 remaining

       ... continues until remaining = 0

Security

All release artifacts are signed with Sigstore for supply chain security.

Verify JAR:

VERSION=1.0.2
cosign verify-blob \
  --signature sheriff-mcp-${VERSION}-all.jar.sig \
  --certificate sheriff-mcp-${VERSION}-all.jar.pem \
  --certificate-identity-regexp "https://github.com/ryansmith4/sheriff-mcp" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  sheriff-mcp-${VERSION}-all.jar

Verify Docker image:

cosign verify ghcr.io/ryansmith4/sheriff-mcp:latest \
  --certificate-oidc-issuer=https://token.actions.githubusercontent.com \
  --certificate-identity-regexp="github.com/ryansmith4/sheriff-mcp"

See SECURITY.md for our security policy.


Contributing

Contributions welcome! See CONTRIBUTING.md for guidelines.

License

Apache License 2.0 - see LICENSE

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

No tool schema history has been recorded yet.

Maintenance

ActivityNo data
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI agents to scan GitHub repositories for security vulnerabilities, deployment blockers, and code quality issues. It provides detailed findings and auto-generated code patches to help developers ensure their code is production-ready.
    83
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to scan codebases for TODO/FIXME/XXX patterns and get prioritized results over MCP, supporting CI gates and multiple output formats.
    -
  • A
    license
    A
    quality
    A
    maintenance
    Enables AI agents to scan code for security vulnerabilities using multiple static analysis tools, with support for filtering, deduplication, and CI/CD integration.
    27
    2
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/ryansmith4/sheriff-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server