MCP server for running Ox Security MegaLinter via mega-linter-runner
io.github.DownAtTheBottomOfTheMoleHole/megalinter MCP Server
This MCP server runs Ox Security MegaLinter via a mega-linter-runner. It exposes tooling for developer workflows that integrate linting and security checks in environments that support the Model Context Protocol. The project is community-maintained and positioned as a complement to Ox Securityβs official MegaLinter tools.
π οΈ Key Features
Runs Ox Security MegaLinter via mega-linter-runner
Tooling count: 3
π Use Cases
DevSecOps linting in automated pipelines
Integration with GitHub Actions workflows
Model Context Protocol-based tooling for MegaLinter
β‘ Developer Benefits
Supports topics aligned with linting and MegaLinter usage: devsecops, github-actions, linting, megalinter
Includes MCP-focused implementation details (MCP, model-context-protocol)
β οΈ Limitations
Community-maintained; not an official Model Context Protocol server
Sanctioned by Ox Security only as a complement to official MegaLinter tools
Note: This is a community-maintained MCP server. It is not an official Model Context Protocol server, but it is sanctioned by Ox Security as a complement to their official MegaLinter tools.
A Model Context Protocol (MCP) server for running Ox Security MegaLinter through mega-linter-runner. Works with any CI/CD platform (GitHub Actions, GitLab CI, Azure DevOps, CircleCI, Jenkins) or locally.
Overview
This server provides 15 MCP tools in total: 10 core tools and 5 convenience aliases across execution, discovery, and analysis workflows.
megalinter_quick_action for short, natural requests with sensible defaults.
megalinter_run to execute MegaLinter with configurable runtime and runner options.
megalinter_write_config to generate a minimal .mega-linter.yml file.
megalinter_list_flavors to return common MegaLinter flavors.
megalinter_get_linters to discover available linters by language, security focus, and auto-fix capability.
megalinter_get_security_info to group security linters by threat category.
megalinter_get_reporters to list supported report output formats and CI-targeted reporters.
megalinter_parse_reports to parse JSON or SARIF report artefacts.
megalinter_get_issue_summary to aggregate report issues by linter and severity.
megalinter_get_security_recommendations to generate security-focused remediation guidance.
Quick Start (Short Prompts)
If you prefer short prompts, use megalinter_quick_action first:
@megalinter quick scan this repository
@megalinter security scan
@megalinter summarise errors
@megalinter list python security linters
@megalinter write config
Or use ultra-short aliases for minimal typing:
@megalinter scan β Quick scan with defaults
@megalinter summary β Summarise last run's errors
@megalinter parse β Parse JSON report
@megalinter help_quick β Context-aware help for your project
Platform Compatibility
This MCP server is platform-agnostic and works universally:
β Locally β Run MegaLinter from your IDE or command line
β GitHub Actions β Integrate with workflows
β GitLab CI/CD β Use in GitLab pipelines
β Azure DevOps β Run in Azure Pipelines
β CircleCI, Jenkins, Bitbucket Pipelines β Any CI/CD platform with Docker support
β AI Agents & Copilot β Automated code quality checks via MCP
The only requirement is Docker (or a compatible container runtime like Colima).
Tool Matrix
Tool
Category
Typical outcome
megalinter_quick_action
Interactive
Handle short natural requests with defaults
scan
Alias
Ultra-short alias for quick scan
summary
Alias
Ultra-short alias for error summary
parse
Alias
Ultra-short alias for report parsing
help_quick
Alias
Ultra-short alias for context-aware help
megalinter_help_quick
Help
Context-aware suggestions for your project
megalinter_run
Execution
Run linting and produce report artefacts
megalinter_write_config
Configuration
Generate baseline .mega-linter.yml
megalinter_list_flavors
Discovery
Identify an appropriate flavour for your stack
megalinter_get_linters
Discovery
Filter linters by language, security, and auto-fix support
megalinter_get_security_info
Discovery
View security linters grouped by SAST, secrets, container, and IaC
megalinter_get_reporters
Discovery
Select output/reporting formats for local and CI workflows
megalinter_parse_reports
Analysis
Read JSON or SARIF reports in structured form
megalinter_get_issue_summary
Analysis
Summarise issue totals and top failing linters
megalinter_get_security_recommendations
Analysis
Produce practical shift-left security actions
Tools
megalinter_quick_action
Interactive shortcut that accepts a short request and routes it to the right workflow.
Inputs:
request (string, optional): Short instruction. Default: quick scan.
Example: @megalinter parse parses the JSON report.
megalinter_help_quick
Get context-aware help based on your current repository. Detects languages, frameworks, Docker, Terraform, and security files to suggest relevant commands.
No inputs required.
Example: @megalinter help_quick returns tailored suggestions for your project.
megalinter_run
Use this tool when you need full argument-level control. For short prompts, prefer megalinter_quick_action.
Runs mega-linter-runner via npx.
Inputs:
workingDirectory (string, optional): Command working directory. Defaults to current process directory.
path (string, optional): Directory path to lint.
flavor (string, optional): MegaLinter flavor. Default: all.
Use these copy/paste prompts in Copilot Chat with @megalinter.
CLI tools default to the current workspace root when no path is given.
If you add a file or folder as Copilot context (#file or #folder), reference it in your prompt and the tool will target that path.
Expected output: Routes each short request to the correct tool with sensible defaults.
Deterministic alternatives using explicit action fields:
text
@megalinter run quick action with action summary and severity error
@megalinter run quick action with action parse and reportType sarif
@megalinter run quick action with action scan and scanMode security
Run MegaLinter (megalinter_run)
text
@megalinter run megalinter with flavor all on . with reports in megalinter-reports
Expected output: Executes linters and reports issues found across all languages. Creates megalinter-reports/ with JSON, SARIF, and text reports.
Create Config (megalinter_write_config)
text
@megalinter create a MegaLinter config at .mega-linter.yml
Expected output: Creates .mega-linter.yml with specified settings ready for customization.
List Flavors (megalinter_list_flavors)
text
@megalinter list all available MegaLinter flavors
Expected output: Table of flavors (all, python, javascript, go, etc.) with descriptions and use cases.
Query Linters (megalinter_get_linters)
text
@megalinter list python security linters with autofix support
Expected output: Filtered list of Python-related and multi-language security linters from the current catalog that support autofix (if any match the query).