Argus (GitLab)

by athapong

1 stars
1.3k downloads
Not rated
GitHub

About

Integrates with GitLab repositories to enable automated security assessments, code reviews, and DevOps workflows through repository analysis and file retrieval capabilities.

Details

Author
athapong
Repository
athapong/argus
GitHub stars
1
Downloads
1,303
License
MIT License
Categories
Productivity, Developer Tools, Design, Workplace, File Management, AI, Frontend, Communication, Automation, Project Management, Search

- Multi-Language Support
- Go: gocyclo, golangci-lint analysis
- Java: PMD static analysis
- Python: Pylint, Bandit security checks
- JavaScript/TypeScript: ESLint analysis
- Automatic language detection

- Security Scanning
- Integrated Trivy vulnerability scanner
- Comprehensive security reports
- Support for multiple branches

- Git Operations
- Branch enumeration and management
- Commit history analysis
- Diff comparisons
- Repository structure visualization

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Argus (GitLab)
    Command (node, npx, python, etc.) uvx
    Arguments
    • Argument 1 --from
    • Argument 2 git+https://github.com/athapong/argus
    • Argument 3 argus

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

uvx argus
{
    "command": "uvx",
    "args": [
        "--from",
        "git+https://github.com/athapong/argus",
        "argus"
    ],
    "alwaysAllow": [
        "get_commit_history",
        "enumerate_branches",
        "compare_git_changes",
        "analyze_code_quality",
        "security_scan_repository"  
    ],
    "timeout": 300
}

- SKIP_SYSTEM_CHECK: Set to any value to skip system dependency checks
- PATH: Automatically updated for tool installations

analyze_repository_structure

Analyze the structure of a repository. Parameters: repo_url (string), gitlab_credentials (optional dictionary), branch (optional string)

analyze_code_quality

Perform code quality analysis on a repository. Parameters: repo_url (string), language (optional string)

security_scan_repository

Conduct a security scan on a repository. Parameters: repo_url (string), scan_type (string)

compare_git_changes

Compare changes between two branches in a repository. Parameters: repo_url (string), source (string), target (string)

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "argus (gitlab)": {
            "cwd": "string (optional)",
            "env": {},
            "args": [
                "--from",
                "git+https://github.com/athapong/argus",
                "argus"
            ],
            "shell": false,
            "command": "uvx"
        }
    }
}

Linux

{
    "cwd": "string (optional)",
    "env": [],
    "args": [
        "--from",
        "git+https://github.com/athapong/argus",
        "argus"
    ],
    "shell": false,
    "command": "uvx"
}

Macos

{
    "cwd": "string (optional)",
    "env": [],
    "args": [
        "--from",
        "git+https://github.com/athapong/argus",
        "argus"
    ],
    "shell": false,
    "command": "uvx"
}

Windows

{
    "cwd": "string (optional)",
    "env": [],
    "args": [
        "/c",
        "uvx",
        "--from",
        "git+https://github.com/athapong/argus",
        "argus"
    ],
    "shell": false,
    "command": "cmd"
}

Argus - Repository Analysis and Security Assessment Tool

A powerful Model Context Protocol (MCP) tool for analyzing code repositories, performing security scans, and assessing code quality across multiple programming languages.

Features

- Multi-Language Support
- Go: gocyclo, golangci-lint analysis
- Java: PMD static analysis
- Python: Pylint, Bandit security checks
- JavaScript/TypeScript: ESLint analysis
- Automatic language detection

- Security Scanning
- Integrated Trivy vulnerability scanner
- Comprehensive security reports
- Support for multiple branches

- Git Operations
- Branch enumeration and management
- Commit history analysis
- Diff comparisons
- Repository structure visualization

Installation

Prerequisites

- Python 3.8+
- Git
- libmagic (system dependency)

System Dependencies

macOS

brew install libmagic

Linux (Ubuntu/Debian)

sudo apt-get update
sudo apt-get install -y libmagic1

Installation via uv

uvx argus

Usage

Basic MCP Commands

# Analyze repository structure
analyze_repository_structure(
    repo_url="https://gitlab.com/user/repo",
    gitlab_credentials={"api_key": "your-token"},  # Optional
    branch="main"  # Optional
)

Perform code quality analysis

analyze_code_quality( repo_url="https://gitlab.com/user/repo", language="python" # Optional, will auto-detect if not specified )

Security scan

security_scan_repository( repo_url="https://gitlab.com/user/repo", scan_type="trivy" )

Compare changes

compare_git_changes( repo_url="https://gitlab.com/user/repo", source="feature-branch", target="main" )

Security scan repository

security_scan_repository( repo_url="https://gitlab.com/user/repo", scan_type="trivy" )

MCP Configuration

json
{
"command": "uvx",
"args": [
"--from",
"git+https://github.com/athapong/argus",
"argus"
],
"alwaysAllow": [
"get_commit_history",
"enumerate_branches",
"compare_git_changes",
"analyze_code_quality",
"security_scan_repository"
],
"timeout": 300
}
``

Supported Analysis Tools

| Language | Tools | Installation |
|------------|-------------------------|------------------------------------------------|
| Go | gocyclo, golangci-lint |
go install github.com/fzipp/gocyclo/cmd/gocyclo@latest |
| Java | PMD | macOS:
brew install pmd, Linux: Auto-installed |
| Python | Pylint, Bandit | Auto-installed via dependencies |
| JavaScript | ESLint |
npm install -g eslint |

Environment Variables

- SKIP_SYSTEM_CHECK: Set to any value to skip system dependency checks
-
PATH`: Automatically updated for tool installations

Error Handling

The tool provides detailed error messages and graceful fallbacks:
- Dependency installation failures show warnings instead of errors
- Language detection falls back to specified language if auto-detection fails
- Tool execution errors are captured in the response structure

License

MIT License

Contributing

1. Fork the repository
2. Create your feature branch
3. Commit your changes
4. Push to the branch
5. Create a new Pull Request

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.