MCP Code Review Server MCP server
Code review as an MCP server — structured reviews with OWASP security scanning.
2 stars
Reviews
Write oneNobody has reviewed MCP Code Review Server yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
MCP Code Review Server tools (3)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
review_codeReview source code for bugs, security, performance, and quality issues.
review_diffReview a git diff for potential issues before merging.
review_fileReview a local file for code quality and security issues.
Public scan report
scanner v0.1.9 · 2026-09-23 · same rubric, same numbers if you re-run it
- Code scan7 source files scanned20/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 3 days ago15/15
- Maintainer identityregistry namespace matches repository owner6/10
Findings (1)
- mediumsubprocess with shell=True
exec.shell-trueaicraft_code_review-0.1.2/src/mcp_code_review/reviewer.py: …"Use subprocess.run with args list, not shell=True", "command_injection"), (r"…
What the publisher says
From the MCP Code Review Server repository's README, as published. We do not edit it. Read it on GitHub
AICraft — AI-Powered Developer Tools
Production-ready developer tools, code templates, and AI prompt packs. Built by engineers, for engineers.
Products
Prompt Packs
Code Templates
MCP Tools
Custom rules & team profiles: commit a .mcp-code-review.yaml to your repo for shared regex rules, disabled checks, severity overrides, and per-repo thresholds.
Start with the free 10-minute trial or download the versioned trial bundle. It uses an intentionally unsafe sample, not your repository, and produces a structured local report.
If that workflow proves useful for a shared team baseline, the optional Team Rules Pack is a one-time $49 purchase. It includes 63 ready-made rules for Python, JavaScript/TypeScript, Go, and Java; GitHub Actions and GitLab CI merge-gate templates; and 20 review prompts. For a real pull-request check, copy the secretless GitHub Actions starter. It uses the pinned PyPI 0.1.2 release; no API key or paid service is required.
Share structured trial feedback or request a free team trial. Do not include source code or credentials.
Marketplaces: Official MCP Registry · Smithery · mcpservers.org · cursor.directory · PyPI
For a repeatable, read-only distribution audit, run python3 scripts/distribution_report.py. It reports PyPI and GitHub Release downloads separately; downloads are distribution signals, not contacts, customers, or revenue.
AgentPowers Skills (Free)
Shortened. The full README is on GitHub.
Nothing above is checked by us. What we check is on the safety report.
Install directly
claude mcp add aicraft-code-review -- uvx aicraft-code-review
MCP Code Review Server: common questions
- Is MCP Code Review Server MCP server safe?
- Mostly: it is graded B (82/100). Read the MCP Code Review Server safety report
- How do I install MCP Code Review Server?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does MCP Code Review Server need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is MCP Code Review Server maintained?
- The last commit was 3 days ago (2026-09-20). The latest release is v0.1.2.
- What can I use instead of MCP Code Review Server?
- Servers from other publishers that do the same job: MCPProxy MCP server, Npm Sentinel MCP server and Trent MCP server. Compare all MCP Code Review Server alternatives.
Alternatives to MCP Code Review Server
Same job from other publishers: the closest match first, then the best rated.
- MCPProxyLocal-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savingsnot reviewedGrowingB
- Npm SentinelAdvanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.not reviewedGrowingA
TrentSecurity reviews, threat models over a repo or website, and remediation tracking, in your editor.not reviewedGrowingA- SecHelixEvidence-first security review of authorized repositories. Read-only, root-confined, no shell.not reviewedGrowingA
DraugrSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.not reviewedGrowingA