Open Code ReviewBLOCK
🤖 AI code quality gate for AI-generated code. Detects hallucinated packages, phantom dependencies, stale APIs, and more. MCP Server + CLI + CI/CD Action.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The first open-source CI/CD quality gate built specifically for AI-generated code. Detects hallucinated imports, stale APIs, over-engineering, and security anti-patterns — powered by local LLMs and any OpenAI-compatible provider. Free. Self-hostable. 6 languages.
[](https://www.npmjs.com/package/@opencodereview/cli) [](https://www.npmjs.com/package/@opencodereview/mcp-server) [](https://www.npmjs.com/package/@opencodereview/cli) [](LICENSE) [](https://github.com/raye-deng/open-code-review/actions/workflows/ci.yml) [](https://github.com/raye-deng/open-code-review) [](http://makeapullrequest.com)
Works With

4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
explain_issue | read | Explain a code quality issue detected by OCR. Returns detailed explanation, category context, and fix guidance for the AI agent to act on. |
heal_code | read | Load a file |
scan_diff | read | Scan git diff between two branches for code quality issues. Ideal for PR/MR review — only analyzes changed files and lines. |
scan_directory | read | Scan a directory for AI-generated code quality issues. Detects hallucinated imports, phantom packages, stale APIs, security anti-patterns, and more. Supports TypeScript, JavaScript, Python, Java, Go, and Kotlin. |
Trust audit
BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (9 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
message: 'pickle.load() can execute arbitrary code. Use json or safer serialization for untrusted data.',
message: 'Use of eval() detected — allows arbitrary code execution',
suggestion: 'Avoid eval(). Use JSON.parse() for data parsing, or safer alternatives like Function constructors with strict sandboxing.',
message: 'Use of new Function() detected — allows dynamic code execution',
suggestion: 'Avoid new Function(). Use structured approaches to achieve dynamic behavior.',
message: 'eval() usage detected — enables arbitrary code execution. Use ast.literal_eval() for safe evaluation.',
message: 'TLS certificate verification is disabled (rejectUnauthorized: false)',
* 4. Insecure cryptography: Math.random(), MD5/SHA1 for passwords (CWE-328/338)
console.log('User login attempt:', { username, password, apiKey: process.env.API_KEY });'const API_KEY = "sk-proj-abc123def456"',
const token = "eyJhbGciOiJIUzI1NiJ9.test";
code: 'const token = "ghp_1234567890abcdef1234567890abcdef";',
apiKey: '81b74bce658546b9be069cc4bd4120ea.bT8x39i5GEEQ7ZbK',
apiKey: '81b74bce658546b9be069cc4bd4120ea.bT8x39i5GEEQ7ZbK',
code: 'const token = "ghp_1234567890abcdef1234567890abcdef";',
const githubToken = "ghp_000000000000000000000000000000000000";
const unit = makeUnit('const token = "ghp_000000000000000000000000000000000000";');const unit = makeUnit('const key = `-----BEGIN RSA PRIVATE KEY-----\nMIIE...`;');const slackToken = "xoxb-0000000000-0000000000";
const unit = makeUnit('const slackToken = "xoxb-0000000000-0000000000";');.clinerules
.continuerc.json
.githubignore
.gitlab-ci.yml
.windsurfrules
Gates applied: no_behavioural_pass.
2bb990a707b5full audit observations/trust-audit/mcp-server/raye-deng__open-code-review.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2bb990a707b5 | BLOCK | F | 52 | first audit |
Questions
What is the Open Code Review MCP server?
🤖 AI code quality gate for AI-generated code. Detects hallucinated packages, phantom dependencies, stale APIs, and more. MCP Server + CLI + CI/CD Action.
What tools does Open Code Review expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Open Code Review safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (52/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Open Code Review need?
It reads ANTHROPIC_API_KEY, API_KEY, API_SECRET, DB_PASSWORD, JWT_SECRET, MY_API_KEY, OCR_API_KEY, OPENAI_API_KEY, SECRET and SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Open Code Review run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @open-code-review/worker at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (2bb990a707b5), read on 2026-10-08. The repository is watched and re-audited when it changes.