MCP server for running Ox Security MegaLinter via mega-linter-runner
SaferSkills independently audited megalinter (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Down At The Bottom Of The Mole Hole banner
<!-- mcp-name: io.github.downatthebottomofthemolehole/megalinter-mcp-server -->
Note: This is a community-maintained MCP server. It is not an official Model Context Protocol server, but it is sanctioned by Ox Security as a complement to their official MegaLinter tools.
A Model Context Protocol (MCP) server for running Ox Security MegaLinter through mega-linter-runner. Works with any CI/CD platform (GitHub Actions, GitLab CI, Azure DevOps, CircleCI, Jenkins) or locally.
This server provides 15 MCP tools in total: 10 core tools and 5 convenience aliases across execution, discovery, and analysis workflows.
megalinter_quick_action for short, natural requests with sensible defaults.megalinter_run to execute MegaLinter with configurable runtime and runner options.megalinter_write_config to generate a minimal .mega-linter.yml file.megalinter_list_flavors to return common MegaLinter flavors.megalinter_get_linters to discover available linters by language, security focus, and auto-fix capability.megalinter_get_security_info to group security linters by threat category.megalinter_get_reporters to list supported report output formats and CI-targeted reporters.megalinter_parse_reports to parse JSON or SARIF report artefacts.megalinter_get_issue_summary to aggregate report issues by linter and severity.megalinter_get_security_recommendations to generate security-focused remediation guidance.If you prefer short prompts, use megalinter_quick_action first:
@megalinter quick scan this repository@megalinter security scan@megalinter summarise errors@megalinter list python security linters@megalinter write configOr use ultra-short aliases for minimal typing:
@megalinter scan — Quick scan with defaults@megalinter summary — Summarise last run's errors@megalinter parse — Parse JSON report@megalinter help_quick — Context-aware help for your projectThis MCP server is platform-agnostic and works universally:
The only requirement is Docker (or a compatible container runtime like Colima).
| Tool | Category | Typical outcome |
|---|---|---|
megalinter_quick_action | Interactive | Handle short natural requests with defaults |
scan | Alias | Ultra-short alias for quick scan |
summary | Alias | Ultra-short alias for error summary |
parse | Alias | Ultra-short alias for report parsing |
help_quick | Alias | Ultra-short alias for context-aware help |
megalinter_help_quick | Help | Context-aware suggestions for your project |
megalinter_run | Execution | Run linting and produce report artefacts |
megalinter_write_config | Configuration | Generate baseline .mega-linter.yml |
megalinter_list_flavors | Discovery | Identify an appropriate flavour for your stack |
megalinter_get_linters | Discovery | Filter linters by language, security, and auto-fix support |
megalinter_get_security_info | Discovery | View security linters grouped by SAST, secrets, container, and IaC |
megalinter_get_reporters | Discovery | Select output/reporting formats for local and CI workflows |
megalinter_parse_reports | Analysis | Read JSON or SARIF reports in structured form |
megalinter_get_issue_summary | Analysis | Summarise issue totals and top failing linters |
megalinter_get_security_recommendations | Analysis | Produce practical shift-left security actions |
megalinter_quick_actionInteractive shortcut that accepts a short request and routes it to the right workflow.
Inputs:
request (string, optional): Short instruction. Default: quick scan.action (string, optional): Explicit quick action (scan, config, flavors, linters, security, reporters, parse, summary, recommendations).scanMode (string, optional): Scan preset (quick, full, security, fix).target (string, optional): Directory to scan. Default: ..workingDirectory (string, optional): Command working directory.reportsPath (string, optional): Reports directory. Default: megalinter-reports.reportType (string, optional): Parse format (json or sarif).severity (string, optional): Summary filter (error, warning, info).language (string, optional): Language filter for linter queries. For scans, maps to a flavor hint (python, javascript, terraform, and similar).securityOnly (boolean, optional): Return only security linters in linter queries. For scans, forces security flavor.autoFixOnly (boolean, optional): Return only auto-fix linters in linter queries.timeoutMinutes (number, optional): Timeout for scan actions. Default: 20.summaryOnly (boolean, optional): Return concise output for scans. Default: true.flavor (string, optional): Optional flavor override for scan actions.fix (boolean, optional): Force auto-fixes for scan actions.targetPath (string, optional): Config output path for write-config requests.Examples:
request: "quick scan" -> Runs ci_light against changed files.request: "full scan" -> Runs all flavor.request: "security scan" -> Runs security flavor.request: "summarise errors" -> Returns issue summary filtered to errors.request: "parse sarif report" -> Parses SARIF output.action: "summary", severity: "error" -> Deterministic summary with no phrase parsing.action: "scan", scanMode: "security" -> Deterministic security scan.scan (Ultra-short alias)Run a quick scan with minimal typing. Accepts optional parameters for customization.
Inputs:
language (string, optional): Target language mapped to flavor (e.g., python, javascript, terraform).scanMode (string, optional): Scan preset (quick, full, security, fix). Default: quick.summaryOnly (boolean, optional): Return concise output. Default: true.Example: @megalinter scan runs a quick scan with concise output.
summary (Ultra-short alias)Summarise errors from the last MegaLinter run with minimal typing.
Inputs:
severity (string, optional): Filter by severity (error, warning, info).linterFilter (string, optional): Filter by linter name.Example: @megalinter summary shows all error/warning totals.
parse (Ultra-short alias)Parse MegaLinter report files with minimal typing.
Inputs:
reportType (string, optional): Report format (json or sarif). Default: json.reportsPath (string, optional): Reports directory path.Example: @megalinter parse parses the JSON report.
megalinter_help_quickGet context-aware help based on your current repository. Detects languages, frameworks, Docker, Terraform, and security files to suggest relevant commands.
No inputs required.
Example: @megalinter help_quick returns tailored suggestions for your project.
megalinter_runUse this tool when you need full argument-level control. For short prompts, prefer megalinter_quick_action.
Runs mega-linter-runner via npx.
Inputs:
workingDirectory (string, optional): Command working directory. Defaults to current process directory.path (string, optional): Directory path to lint.flavor (string, optional): MegaLinter flavor. Default: all.release (string, optional): MegaLinter image tag. Default: v9.image (string, optional): Full Docker image override.env (string, optional): Environment variable string passed to --env.fix (boolean, optional): Apply auto-fixes.help (boolean, optional): Show mega-linter-runner help.install (boolean, optional): Generate MegaLinter starter config.containerName (string, optional): Docker container name override.removeContainer (boolean, optional): Remove container after run.configFile (string, optional): Path to .mega-linter.yml.reportsPath (string, optional): Reports directory. Default: megalinter-reports.disableLinters (string, optional): Comma-separated list of linters to disable.lintChangedFilesOnly (boolean, optional): Sets VALIDATE_ALL_CODEBASE=false when true.runnerVersion (string, optional): npm version for mega-linter-runner (for example latest).timeoutSeconds (number, optional): Timeout in seconds. Default: 3600.summaryOnly (boolean, optional): Return concise logs. Default: false.extraArgs (string[], optional): Additional CLI arguments.megalinter_write_configWrites a minimal MegaLinter configuration.
Inputs:
targetPath (string, optional): Output file path. Default: .mega-linter.yml.applyFixes (string, optional): Value for APPLY_FIXES. Default: none.showElapsedTime (boolean, optional): Value for SHOW_ELAPSED_TIME. Default: true.flavorSuggestions (boolean, optional): Value for FLAVOR_SUGGESTIONS. Default: false.disableLinters (string[], optional): Values for DISABLE_LINTERS.megalinter_list_flavorsReturns the built-in list of common flavors (all, javascript, python, terraform, and others).
megalinter_get_lintersReturns linter metadata from the built-in catalogue and supports targeted filtering.
Inputs:
language (string, optional): Filter by language (for example python, javascript, terraform).securityOnly (boolean, optional): Return only security-focused linters.autoFixOnly (boolean, optional): Return only linters with automatic fix capability.megalinter_get_security_infoReturns security linters grouped into categories such as SAST, secrets, supply chain, container, and infrastructure.
Inputs:
megalinter_get_reportersReturns available MegaLinter reporters, including CI-targeted formats.
Inputs:
megalinter_parse_reportsParses MegaLinter report files from the reports directory.
Inputs:
reportsPath (string, optional): Report directory path. Default: megalinter-reports.reportType (string, optional): Report type (json or sarif). Default: json.megalinter_get_issue_summarySummarises issues from megalinter-report.json and can apply severity/linter filters.
Inputs:
reportsPath (string, optional): Report directory path. Default: megalinter-reports.severityFilter (string, optional): Filter results by severity (error, warning, info).linterFilter (string, optional): Filter results by linter name.megalinter_get_security_recommendationsGenerates security recommendations based on active linters in the parsed report data.
Inputs:
reportsPath (string, optional): Report directory path. Default: megalinter-reports.Use these copy/paste prompts in Copilot Chat with @megalinter. CLI tools default to the current workspace root when no path is given. If you add a file or folder as Copilot context (#file or #folder), reference it in your prompt and the tool will target that path.
megalinter_quick_action)@megalinter quick scan
@megalinter full scan
@megalinter security scan
@megalinter summarise errors
@megalinter parse sarif report
@megalinter write configExpected output: Routes each short request to the correct tool with sensible defaults.
Deterministic alternatives using explicit action fields:
@megalinter run quick action with action summary and severity error
@megalinter run quick action with action parse and reportType sarif
@megalinter run quick action with action scan and scanMode securitymegalinter_run)@megalinter run megalinter with flavor all on . with reports in megalinter-reportsExpected output: Executes linters and reports issues found across all languages. Creates megalinter-reports/ with JSON, SARIF, and text reports.
megalinter_write_config)@megalinter create a MegaLinter config at .mega-linter.ymlExpected output: Creates .mega-linter.yml with specified settings ready for customization.
megalinter_list_flavors)@megalinter list all available MegaLinter flavorsExpected output: Table of flavors (all, python, javascript, go, etc.) with descriptions and use cases.
megalinter_get_linters)@megalinter list python security linters with autofix supportExpected output: Filtered list of Python-related and multi-language security linters from the current catalog that support autofix (if any match the query).
megalinter_get_security_info)@megalinter show MegaLinter security linter categoriesExpected output: Security categories (for example, sast, secrets, supply-chain, container, infrastructure) with associated linters (gitleaks, trivy, etc.).
megalinter_get_reporters)@megalinter list available MegaLinter reportersExpected output: List of reporters (console, json, sarif, github-comment, etc.) with activation methods.
megalinter_parse_reports)@megalinter parse the json report from megalinter-reportsExpected output: Parsed MegaLinter JSON or SARIF report content as structured data (raw report payload).
megalinter_get_issue_summary)@megalinter summarise issues from megalinter-reports with severity errorExpected output: Summary of issues filtered by severity and linter inputs, aggregated by linter with totals and run counts.
megalinter_get_security_recommendations)@megalinter generate security recommendations using megalinter-reportsExpected output: Actionable security recommendations prioritized by severity with linter names, rule IDs, and suggested next steps.
>=24.0.0megalinter_run)Runtime:
@modelcontextprotocol/sdk (MCP server SDK)Development:
typescript (build/compile)tsx (development runner)@types/node (Node.js typings)Runtime note:
mega-linter-runner is executed via npx at runtime and can be pinned with the runnerVersion tool input.npm install
npm run buildThis workspace is preconfigured in .vscode/mcp.json:
{
"servers": {
"megalinter": {
"type": "stdio",
"command": "node",
"args": ["./dist/index.js"]
}
}
}Reload VS Code (Cmd+Shift+P → Developer: Reload Window) after changing MCP configuration.
Then query the server from Copilot Chat with @megalinter, for example:
@megalinter list available flavors
@megalinter list security linters for javascriptUse a stdio server configuration that runs the compiled entrypoint:
{
"name": "megalinter-mcp-server",
"type": "stdio",
"command": "node",
"args": ["/absolute/path/to/megalinter-mcp/dist/index.js"]
}Build first with npm run build, then start your MCP client.
npm startDevelopment mode:
npm run devUse .vscode/launch.json:
Debug MCP Server (runs npm run dev)Debug MCP Server (Built) (runs dist/index.js after build)Set breakpoints in src/index.ts, then press F5.
See docs/TESTING.md for Copilot Chat scenarios, manual JSON-RPC checks, and troubleshooting guidance.
Quick validation prompt in Copilot Chat:
@megalinter list available flavors@megalinter run megalinter on this repository with reports enabled@megalinter parse the json report in megalinter-reports@megalinter summarise error-level issues and top failing linters@megalinter generate security recommendations from the current report@megalinter list python security linters with autofix support@megalinter create a megalinter config file with apply fixes set to none@megalinter list available reportersmegalinter_write_config, then tighten rules in small steps.lintChangedFilesOnly during fast feedback loops, and full scans in CI.reportsPath stable so downstream analysis tools always read from a known location.megalinter_get_issue_summary for triage before requesting full report dumps.megalinter_get_security_recommendations regularly to maintain shift-left coverage.megalinter_run in PR checks and publish SARIF output.megalinter_get_linters and megalinter_list_flavors to choose a baseline quickly.megalinter_parse_reports and megalinter_get_issue_summary for recurring snapshots.Maintained by Carl Dawson under the Down At The Bottom Of The Mole Hole organization.
Licensed under the MIT License. MegaLinter is managed by Ox Security.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.