CodestewardBLOCK
Agentic code review with structural graph intelligence — PR gate + branch stewardship. Self-hosted. Apache-2.0.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Codesteward Review
Agentic code review that knows your graph. Gate every merge. Steward every branch. Self-hosted.
Website · Docs · Category stack · Helm · Cloud one-click · Changelog
Product UI: dual-mode control plane — gate merges, steward lo
679ef025d03dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add worker --env AUTH_STORE_PATH=${AUTH_STORE_PATH} --env AZURE_CLIENT_SECRET=${AZURE_CLIENT_SECRET} --env AZURE_DEVOPS_CLIENT_SECRET=${AZURE_DEVOPS_CLIENT_SECRET} --env AZURE_DEVOPS_TOKEN=${AZURE_DEVOPS_TOKEN} -- npx -y @codesteward/[email protected]{
"mcpServers": {
"worker": {
"command": "npx",
"args": [
"-y",
"@codesteward/[email protected]"
],
"env": {
"AUTH_STORE_PATH": "${AUTH_STORE_PATH}",
"AZURE_CLIENT_SECRET": "${AZURE_CLIENT_SECRET}",
"AZURE_DEVOPS_CLIENT_SECRET": "${AZURE_DEVOPS_CLIENT_SECRET}",
"AZURE_DEVOPS_TOKEN": "${AZURE_DEVOPS_TOKEN}"
}
}
}
}Exposed tools (15)
12 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Group | read | Group (org-scoped) |
User | read | User Account (org-scoped) |
graph_augment | read | Record an agent-inferred graph edge for this repo only (confidence < 1.0). |
graph_query | read | Query the structural code graph for this review (and allowed linked repos). queryType: lexical|referential|semantic|dependency. If empty and no prior rebuild this unit, call graph_rebuild first. |
graph_rebuild | read | Parse/rebuild the structural graph for THIS unit |
graph_status | read | Return Codesteward Graph status for the current repo (nodes, edges, last_build). If last_build is null, call graph_rebuild before graph_query. |
sandbox_exec | write | Run a shell command in this unit |
sandbox_ls | read | List files in this unit |
sandbox_read | read | Read a file from this unit |
stew_effective_policy | read | Load effective STEWARD.md policy from a repo path |
stew_graph_status | read | Proxy graph_status for a repo |
stew_list_findings | read | List findings, optionally filtered by session |
stew_list_sessions | read | List review sessions |
stew_start_gate_review | write | Start a PR/MR gate review session |
stew_start_stewardship | write | Start a branch/codebase stewardship scan |
Trust audit
BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (15 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA0Z3VS5JJcds3xfn/ygWyF6PZGFwODA6S2kP\n-----END RSA PRIVATE KEY-----",
const natsMod = (await new Function("return import('nats')")()) as {const amqp = (await new Function("return import('amqplib')")()) as any;const Pulsar = (await new Function("return import('pulsar-client')")()) as any;exec(
'http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2021-12-13&format=text' || true)"
ip="$(curl -fsS --max-time 3 http://169.254.169.254/latest/meta-data/public-ipv4 2>/dev/null || true)"
http://169.254.169.254/computeMetadata/v1/instance/network-interfaces/0/access-configs/0/external-ip 2>/dev/null || true)"
'http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2021-12-13&format=text' 2>/dev/null || true)"
'http://169.254.169.254/metadata/loadbalancer?api-version=2021-12-13' 2>/dev/null \
DATABASE_URL=postgres://steward:steward@localhost:5432/codesteward
# RABBITMQ_URL=amqp://steward:steward@localhost:5672
DATABASE_URL=postgres://steward:steward@postgres:5432/codesteward
DATABASE_URL: postgres://steward:steward@postgres:5432/codesteward
Dockerfile.node
'http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2021-12-13&format=text' || true)"
ip="$(curl -fsS --max-time 3 http://169.254.169.254/latest/meta-data/public-ipv4 2>/dev/null || true)"
http://169.254.169.254/computeMetadata/v1/instance/network-interfaces/0/access-configs/0/external-ip 2>/dev/null || true)"
'http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2021-12-13&format=text' 2>/dev/null || true)"
'http://169.254.169.254/metadata/loadbalancer?api-version=2021-12-13' 2>/dev/null \
export DATABASE_URL=postgres://steward:steward@localhost:5432/codesteward
const secret = "commercial-hmac-secret";
const secret = "commercial-hmac-secret";
body: JSON.stringify({ enabled: true, config: { token: "ghp_acceptancetest1234" } }),privateKeyPem: "-----BEGIN RSA PRIVATE KEY-----\nMIIE\n-----END RSA PRIVATE KEY-----",
Gates applied: critical_finding, no_behavioural_pass.
679ef025d03dfull audit observations/trust-audit/mcp-server/codesteward__codesteward-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 679ef025d03d | BLOCK | F | 47 | first audit |
Questions
What is the Codesteward MCP server?
Agentic code review with structural graph intelligence — PR gate + branch stewardship. Self-hosted. Apache-2.0.
What tools does Codesteward expose?
15 in total: 12 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Codesteward safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (47/100) and found 14 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Codesteward need?
It reads AUTH_STORE_PATH, AZURE_CLIENT_SECRET, AZURE_DEVOPS_CLIENT_SECRET, AZURE_DEVOPS_TOKEN, AZURE_DEVOPS_WEBHOOK_SECRET, BITBUCKET_TOKEN, BITBUCKET_WEBHOOK_SECRET, CLICKHOUSE_PASSWORD, CONFLUENCE_TOKEN, CROSS_REPO_MAX_TOKENS, FORGEJO_TOKEN and GH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Codesteward run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @codesteward/worker at 1.5.0.
How current is this page?
The grade is for one exact copy of the source (679ef025d03d), read on 2026-10-08. The repository is watched and re-audited when it changes.