AI DevSecOps Agent MCP Server
Enables LLM clients to access DevSecOps tooling such as CI/CD pipeline status, vulnerability triage, log search, and dependency scanning through MCP, turning AI copilots into security-aware engineering partners.
README
AI-Assisted DevSecOps Agent β MCP Server π€π
An MCP (Model Context Protocol) server exposing DevSecOps tooling to LLM clients β turning your AI copilot into a security-aware engineering partner.
The Problem
DevSecOps teams drown in context-switching: checking pipeline status in one tab, triaging vulnerabilities in another, searching logs in a third. Meanwhile, LLM coding assistants can write code but are blind to your operational reality β they can't see your failing builds, open CVEs, or production errors.
The Solution
This MCP server bridges the gap by exposing four security-critical tools to any MCP-compatible LLM client (GitHub Copilot, Claude Desktop, Cursor, etc.):
| Tool | What It Does |
|---|---|
get_pipeline_status |
Fetches CI/CD pipeline runs from GitHub Actions |
triage_vulnerabilities |
Queries a vulnerability board and returns severity-ranked CVEs |
search_logs |
Searches application logs by service, severity, and time range |
scan_dependencies |
Analyzes a package.json or requirements.txt for known vulnerabilities |
Why This Over the Obvious Alternative
Most "AI + DevOps" demos are chatbots with hardcoded responses. This project implements the Model Context Protocol (MCP) β the open standard for tool-use that GitHub Copilot, Claude, and other major LLM clients natively support. The tools return real, structured data that the LLM reasons over, not canned answers.
Architecture
βββββββββββββββββββ MCP (stdio/SSE) ββββββββββββββββββββββββ
β LLM Client βββββββββββββββββββββββββΊβ MCP Server β
β (Copilot, β β β
β Claude, etc.) β β ββββββββββββββββββ β
β β β β Pipeline Tool β β
β β β β Vuln Triage Toolβ β
β β β β Log Search Tool β β
β β β β Dep Scan Tool β β
β β β ββββββββββββββββββ β
βββββββββββββββββββ ββββββββββββββββββββββββ
β
βββββββββ΄ββββββββ
β Mock Data β
β (Simulated β
β APIs) β
βββββββββββββββββ
π οΈ Tech Stack
- Runtime: Node.js + TypeScript
- Protocol: Model Context Protocol (MCP) SDK
- Transport: stdio (local) and SSE (remote)
- Containerization: Docker
π Getting Started
Local Development
npm install
npm run build
npm run start
With Docker
docker-compose up -d --build
Connecting to Claude Desktop
Add to your Claude Desktop MCP config (claude_desktop_config.json):
{
"mcpServers": {
"devsecops-agent": {
"command": "node",
"args": ["dist/index.js"]
}
}
}
π Project Structure
src/
βββ index.ts # MCP Server entry point
βββ tools/
β βββ pipeline.tool.ts # GitHub Actions pipeline status
β βββ vulnerability.tool.ts # CVE triage from mock board
β βββ logs.tool.ts # Log search across services
β βββ dependency.tool.ts # Dependency vulnerability scanning
βββ data/
βββ mock-data.ts # Simulated API responses
Decision Log
| Decision | Rationale |
|---|---|
| MCP over REST API | MCP is the emerging standard for LLM tool-use; REST would require custom integration per client |
| TypeScript over Python | Aligns with existing TypeScript expertise; MCP TS SDK is mature |
| Mock data layer | Keeps the PoC self-contained without requiring real GitHub/Jira API keys |
| stdio transport | Default for local MCP; SSE available for remote deployment |
Γ°ΕΈββΉ Prerequisites
| Tool | Version | Purpose |
|---|---|---|
| Node.js | >= 20.x | Runtime |
| npm | >= 10.x | Package manager |
| Docker | >= 24.x | Containerization (optional) |
| MCP Client | Any | Claude Desktop, GitHub Copilot, Cursor, etc. |
Γ°ΕΈΕ‘β¬ Step-by-Step Setup
Option A: Local Development
# 1. Clone the repository
git clone https://github.com/SumitDalavi/ai-devsecops-agent-mcp.git
cd ai-devsecops-agent-mcp
# 2. Install dependencies
npm install
# 3. Build the TypeScript project
npm run build
# 4. Start the MCP server (stdio transport)
npm run start
Option B: Docker
# 1. Clone and build
git clone https://github.com/SumitDalavi/ai-devsecops-agent-mcp.git
cd ai-devsecops-agent-mcp
# 2. Build and run
docker build -t devsecops-mcp-agent .
docker run -i devsecops-mcp-agent
Connecting to Claude Desktop
Add to your Claude Desktop config (claude_desktop_config.json):
{
"mcpServers": {
"devsecops-agent": {
"command": "node",
"args": ["/absolute/path/to/ai-devsecops-agent-mcp/dist/index.js"]
}
}
}
Γ°ΕΈΒ§Βͺ Usage & Demo
Once connected to an MCP client, you can ask natural language questions like:
| Prompt | Tool Invoked |
|---|---|
| "Show me the latest pipeline runs" | get_pipeline_status |
| "Are there any critical vulnerabilities?" | triage_vulnerabilities |
| "Search for error logs in the payment service" | search_logs |
| "Scan dependencies for known CVEs" | scan_dependencies |
| "Show me Kubernetes events in production" | get-kubernetes-events |
| "Check for active incidents" | get-sre-incident-correlation |
The server returns structured JSON data that the LLM reasons over to provide contextual answers.
Γ’Εβ¦ Verification
# Verify the build succeeds
npm run build
# Verify the server starts (it will wait for MCP client connection on stdio)
node dist/index.js
# You should see: "DevSecOps MCP Agent running on stdio" on stderr
π¨βπ» Author
Built to demonstrate AI-augmented DevSecOps workflows and close the gap between LLM assistants and operational tooling.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.