Argus (GitLab)
About
Integrates with GitLab repositories to enable automated security assessments, code reviews, and DevOps workflows through repository analysis and file retrieval capabilities.
Details
- Author
- athapong
- Repository
- athapong/argus
- GitHub stars
- 1
- Downloads
- 1,303
- License
- MIT License
- Categories
- Productivity, Developer Tools, Design, Workplace, File Management, AI, Frontend, Communication, Automation, Project Management, Search
Jump to
- Multi-Language Support
- Go: gocyclo, golangci-lint analysis
- Java: PMD static analysis
- Python: Pylint, Bandit security checks
- JavaScript/TypeScript: ESLint analysis
- Automatic language detection
- Security Scanning
- Integrated Trivy vulnerability scanner
- Comprehensive security reports
- Support for multiple branches
- Git Operations
- Branch enumeration and management
- Commit history analysis
- Diff comparisons
- Repository structure visualization
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Argus (GitLab)Command (node, npx, python, etc.)uvxArguments-
Argument 1
--from -
Argument 2
git+https://github.com/athapong/argus -
Argument 3
argus
Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
-
Argument 1
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
uvx argus
{
"command": "uvx",
"args": [
"--from",
"git+https://github.com/athapong/argus",
"argus"
],
"alwaysAllow": [
"get_commit_history",
"enumerate_branches",
"compare_git_changes",
"analyze_code_quality",
"security_scan_repository"
],
"timeout": 300
}
- SKIP_SYSTEM_CHECK: Set to any value to skip system dependency checks
- PATH: Automatically updated for tool installations
analyze_repository_structure
Analyze the structure of a repository. Parameters: repo_url (string), gitlab_credentials (optional dictionary), branch (optional string)
analyze_code_quality
Perform code quality analysis on a repository. Parameters: repo_url (string), language (optional string)
security_scan_repository
Conduct a security scan on a repository. Parameters: repo_url (string), scan_type (string)
compare_git_changes
Compare changes between two branches in a repository. Parameters: repo_url (string), source (string), target (string)
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"argus (gitlab)": {
"cwd": "string (optional)",
"env": {},
"args": [
"--from",
"git+https://github.com/athapong/argus",
"argus"
],
"shell": false,
"command": "uvx"
}
}
}
Linux
{
"cwd": "string (optional)",
"env": [],
"args": [
"--from",
"git+https://github.com/athapong/argus",
"argus"
],
"shell": false,
"command": "uvx"
}
Macos
{
"cwd": "string (optional)",
"env": [],
"args": [
"--from",
"git+https://github.com/athapong/argus",
"argus"
],
"shell": false,
"command": "uvx"
}
Windows
{
"cwd": "string (optional)",
"env": [],
"args": [
"/c",
"uvx",
"--from",
"git+https://github.com/athapong/argus",
"argus"
],
"shell": false,
"command": "cmd"
}
Argus - Repository Analysis and Security Assessment Tool
A powerful Model Context Protocol (MCP) tool for analyzing code repositories, performing security scans, and assessing code quality across multiple programming languages.
Features
- Multi-Language Support
- Go: gocyclo, golangci-lint analysis
- Java: PMD static analysis
- Python: Pylint, Bandit security checks
- JavaScript/TypeScript: ESLint analysis
- Automatic language detection
- Security Scanning
- Integrated Trivy vulnerability scanner
- Comprehensive security reports
- Support for multiple branches
- Git Operations
- Branch enumeration and management
- Commit history analysis
- Diff comparisons
- Repository structure visualization
Installation
Prerequisites
- Python 3.8+
- Git
- libmagic (system dependency)
System Dependencies
macOS
brew install libmagic
Linux (Ubuntu/Debian)
sudo apt-get update
sudo apt-get install -y libmagic1
Installation via uv
uvx argus
Usage
Basic MCP Commands
# Analyze repository structure
analyze_repository_structure(
repo_url="https://gitlab.com/user/repo",
gitlab_credentials={"api_key": "your-token"}, # Optional
branch="main" # Optional
)
Perform code quality analysis
analyze_code_quality(
repo_url="https://gitlab.com/user/repo",
language="python" # Optional, will auto-detect if not specified
)
Security scan
security_scan_repository(
repo_url="https://gitlab.com/user/repo",
scan_type="trivy"
)
Compare changes
compare_git_changes(
repo_url="https://gitlab.com/user/repo",
source="feature-branch",
target="main"
)
Security scan repository
security_scan_repository(
repo_url="https://gitlab.com/user/repo",
scan_type="trivy"
)
MCP Configuration
json{
"command": "uvx",
"args": [
"--from",
"git+https://github.com/athapong/argus",
"argus"
],
"alwaysAllow": [
"get_commit_history",
"enumerate_branches",
"compare_git_changes",
"analyze_code_quality",
"security_scan_repository"
],
"timeout": 300
}
``
Supported Analysis Tools
| Language | Tools | Installation |
|------------|-------------------------|------------------------------------------------|
| Go | gocyclo, golangci-lint |
go install github.com/fzipp/gocyclo/cmd/gocyclo@latest |
| Java | PMD | macOS: brew install pmd, Linux: Auto-installed |
| Python | Pylint, Bandit | Auto-installed via dependencies |
| JavaScript | ESLint | npm install -g eslint |
Environment Variables
-
SKIP_SYSTEM_CHECK: Set to any value to skip system dependency checks
- PATH`: Automatically updated for tool installations
Error Handling
The tool provides detailed error messages and graceful fallbacks:
- Dependency installation failures show warnings instead of errors
- Language detection falls back to specified language if auto-detection fails
- Tool execution errors are captured in the response structure
License
MIT License
Contributing
1. Fork the repository
2. Create your feature branch
3. Commit your changes
4. Push to the branch
5. Create a new Pull Request
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





