Atlas / MCP servers / codesteward / Codesteward

CodestewardBLOCK

mcp/codesteward/codesteward-1

Agentic code review with structural graph intelligence — PR gate + branch stewardship. Self-hosted. Apache-2.0.

Verdict
BLOCK
Grade
F
Trust score
47 /100
Exposed tools
15 12r · 3w · 0d
Transport
streamable-http
License
Apache-2.0
Stars
21
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Codesteward Review

Agentic code review that knows your graph. Gate every merge. Steward every branch. Self-hosted.

Website · Docs · Category stack · Helm · Cloud one-click · Changelog

Product UI: dual-mode control plane — gate merges, steward lo

Read from source at commit 679ef025d03dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add worker --env AUTH_STORE_PATH=${AUTH_STORE_PATH} --env AZURE_CLIENT_SECRET=${AZURE_CLIENT_SECRET} --env AZURE_DEVOPS_CLIENT_SECRET=${AZURE_DEVOPS_CLIENT_SECRET} --env AZURE_DEVOPS_TOKEN=${AZURE_DEVOPS_TOKEN} -- npx -y @codesteward/[email protected]
claude-desktop
{
  "mcpServers": {
    "worker": {
      "command": "npx",
      "args": [
        "-y",
        "@codesteward/[email protected]"
      ],
      "env": {
        "AUTH_STORE_PATH": "${AUTH_STORE_PATH}",
        "AZURE_CLIENT_SECRET": "${AZURE_CLIENT_SECRET}",
        "AZURE_DEVOPS_CLIENT_SECRET": "${AZURE_DEVOPS_CLIENT_SECRET}",
        "AZURE_DEVOPS_TOKEN": "${AZURE_DEVOPS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (15)

12 read · 3 write · 0 destructive.

ToolRiskDescription
GroupreadGroup (org-scoped)
UserreadUser Account (org-scoped)
graph_augmentreadRecord an agent-inferred graph edge for this repo only (confidence < 1.0).
graph_queryreadQuery the structural code graph for this review (and allowed linked repos). queryType: lexical|referential|semantic|dependency. If empty and no prior rebuild this unit, call graph_rebuild first.
graph_rebuildreadParse/rebuild the structural graph for THIS unit
graph_statusreadReturn Codesteward Graph status for the current repo (nodes, edges, last_build). If last_build is null, call graph_rebuild before graph_query.
sandbox_execwriteRun a shell command in this unit
sandbox_lsreadList files in this unit
sandbox_readreadRead a file from this unit
stew_effective_policyreadLoad effective STEWARD.md policy from a repo path
stew_graph_statusreadProxy graph_status for a repo
stew_list_findingsreadList findings, optionally filtered by session
stew_list_sessionsreadList review sessions
stew_start_gate_reviewwriteStart a PR/MR gate review session
stew_start_stewardshipwriteStart a branch/codebase stewardship scan
04

Trust audit

BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (15 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
scripts/category-acceptance.mjs:349
"-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA0Z3VS5JJcds3xfn/ygWyF6PZGFwODA6S2kP\n-----END RSA PRIVATE KEY-----",
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/api/src/queue-broker.ts:72
const natsMod = (await new Function("return import('nats')")()) as {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/api/src/queue-broker.ts:186
const amqp = (await new Function("return import('amqplib')")()) as any;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/api/src/queue-broker.ts:288
const Pulsar = (await new Function("return import('pulsar-client')")()) as any;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/sandbox/src/types.ts:34
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
deploy/cloud/azure/main.bicep:66
'http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2021-12-13&format=text' || true)"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
deploy/cloud/first-boot.sh:80
ip="$(curl -fsS --max-time 3 http://169.254.169.254/latest/meta-data/public-ipv4 2>/dev/null || true)"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
deploy/cloud/first-boot.sh:85
http://169.254.169.254/computeMetadata/v1/instance/network-interfaces/0/access-configs/0/external-ip 2>/dev/null || true)"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
deploy/cloud/first-boot.sh:90
'http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2021-12-13&format=text' 2>/dev/null || true)"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
deploy/cloud/first-boot.sh:95
'http://169.254.169.254/metadata/loadbalancer?api-version=2021-12-13' 2>/dev/null \
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:5
DATABASE_URL=postgres://steward:steward@localhost:5432/codesteward
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:108
# RABBITMQ_URL=amqp://steward:steward@localhost:5672
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
deploy/compose/.env.example:19
DATABASE_URL=postgres://steward:steward@postgres:5432/codesteward
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
deploy/compose/docker-compose.category.yml:27
DATABASE_URL: postgres://steward:steward@postgres:5432/codesteward
MEDIUMInventory / provenance · inv.binary · CWE-1104
deploy/compose/Dockerfile.node
Dockerfile.node
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/cloud/azure/main.bicep:66
'http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2021-12-13&format=text' || true)"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/cloud/first-boot.sh:80
ip="$(curl -fsS --max-time 3 http://169.254.169.254/latest/meta-data/public-ipv4 2>/dev/null || true)"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/cloud/first-boot.sh:85
http://169.254.169.254/computeMetadata/v1/instance/network-interfaces/0/access-configs/0/external-ip 2>/dev/null || true)"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/cloud/first-boot.sh:90
'http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2021-12-13&format=text' 2>/dev/null || true)"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/cloud/first-boot.sh:95
'http://169.254.169.254/metadata/loadbalancer?api-version=2021-12-13' 2>/dev/null \
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
README.md:188
export DATABASE_URL=postgres://steward:steward@localhost:5432/codesteward
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/api/src/__tests__/license.test.ts:102
const secret = "commercial-hmac-secret";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/api/src/__tests__/license.test.ts:122
const secret = "commercial-hmac-secret";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/ga-acceptance.mjs:174
body: JSON.stringify({ enabled: true, config: { token: "ghp_acceptancetest1234" } }),
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/api/src/__tests__/org-isolation.test.ts:50
privateKeyPem: "-----BEGIN RSA PRIVATE KEY-----\nMIIE\n-----END RSA PRIVATE KEY-----",

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 679ef025d03dfull audit observations/trust-audit/mcp-server/codesteward__codesteward-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08679ef025d03dBLOCKF47first audit
06

Questions

What is the Codesteward MCP server?

Agentic code review with structural graph intelligence — PR gate + branch stewardship. Self-hosted. Apache-2.0.

What tools does Codesteward expose?

15 in total: 12 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Codesteward safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (47/100) and found 14 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Codesteward need?

It reads AUTH_STORE_PATH, AZURE_CLIENT_SECRET, AZURE_DEVOPS_CLIENT_SECRET, AZURE_DEVOPS_TOKEN, AZURE_DEVOPS_WEBHOOK_SECRET, BITBUCKET_TOKEN, BITBUCKET_WEBHOOK_SECRET, CLICKHOUSE_PASSWORD, CONFLUENCE_TOKEN, CROSS_REPO_MAX_TOKENS, FORGEJO_TOKEN and GH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Codesteward run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @codesteward/worker at 1.5.0.

How current is this page?

The grade is for one exact copy of the source (679ef025d03d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement