Agent skill

Megalinter Setup

by nvuillam in nvuillam/npm-groovy-lint

Install or upgrade MegaLinter on a repository. An agent skill from nvuillam/npm-groovy-lint.

MITAuto-check: notesDevelopment

Install Megalinter Setup

skills CLI
$ npx skills add nvuillam/npm-groovy-lint --skill megalinter-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nvuillam/npm-groovy-lint megalinter-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nvuillam/npm-groovy-lint.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/megalinter-setup .claude/skills/megalinter-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
megalinter-setup
GitHub stars
248
Used in
1 other repo
Token cost
~2.5k tokens
SKILL.md length
1,133 words
Files
5
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Install or upgrade MegaLinter on a repository. An agent skill from nvuillam/npm-groovy-lint.

  • Works in 6 steps: Analyze the repository → Install or upgrade → Refine .mega-linter.yml (only AFTER… → …
  • The user wants to add MegaLinter to a project
  • SKILL.md covers 1. Analyze the repository, 2. Install or upgrade, 3. Refine .mega-linter.yml… and 4. Install the MegaLinter…, plus 2 more sections
  • Calls npx, docker and git; needs LINTER_KEY and GRAFANA_TOKEN

What it does

Megalinter Setup is an agent skill from nvuillam/npm-groovy-lint. Install or upgrade MegaLinter on a repository. Use when the user wants to add MegaLinter to a project, set up linting CI, update MegaLinter configuration or version, or says "install megalinter", "setup linting", "add code quality checks". Always goes through npx mega-linter-runner (--install or --upgrade), then refines .mega-linter.yml.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `agents/INSTALL.md`, `agents/megalinter-fixer.md` and `agents/megalinter-runner.md`).

It sits in Development, covering Linting and formatting. It works with Jenkins. The repository describes itself as: Lint, format and auto-fix your Groovy / Jenkinsfile / Gradle files using command line. The licence is MIT.

When your agent uses it

  • The user wants to add MegaLinter to a project
  • Set up linting CI
  • Update MegaLinter configuration
  • Says install megalinter

Example prompts

  • “install megalinter”
  • “setup linting”
  • “add code quality checks”
  • “/megalinter-setup”

Requirements

  • Node.js
  • Docker
  • A credential in LINTER_KEY
  • A credential in GRAFANA_TOKEN
  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, Edit, Write, WebFetch, Skill, AskUserQuestion

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Analyze the repository
  2. Install or upgrade
  3. Refine .mega-linter.yml (only AFTER install/upgrade)
  4. Install the MegaLinter sub-agents (if your platform supports them)
  5. Observability dashboards (optional)
  6. Wrap up

What it can do on your machine

Read from SKILL.md and the folder at commit 2080dff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • Edit
    • Write
    • WebFetch
    • Skill
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • docker
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • megalinter.io
    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • LINTER_KEY
    • GRAFANA_TOKEN
    • DD_API_KEY
    • DD_APP_KEY
    • DD_BEARER_TOKEN
    • ELASTIC_API_KEY
    • NEW_RELIC_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Megalinter Setup loads about 2.5k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 1,133 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, Edit, Write, WebFetch, Skill, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nvuillam/npm-groovy-lint at commit 2080dff, republished under its MIT licence (© nvuillam). 1,133 words, ~2,473 tokens.

Download SKILL.mdSave it as .claude/skills/megalinter-setup/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
megalinter-setup
description
Install or upgrade MegaLinter on a repository. Use when the user wants to add MegaLinter to a project, set up linting CI, update MegaLinter configuration or version, or says "install megalinter", "setup linting", "add code quality checks". Always goes through npx mega-linter-runner (--install or --upgrade), then refines .mega-linter.yml.
allowed-tools
Bash, Read, Grep, Glob, Edit, Write, WebFetch, Skill, AskUserQuestion
argument-hint
[install|upgrade] [flavor, e.g. python|javascript|all]
user-invocable
true
licence
MegaLinter by OX Security, Copyright 2026 - https://megalinter.io/

MegaLinter setup

Install or upgrade MegaLinter on the current repository. Always use npx mega-linter-runner to scaffold or upgrade the configuration — never write .mega-linter.yml or CI workflow files from scratch. Only refine the generated files afterwards.

1. Analyze the repository

Gather what you need to answer the installer's options:

  • Flavor: detect the main technology and pick a flavor (python, javascript, java, go, php, ruby, rust, salesforce, swift, terraform, dotnet, dotnetweb, c_cpp, documentation, formatters, security, ...). Mixed or unclear → all.
  • CI system: from existing config (.github/ → gitHubActions, .gitlab-ci.yml → gitLabCI, azure-pipelines.yml → azure, bitbucket-pipelines.yml → bitbucket, Jenkinsfile → jenkins, .drone.yml → droneCI) or the git remote host. None → other.
  • Default branch: git remote show origin or the current repository default.

2. Install or upgrade

No MegaLinter configuration yet — run the installer non-interactively:

bash
npx mega-linter-runner --install --no-prompt \
  --flavor <flavor> \
  --setup-ci <ci> \
  --setup-default-branch <branch> \
  --fix

If the runner rejects one of the options above ("Invalid option" error), the resolved mega-linter-runner version is outdated: re-run with npx mega-linter-runner@latest (the --setup-* and --linter options need a recent version).

Notes:

  • The whole codebase is validated on each run (default). Pass --setup-validate-all-code-base diff only if the user explicitly asks to lint updated files only.
  • Add --release beta only if the user asks for the beta version (the installer then writes MEGALINTER_VERSION: beta in .mega-linter.yml).
  • Version rule (all skills): runner and Docker image versions always follow MEGALINTER_VERSION from .mega-linter.yml — invoke npx mega-linter-runner@beta when it is beta, plain npx mega-linter-runner in every other case, and never pass --release outside of this install step.
  • --fix enables auto-fixes (APPLY_FIXES: all); omit it if the user doesn't want automatic formatting.
  • If the user is present and wants to choose interactively, run plain npx mega-linter-runner --install instead and let them answer.

Preserve existing customizations. In non-interactive mode the installer overwrites conflicting files, but it first backs up every pre-existing target as <file>.megalinter-setup.bak (config files and the CI workflow file). After the install:

  1. Diff each .megalinter-setup.bak file against its regenerated version.
  2. Re-apply the user's customizations that are still relevant (extra workflow steps, env vars, custom triggers, added config entries...). When a customization conflicts with the new template or its intent is unclear, ask the user what to keep.
  3. Delete the .megalinter-setup.bak files once merged.

Configuration already exists — upgrade it:

bash
npx mega-linter-runner --upgrade --no-prompt

--upgrade migrates every MegaLinter reference of the repository to the current major version: image tags and action versions in the CI workflow files, deprecated variable names, and the MEGALINTER_VERSION property of .mega-linter.yml. Run it whenever the repository references an older MegaLinter major version (e.g. v8 image tags), even if the user only asked for a "check".

<!-- MAJOR-RELEASE-IMPACTED (example tags below) -->

Mandatory after --upgrade — migrate Docker image references to ghcr.io. Since MegaLinter v9.5.0, images are only published to GitHub Container Registry (Docker Hub is frozen at v9.4.0), and --upgrade does NOT rewrite the registry: it normalizes references to the bare oxsecurity/megalinter... form. So always finish with this pass:

  1. Search every CI/workflow file of the repository (.github/workflows/*, .gitlab-ci.yml, azure-pipelines.yml, bitbucket-pipelines.yml, Jenkinsfile, .drone.yml, shell scripts...) for oxsecurity/megalinter occurrences.
  2. Rewrite every occurrence used as a Docker image (after image:, container:, services:, docker run, docker pull, or any oxsecurity/megalinter[-<flavor>]:<tag> form, including megalinter-only-* standalone images and docker.io/-prefixed references) to the same reference prefixed with ghcr.io/ — keep flavor and tag unchanged: oxsecurity/megalinter-python:v10 becomes ghcr.io/oxsecurity/megalinter-python:v10.
  3. Leave untouched: references already prefixed with ghcr.io/, GitHub Action references (uses: oxsecurity/megalinter@... — actions are not Docker images), and documentation URLs.

3. Refine .mega-linter.yml (only AFTER install/upgrade)

Once the runner has generated/upgraded the files, you may adjust .mega-linter.yml:

  • Ensure MEGALINTER_FLAVOR and MEGALINTER_VERSION are set (the installer writes them; add them if upgrading an older config) — they drive which Docker image mega-linter-runner and these skills use.
  • Add DISABLE / DISABLE_LINTERS entries the user asks for.
  • Add FILTER_REGEX_EXCLUDE for generated or vendored folders (e.g. (dist/|build/|vendor/|node_modules/)). Excluded directories (and folders identified from these regexes) are also automatically forwarded to project-mode linters through their native exclusion arguments or generated ignore/config files; if the repository already maintains its own up-to-date ignore/config files for a linter, that forwarding can be turned off with FORWARD_EXCLUDED_DIRECTORIES: false (global) or <LINTER_KEY>_FORWARD_EXCLUDED_DIRECTORIES: false (per linter).

Validate the file against its JSON schema: https://raw.githubusercontent.com/oxsecurity/megalinter/main/megalinter/descriptors/schemas/megalinter-configuration.jsonschema.json

Show full SKILL.md (466 more words)Show less

4. Install the MegaLinter sub-agents (if your platform supports them)

This skill ships three sub-agent definitions in its agents/ folder (megalinter-watcher, megalinter-runner, megalinter-fixer) that make the other MegaLinter skills faster and cheaper by keeping CI logs and linter output out of the main context.

If the coding agent you are running on supports custom sub-agent definitions (Claude Code, OpenCode, GitHub Copilot, Codex... — you know whether you do), read agents/INSTALL.md in this skill's directory and follow the instructions for your platform: copy the three agents/*.md files to your platform's agents folder, adapting the frontmatter when needed.

If a target file already exists, ask the user before overwriting it. If your platform has no sub-agent support, skip this step — the skills degrade gracefully to inline execution.

5. Observability dashboards (optional)

MegaLinter can send its results to observability platforms (Grafana, Datadog, Elastic, New Relic) and ships ready-to-use dashboards: quality gate, error trends, top rules and files across repositories. Documentation: https://megalinter.io/latest/observability/

Offer this to the user only if they seem interested in monitoring or already use one of these platforms. If accepted:

  1. Ask which provider they use, and make sure the provider auth environment variables are available (never write secrets in committed files):
    • grafana: GRAFANA_URL + GRAFANA_TOKEN (service account token)
    • datadog: DD_SITE + DD_API_KEY + DD_APP_KEY (or DD_BEARER_TOKEN)
    • elastic: KIBANA_URL + ELASTIC_API_KEY
    • newrelic: NEW_RELIC_API_KEY + NEW_RELIC_ACCOUNT_ID + NEW_RELIC_REGION
  2. Provision the dashboards: npx mega-linter-runner --upload-dashboards <provider> (idempotent, re-run anytime to refresh).
  3. Add to .mega-linter.yml: API_REPORTER: true, API_REPORTER_PROVIDER: <provider>, and the provider's non-secret variables (endpoints, site, region — see the documentation page of the provider). Point the user to the CI secrets to define for the auth variables (API_REPORTER_* tokens/keys).

6. Wrap up

  • Show the user the generated/updated files.
  • Propose the two ways to see MegaLinter in action (first install and upgrade alike), and offer to do it for them. A local run is resource-consuming (Docker-based, downloads an image of several GB on first run, then loads CPU/RAM/disk), so running in CI is usually the recommended option — ask the user which one they want (use your platform's structured question mechanism if it has one, with the CI option first/recommended) instead of picking silently:
    • Create a pull request (recommended) with the generated/updated files (commit on the current branch if it is already a feature branch, otherwise on a new branch — never on the default branch —, push, open the PR), then run the megalinter-check skill (watch mode) on the created PR to watch the CI job results and fix the errors.
    • Run MegaLinter locally through the megalinter-check skill (local mode) to preview and fix errors before pushing anything. Its first run starts with a prerun analysis (--prerun, MegaLinter v10 or beta) that suggests .mega-linter.yml performance tuning (directories to exclude, flavor) before the real lint.
  • Do not commit or push without user confirmation, and never on the default branch.

© nvuillam, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in .claude/skills/megalinter-setup of nvuillam/npm-groovy-lint.

  • SKILL.md
  • agents/INSTALL.md
  • agents/megalinter-fixer.md
  • agents/megalinter-runner.md
  • agents/megalinter-watcher.md

Open the folder on GitHubat commit 2080dff

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in nvuillam/npm-groovy-lint, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Megalinter Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Megalinter Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Megalinter Setup this skillnvuillam/npm-groovy-lint2481 repos~2.5kAutomated safety check: NotesMIT
Jenkinsfile Validatorakin-ozer/cc-devops-skills319—~2.7kAutomated safety check: PassApache-2.0
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.2k—~2.2kAutomated safety check: PassMIT
Babysit PR To Pass CIsgl-project/sglang37k2 repos~3kAutomated safety check: PassApache-2.0
Rust Best Practicesfarm-fe/farm5.6k3 repos~1.1kAutomated safety check: PassMIT
Go Pedantrychromedp/chromedp13k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Jenkinsfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or check Jenkinsfiles and shared libraries.

    319 GitHub stars~2.7k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.2k GitHub stars~2.2k tokensUpdated 27 days ago
    DevelopmentAuto-check passed
  • Babysit PR To Pass CI

    sgl-project/sglang

    Start and persistently pursue a goal to babysit an SGLang pull request until selected GitHub Actions workflows pass on the latest PR head.

    37k GitHub starsUsed in 2 repos~3k tokens
    DevelopmentAuto-check passed
  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Go Pedantry

    chromedp/chromedp

    This skill should be used when the user is writing Go code and needs guidance on Go-specific pedantry: error wrapping with fmt.Errorf and %w, interface design (accept interfaces return structs)…

    13k GitHub stars~3.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Kedro Babysit

    kedro-org/kedro

    Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…

    11k GitHub stars~4k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from nvuillam/npm-groovy-lint

  • Megalinter Check

    nvuillam/npm-groovy-lint

    Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Megalinter

    nvuillam/npm-groovy-lint

    Entry point for everything MegaLinter. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~915 tokens
    Auto-check: notes
  • Upgrade Java Deps

    nvuillam/npm-groovy-lint

    Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

    248 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check: notes
  • Megalinter Fix

    nvuillam/npm-groovy-lint

    Fix the errors reported by MegaLinter. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check: notes
  • PR Watch Fix

    nvuillam/npm-groovy-lint

    Watch the GitHub PR for the current branch, wait for CI to finish, and autonomously fix failing jobs by reading logs, editing sources, and pushing.

    248 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check: notes

Works with

Categories

Questions about Megalinter Setup

What does Megalinter Setup do?

Install or upgrade MegaLinter on a repository. An agent skill from nvuillam/npm-groovy-lint. Megalinter Setup is an agent skill from nvuillam/npm-groovy-lint. Install or upgrade MegaLinter on a repository.

When should I use Megalinter Setup?

Megalinter Setup fits situations like: the user wants to add MegaLinter to a project; set up linting CI; update MegaLinter configuration; says install megalinter.

How do I install Megalinter Setup in Claude Code?

Run `npx skills add nvuillam/npm-groovy-lint --skill megalinter-setup -a claude-code`. Or copy the skill folder (.claude/skills/megalinter-setup in nvuillam/npm-groovy-lint) into .claude/skills/megalinter-setup in your project. Claude Code loads it when a task matches its description.

How do I install Megalinter Setup in Codex?

Run `npx skills add nvuillam/npm-groovy-lint --skill megalinter-setup -a codex`. Or copy the skill folder (.claude/skills/megalinter-setup in nvuillam/npm-groovy-lint) into .agents/skills/megalinter-setup in your project. Codex loads it when a task matches its description.

Can I use Megalinter Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nvuillam/npm-groovy-lint --skill megalinter-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/megalinter-setup, .gemini/skills/megalinter-setup, .github/skills/megalinter-setup and .opencode/skills/megalinter-setup in your project.

What does Megalinter Setup need to run?

Going by SKILL.md and its folder, Megalinter Setup needs the command-line tools its instructions call (npx, docker and git) and credentials named LINTER_KEY, GRAFANA_TOKEN, DD_API_KEY and DD_APP_KEY. Our summary lists: Node.js; Docker; A credential in LINTER_KEY; A credential in GRAFANA_TOKEN. Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Edit, Write, WebFetch, Skill, AskUserQuestion.

Does Megalinter Setup access the network?

SKILL.md names 2 domains. As links in the text: megalinter.io and raw.githubusercontent.com. This is read from the text; nothing was executed.

Is Megalinter Setup safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Megalinter Setup use?

Megalinter Setup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Megalinter Setup use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Megalinter Setup?

Skills that share tags, products or a category with Megalinter Setup: Jenkinsfile Validator (akin-ozer/cc-devops-skills, 319 stars), Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.2k stars), Babysit PR To Pass CI (sgl-project/sglang, 37k stars) and Rust Best Practices (farm-fe/farm, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Megalinter Setup?

nvuillam (a GitHub user) maintains it in nvuillam/npm-groovy-lint, which has 248 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 4, 2026.

Source: nvuillam/npm-groovy-lint on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.