π Kill the Junior AI Era. π€ Level up AI code to automatically Principal standards. π‘οΈ Quality Gate β¨
io.github.mustafacagri/ai-quality-gate MCP Server
This MCP server automates AI-driven code quality checks. It fits a workflow where AI writes code, calls quality_fix, the server applies fixes where possible, and then reports remaining issues back to the AI. It uses a hybrid approach combining ESLint plus Prettier and an optional SonarQube run.
π οΈ Key Features
Tool: quality_fix for server-side code quality fixes
Phase 1: ESLint with 627 rules plus Prettier (about 2β8s, always runs)
Phase 2: SonarQube Server (about 30β60s, optional)
ESLint rules are controlled by MCP for consistent quality gates.
Prettier uses project's config so formatting matches project preferences.
Phase 1 Rule Coverage:
Plugin
Rules
Description
SonarJS
201
Security, bugs, code smells
Unicorn
127
Modern JS best practices
ESLint Core
108
JavaScript fundamentals
TypeScript-ESLint
99
TypeScript-specific rules
RegExp
60
Regex best practices
Import
11
Import/export rules
Promise
10
Async/await best practices
Node.js (n)
9
Node.js specific rules
Unused Imports
2
Auto-remove unused imports
Total
627
Installation
Prerequisites
Node.js 18+ on your PATH (node -v).
Cursor, Antigravity, OpenCode (or another MCP-capable editor) with MCP enabled.
Project root is auto-detected when PROJECT_ROOT is omitted: the server walks up from the MCP process working directory until it finds package.json or tsconfig.json. Set PROJECT_ROOT in env only to analyze a different tree than the inferred root.
MCP configuration (Cursor)
Open Settings β Tools & MCP β Edit (user mcp.json). Add one server block; the examples below match .cursor/mcp.json.example (JSONC with comments β if your editor rejects comments, copy the JSON blocks below only).
Server name vs tool name: The key under mcpServers (e.g. "ai-quality-gate") is only the label for that connection in Cursor. The MCP tool your agent calls is always quality_fix β that name is fixed by this package and is separate from the server key and from ai-quality-gate.
A) Recommended: npx (no global install)
Always runs the published package; good for teams and CI-like setups.
The interactive wizard creates or updates .quality-gate.yaml without hand-editing: it walks you through project root, optional SonarQube (host URL + project key; token is not saved to disk β use SONAR_TOKEN in your environment), which Phase 1 tools to enable (ESLint, curly-brace / arrow AST fixers, Prettier, JSON validator), timeouts, and i18n rules. The generated file includes a fixers: block you can adjust later.
After yarn build (or install from npm), run from the target project (or any path under it):
bash
node dist/server.js --setup
PROJECT_ROOT is inferred when unset (see MCP configuration). Use the same entrypoint as the MCP server (node dist/server.js or npx ai-quality-gate); only the --setup flag switches to wizard mode. Answer prompts in the terminal; on success you get a ready-to-use config next to your project root.
Other CLI modes:--check (read-only Phase 1), --fix (default behavior when using CLI quality run), --phase1-only, --phase2-only β see docs/DEVELOPMENT.md.
Optional files (discovered by walking up from the inferred project root β same algorithm as package.json / tsconfig.json β or from PROJECT_ROOT when set): .quality-gate.yaml (preferred) or .quality-gate.json. Same fields as environment variables (camelCase); you may nest Sonar settings under sonar: { hostUrl, token, projectKey, scannerPath }.
Set QUALITY_GATE_CONFIG to an explicit path to skip discovery.
Custom rules (customRules)
Optional line-based regex checks on lintable files (Phase 1). Each match is reported as an issue with rule set to custom:<id> (and included in quality_fixremaining). Example:
yaml
customRules:-id:no-consolemessage:'Console.log is not allowed'pattern:'console\\.log\\('severity:error-id:no-debuggermessage:'Debugger statement found'pattern:'debugger'severity:warning
Patterns use JavaScript RegExp source (escape backslashes as in YAML strings). Invalid patterns are skipped at runtime with a log line.
JSON validator & i18n locale files
When fixers.jsonValidator is enabled and you pass JSON paths that match locale patterns (for example locales/en.json / locales/tr.json), the tool compares keys across those files.
Syntax errors, invalid UTF-8 BOM, etc. β reported as issues and fail Phase 1 / quality_fix until fixed.
Missing or extra keys between locale files β collected as i18nIssues in the validator result and printed as warnings on stderr during Phase 1. They do not set passed: false and do not block the gate.
Treat i18nIssues as advisory unless you add your own CI check on top.
Environment Variables
All variables are optional unless you use Phase 2, which requires SONAR_HOST_URL, SONAR_TOKEN, and SONAR_PROJECT_KEY together.
Variable
Description
Example
QUALITY_GATE_CONFIG
Absolute path to a .quality-gate.yaml or .quality-gate.json file. Skips walking parent directories for config discovery.
/app/ci/quality-gate.yaml
PROJECT_ROOT
Override detected project root. Default: walk up from the process cwd until package.json or tsconfig.json is found.
Full path to the sonar-scanner executable if it is not on PATH.
/opt/sonar-scanner/bin/sonar-scanner
PHASE1_TIMEOUT
Phase 1 subprocess timeout in milliseconds.
30000 (default)
PHASE2_TIMEOUT
Phase 2 (Sonar) timeout in milliseconds.
300000 (default)
ENABLE_I18N_RULES
Set to true to enable ESLint rules that flag raw string literals in JSX (for i18n-heavy apps).
false (default)
Auto-Fix
Phase 1 automatically fixes these issues:
ESLint Auto-Fix (~100+ rules)
typescript
// var β const/letvar x = 1 β const x = 1// forEach β for...of (unicorn/no-array-for-each)
arr.forEach(x =>f(x)) β for (const x of arr) f(x)
// Nested ternary β extracted (unicorn/no-nested-ternary)
a ? b : c ? d : e β const temp = c ? d : e; a ? b : temp
// Unused imports removedimport { unused } from'x' β (removed)
// Type imports (consistent-type-imports)import { Type } from'x' β importtype { Type } from'x'// Optional chain (prefer-optional-chain)
a && a.b && a.b.c β a?.b?.c// Regex optimization (regexp/*)
/[0-9]/ β /\d/
SETUP.md β Local setup (if included in your tree)
AGREEMENTS.md, docs/ARCHITECTURE.md, etc. β optional; some files may be omitted in minimal clones. README + .cursor/mcp.json.example are enough to run the published package.