AI DevSecOps Agent MCP Server

AI DevSecOps Agent MCP Server

Enables LLM clients to access DevSecOps tooling such as CI/CD pipeline status, vulnerability triage, log search, and dependency scanning through MCP, turning AI copilots into security-aware engineering partners.

Category
Visit Server

README

AI-Assisted DevSecOps Agent β€” MCP Server πŸ€–πŸ”’

An MCP (Model Context Protocol) server exposing DevSecOps tooling to LLM clients β€” turning your AI copilot into a security-aware engineering partner.

The Problem

DevSecOps teams drown in context-switching: checking pipeline status in one tab, triaging vulnerabilities in another, searching logs in a third. Meanwhile, LLM coding assistants can write code but are blind to your operational reality β€” they can't see your failing builds, open CVEs, or production errors.

The Solution

This MCP server bridges the gap by exposing four security-critical tools to any MCP-compatible LLM client (GitHub Copilot, Claude Desktop, Cursor, etc.):

Tool What It Does
get_pipeline_status Fetches CI/CD pipeline runs from GitHub Actions
triage_vulnerabilities Queries a vulnerability board and returns severity-ranked CVEs
search_logs Searches application logs by service, severity, and time range
scan_dependencies Analyzes a package.json or requirements.txt for known vulnerabilities

Why This Over the Obvious Alternative

Most "AI + DevOps" demos are chatbots with hardcoded responses. This project implements the Model Context Protocol (MCP) β€” the open standard for tool-use that GitHub Copilot, Claude, and other major LLM clients natively support. The tools return real, structured data that the LLM reasons over, not canned answers.

Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     MCP (stdio/SSE)     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  LLM Client     │◄──────────────────────►│  MCP Server          β”‚
β”‚  (Copilot,      β”‚                         β”‚                      β”‚
β”‚   Claude, etc.) β”‚                         β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
β”‚                 β”‚                         β”‚  β”‚ Pipeline Tool   β”‚  β”‚
β”‚                 β”‚                         β”‚  β”‚ Vuln Triage Toolβ”‚  β”‚
β”‚                 β”‚                         β”‚  β”‚ Log Search Tool β”‚  β”‚
β”‚                 β”‚                         β”‚  β”‚ Dep Scan Tool   β”‚  β”‚
β”‚                 β”‚                         β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                         β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                                      β”‚
                                              β”Œβ”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”
                                              β”‚  Mock Data    β”‚
                                              β”‚  (Simulated   β”‚
                                              β”‚   APIs)       β”‚
                                              β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ› οΈ Tech Stack

  • Runtime: Node.js + TypeScript
  • Protocol: Model Context Protocol (MCP) SDK
  • Transport: stdio (local) and SSE (remote)
  • Containerization: Docker

πŸš€ Getting Started

Local Development

npm install
npm run build
npm run start

With Docker

docker-compose up -d --build

Connecting to Claude Desktop

Add to your Claude Desktop MCP config (claude_desktop_config.json):

{
  "mcpServers": {
    "devsecops-agent": {
      "command": "node",
      "args": ["dist/index.js"]
    }
  }
}

πŸ“ Project Structure

src/
β”œβ”€β”€ index.ts              # MCP Server entry point
β”œβ”€β”€ tools/
β”‚   β”œβ”€β”€ pipeline.tool.ts  # GitHub Actions pipeline status
β”‚   β”œβ”€β”€ vulnerability.tool.ts  # CVE triage from mock board
β”‚   β”œβ”€β”€ logs.tool.ts      # Log search across services
β”‚   └── dependency.tool.ts # Dependency vulnerability scanning
└── data/
    └── mock-data.ts      # Simulated API responses

Decision Log

Decision Rationale
MCP over REST API MCP is the emerging standard for LLM tool-use; REST would require custom integration per client
TypeScript over Python Aligns with existing TypeScript expertise; MCP TS SDK is mature
Mock data layer Keeps the PoC self-contained without requiring real GitHub/Jira API keys
stdio transport Default for local MCP; SSE available for remote deployment

Γ°ΕΈβ€œβ€Ή Prerequisites

Tool Version Purpose
Node.js >= 20.x Runtime
npm >= 10.x Package manager
Docker >= 24.x Containerization (optional)
MCP Client Any Claude Desktop, GitHub Copilot, Cursor, etc.

ðŸő€ Step-by-Step Setup

Option A: Local Development

# 1. Clone the repository
git clone https://github.com/SumitDalavi/ai-devsecops-agent-mcp.git
cd ai-devsecops-agent-mcp

# 2. Install dependencies
npm install

# 3. Build the TypeScript project
npm run build

# 4. Start the MCP server (stdio transport)
npm run start

Option B: Docker

# 1. Clone and build
git clone https://github.com/SumitDalavi/ai-devsecops-agent-mcp.git
cd ai-devsecops-agent-mcp

# 2. Build and run
docker build -t devsecops-mcp-agent .
docker run -i devsecops-mcp-agent

Connecting to Claude Desktop

Add to your Claude Desktop config (claude_desktop_config.json):

{
  "mcpServers": {
    "devsecops-agent": {
      "command": "node",
      "args": ["/absolute/path/to/ai-devsecops-agent-mcp/dist/index.js"]
    }
  }
}

Γ°ΕΈΒ§Βͺ Usage & Demo

Once connected to an MCP client, you can ask natural language questions like:

Prompt Tool Invoked
"Show me the latest pipeline runs" get_pipeline_status
"Are there any critical vulnerabilities?" triage_vulnerabilities
"Search for error logs in the payment service" search_logs
"Scan dependencies for known CVEs" scan_dependencies
"Show me Kubernetes events in production" get-kubernetes-events
"Check for active incidents" get-sre-incident-correlation

The server returns structured JSON data that the LLM reasons over to provide contextual answers.

Òœ… Verification

# Verify the build succeeds
npm run build

# Verify the server starts (it will wait for MCP client connection on stdio)
node dist/index.js
# You should see: "DevSecOps MCP Agent running on stdio" on stderr

πŸ‘¨β€πŸ’» Author

Built to demonstrate AI-augmented DevSecOps workflows and close the gap between LLM assistants and operational tooling.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured