megalinter
🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.
MegaLinter is an open-source code quality and security analysis tool that functions as an AI sub-agent for coding assistants, automating linting across 67 programming languages and 133 embedded linters. It integrates with Claude Code, Cursor, GitHub Copilot CLI, and other coding agents via installable skills and plugins, enabling agents to setup, run, and fix linter errors autonomously. MegaLinter provides sub-agent orchestration for efficient error detection and fixing, running linters in parallel and isolating large CI logs from the main agent context. The tool works in CI/CD pipelines (GitHub Actions, GitLab CI, Azure Pipelines) and locally via Docker, offering auto-fixes, PR comments, SARIF reports, and security-hardened environment variable handling.
Key Features
Use Cases
- 01Automated code quality enforcement: coding agents setup and run MegaLinter in CI/CD, apply fixes, and commit corrected code without manual intervention
- 02Multi-language project linting: analyze repositories with mixed languages (Python, JavaScript, Terraform, YAML) using a single unified tool
- 03Security scanning: detect secrets, vulnerabilities, and misconfigurations via trivy, checkov, semgrep, trufflehog, and DevSkim linters
- 04PR/MR quality gates: automatically post linting results as comments on pull requests with links to detailed logs and fix suggestions
- 05Local development: run MegaLinter locally via Docker or mega-linter-runner to catch issues before committing, with the same config as CI
- 06Infrastructure-as-Code validation: lint Terraform, Kubernetes manifests, Dockerfiles, ARM templates, and CloudFormation with specialized linters
Related Agents
View morehermes-agent
The agent that grows with you
agency-agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
openinterpreter
A coding agent for open models like Kimi K3
cline
Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
megalinter — FAQ
What is MegaLinter?+
MegaLinter is an open-source tool that runs 133 linters across 67 languages, formats, and tooling configurations to analyze code quality, formatting, and security. It functions as an AI sub-agent via skills/plugins for coding agents like Claude Code and Cursor, enabling autonomous setup, execution, and fixing of linter errors.
How do I install MegaLinter agent skills?+
For Claude Code, run 'npx skills add oxsecurity/megalinter/skills -s "*" -a claude-code -y' to install all four skills (megalinter, megalinter-setup, megalinter-check, megalinter-fix). For other agents, replace 'claude-code' with your agent identifier (cursor, github-copilot, etc.) or use '--copy' to auto-detect installed agents.
Which coding agents does MegaLinter support?+
MegaLinter provides skills/plugins for Claude Code, Cursor, GitHub Copilot CLI, Codex, Windsurf, Cline, Roo Code, Gemini CLI, Antigravity, OpenCode, Amp, Goose, OpenHands, and Qwen Code. It also works in CI/CD pipelines (GitHub Actions, GitLab CI, Azure Pipelines, Jenkins, Bitbucket) and locally via Docker.
Does MegaLinter require API keys or external services?+
No, MegaLinter is 100% free and open-source, running entirely within a Docker container with all 133 linters embedded. No external API keys or paid services are required. Optional integrations (GitHub token for PR comments, cloud observability endpoints) are available but not mandatory.
Is MegaLinter free to use?+
Yes, MegaLinter is free for all uses (personal, professional, public, and private repositories) under the GNU Affero General Public License. Docker images are pulled hundreds of thousands of times per month at no cost.
How does MegaLinter handle secrets and environment variables?+
MegaLinter automatically hides 30+ sensitive environment variables (GITHUB_TOKEN, API keys, passwords, secrets) from linter processes using pattern-based matching, so you only need to trust MegaLinter core code, not the 133 embedded linters. Additional variables can be secured via SECURED_ENV_VARIABLES configuration.
How do I install megalinter?+
Open the source repository on GitHub and follow its README. megalinter is a agent — MCP Agents Market links you directly to the official repo.
Is megalinter free?+
megalinter is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.