Detects database migration table locks, terraform cost leaks, and OWASP API flaws.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A production-ready Model Context Protocol (MCP) Server providing AI coding assistants (Claude Desktop, Cursor, Windsurf, Cline) with automated static analysis tools to prevent production outages, cloud cost leaks, and security vulnerabilities.
This server inspects codebases across three mission-critical engineering vectors:
Cloud Cost Leaks (Terraform / HCL / AWS):
EBS_GP2: Identifies legacy gp2 EBS volumes (gp3 provides equal durability with ~20% baseline cost reduction and higher baseline IOPS).PUBLIC_IP: Flags unneeded associate_public_ip_address = true incurring hourly AWS IPv4 charges ($0.005/hr/IP).CW_NO_RETENTION: Catches aws_cloudwatch_log_group missing retention policies (preventing infinite unbudgeted log ingestion costs).S3_NO_LIFECYCLE: Detects S3 buckets lacking Glacier lifecycle transitions.RDS_MULTIAZ_NONPROD & RDS_PROVISIONED_IOPS_NONPROD: Flags doubled database infrastructure costs on development and staging environments.PostgreSQL Migration Table Lock Hazards:
INDEX_NOT_CONCURRENT: Detects CREATE INDEX missing CONCURRENTLY (which acquires an EXCLUSIVE lock and halts table writes in production).NOT_NULL_VOLATILE_DEFAULT: Catches ADD COLUMN ... NOT NULL DEFAULT <func()> rewriting every table row under an ACCESS EXCLUSIVE lock.FK_NO_INDEX: Flags unindexed foreign key constraints causing cascading table-level sequential lock scans on parent updates/deletes.FOR_UPDATE_UNBOUNDED: Catches SELECT ... FOR UPDATE missing LIMIT or SKIP LOCKED, preventing deadlocks.OWASP & Full-Stack Next.js API Security:
NEXT_PUBLIC_SECRET_LEAK: Flags sensitive tokens and private API keys prefixed with NEXT_PUBLIC_ that leak into public client browser bundles.NEXTJS_SERVER_ACTION_NO_AUTH: Flags Next.js 14/15 Server Actions exporting mutations without explicit session auth verification.SQLI_RAW_INTERPOLATION: Identifies raw SQL query templates using string interpolation instead of parameterized inputs.SSRF_UNVALIDATED_FETCH: Catches external fetch calls consuming user inputs without protocol/hostname validation.This server implements the official Model Context Protocol specification (tools/list and tools/call):
audit_devops_repositoryClones a public Git repository shallowly without executing hooks, performs AST and regex static syntax audits, and returns structured findings and a formatted Markdown report.
repository_url (string, required): Public Git URL of the repository to audit (e.g. https://github.com/example/cloud-infra).sub_directory (string, optional): Specific subdirectory within the repository to inspect (e.g. terraform/ or prisma/migrations/).status: "success" | "error"total_findings: Number of detected issuesfindings: Array of detailed vulnerability records (file, line number, rule ID, severity, message, fix code)markdown_report: Human-readable summary tableaudit_devops_codeDirectly audits a raw code snippet of Terraform (HCL), PostgreSQL migration (SQL), or Next.js API/Server Action code.
code (string, required): The source code string to audit.file_type (string, optional, default: "auto"): One of "terraform", "postgres", "nextjs", or "auto".audit_local_devops_directoryAudits a local filesystem directory on the host machine before submitting a Pull Request or deploying to staging.
directory_path (string, required): Absolute filesystem path to the target folder.Add the server to your claude_desktop_config.json:
In Cursor, navigate to Settings β Features β MCP β Add New MCP Server:
devops-code-auditorcommandpython3 /absolute/path/to/devops-code-auditor/server.pyRun the isolated container via Docker:
Once connected, your AI assistant can evaluate migration files and cloud manifests on demand:
This server executes 100% static analysis using AST pattern matching and regex verification. It never executes untrusted shell commands, arbitrary Python code, or database connections on your machine.
MIT License β Copyright (c) 2026 Neon Innovation Lab. Maintained by Neon Innovation Lab.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/devops-cloud-code-auditor)<a href="https://allmcps.com/mcp/devops-cloud-code-auditor"><img src="https://allmcps.com/api/badge/devops-cloud-code-auditor?style=directory" alt="DevOps & Cloud Code Auditor on AllMCPs" /></a>