Atlas / MCP servers / raye-deng / Open Code Review

Open Code ReviewBLOCK

mcp/raye-deng/open-code-review

🤖 AI code quality gate for AI-generated code. Detects hallucinated packages, phantom dependencies, stale APIs, and more. MCP Server + CLI + CI/CD Action.

Verdict
BLOCK
Grade
F
Trust score
52 /100
Exposed tools
4 4r · 0w · 0d
Transport
stdio · streamable-http
License
NOASSERTION
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The first open-source CI/CD quality gate built specifically for AI-generated code. Detects hallucinated imports, stale APIs, over-engineering, and security anti-patterns — powered by local LLMs and any OpenAI-compatible provider. Free. Self-hostable. 6 languages.

[](https://www.npmjs.com/package/@opencodereview/cli) [](https://www.npmjs.com/package/@opencodereview/mcp-server) [](https://www.npmjs.com/package/@opencodereview/cli) [](LICENSE) [](https://github.com/raye-deng/open-code-review/actions/workflows/ci.yml) [](https://github.com/raye-deng/open-code-review) [](http://makeapullrequest.com)

Works With

![Aider](https://

Read from source at commit 2bb990a707b5OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add worker --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env API_SECRET=${API_SECRET} --env DB_PASSWORD=${DB_PASSWORD} -- npx -y @open-code-review/[email protected]
claude-desktop
{
  "mcpServers": {
    "worker": {
      "command": "npx",
      "args": [
        "-y",
        "@open-code-review/[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "API_KEY": "${API_KEY}",
        "API_SECRET": "${API_SECRET}",
        "DB_PASSWORD": "${DB_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
explain_issuereadExplain a code quality issue detected by OCR. Returns detailed explanation, category context, and fix guidance for the AI agent to act on.
heal_codereadLoad a file
scan_diffreadScan git diff between two branches for code quality issues. Ideal for PR/MR review — only analyzes changed files and lines.
scan_directoryreadScan a directory for AI-generated code quality issues. Detects hallucinated imports, phantom packages, stale APIs, security anti-patterns, and more. Supports TypeScript, JavaScript, Python, Java, Go, and Kotlin.
04

Trust audit

BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (7 observation(s))
Shell
declared (9 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/core/src/detectors/v4/language-specific.ts:544
message: 'pickle.load() can execute arbitrary code. Use json or safer serialization for untrusted data.',
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/src/detectors/security-pattern.ts:74
message: 'Use of eval() detected — allows arbitrary code execution',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/src/detectors/security-pattern.ts:75
suggestion: 'Avoid eval(). Use JSON.parse() for data parsing, or safer alternatives like Function constructors with strict sandboxing.',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/src/detectors/security-pattern.ts:82
message: 'Use of new Function() detected — allows dynamic code execution',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/src/detectors/security-pattern.ts:83
suggestion: 'Avoid new Function(). Use structured approaches to achieve dynamic behavior.',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/src/detectors/v4/language-specific.ts:495
message: 'eval() usage detected — enables arbitrary code execution. Use ast.literal_eval() for safe evaluation.',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/core/src/detectors/security-pattern.ts:152
message: 'TLS certificate verification is disabled (rejectUnauthorized: false)',
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
packages/core/src/detectors/security-pattern.ts:8
* 4. Insecure cryptography: Math.random(), MD5/SHA1 for passwords (CWE-328/338)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
demo-scan/demo-example-keys.js:71
console.log('User login attempt:', { username, password, apiKey: process.env.API_KEY });
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/src/ai/v4/patterns/defect-patterns.ts:269
'const API_KEY = "sk-proj-abc123def456"',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/tests/security-pattern.test.ts:45
const token = "eyJhbGciOiJIUzI1NiJ9.test";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/tests/v4/example-key-pattern-detector.test.ts:111
code: 'const token = "ghp_1234567890abcdef1234567890abcdef";',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/tests/v4/l3-e2e.test.ts:140
apiKey: '81b74bce658546b9be069cc4bd4120ea.bT8x39i5GEEQ7ZbK',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/tests/v4/l3-e2e.test.ts:161
apiKey: '81b74bce658546b9be069cc4bd4120ea.bT8x39i5GEEQ7ZbK',
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/core/tests/v4/example-key-pattern-detector.test.ts:111
code: 'const token = "ghp_1234567890abcdef1234567890abcdef";',
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/core/tests/v4/fixtures/demo-new-detections.ts:66
const githubToken = "ghp_000000000000000000000000000000000000";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/core/tests/v4/security-pattern-detector.test.ts:609
const unit = makeUnit('const token = "ghp_000000000000000000000000000000000000";');
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/core/tests/v4/security-pattern-detector.test.ts:90
const unit = makeUnit('const key = `-----BEGIN RSA PRIVATE KEY-----\nMIIE...`;');
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
packages/core/tests/v4/fixtures/demo-new-detections.ts:67
const slackToken = "xoxb-0000000000-0000000000";
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
packages/core/tests/v4/security-pattern-detector.test.ts:617
const unit = makeUnit('const slackToken = "xoxb-0000000000-0000000000";');
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.continuerc.json
.continuerc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.githubignore
.githubignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitlab-ci.yml
.gitlab-ci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.windsurfrules
.windsurfrules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 2bb990a707b5full audit observations/trust-audit/mcp-server/raye-deng__open-code-review.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082bb990a707b5BLOCKF52first audit
06

Questions

What is the Open Code Review MCP server?

🤖 AI code quality gate for AI-generated code. Detects hallucinated packages, phantom dependencies, stale APIs, and more. MCP Server + CLI + CI/CD Action.

What tools does Open Code Review expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Open Code Review safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (52/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Open Code Review need?

It reads ANTHROPIC_API_KEY, API_KEY, API_SECRET, DB_PASSWORD, JWT_SECRET, MY_API_KEY, OCR_API_KEY, OPENAI_API_KEY, SECRET and SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Open Code Review run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @open-code-review/worker at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (2bb990a707b5), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement