Atlas / MCP servers / selvage-lab / Selvage

SelvageSAFE

mcp/selvage-lab/selvage

An LLM-based code review MCP server with AST-powered smart context extraction

Verdict
SAFE
Grade
B
Trust score
87 /100
Exposed tools
—
Transport
stdio
License
NOASSERTION
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Selvage: AI-Powered Code Review Automation Tool

🌐 한국어

A modern CLI tool that helps AI analyze Git diffs to improve code quality, find bugs, and identify security vulnerabilities.

🤖 AI Agents: Read our documentation at https://selvage.ai/llms.txt

▶ Watch Demo Video

Selvage: Code reviews with an edge!

No more waiting for reviews! AI instantly analyzes your code changes to provide quality improvements and bug prevention. With smart context analysis (AST-based) that's accurate and cost-effective, plus multi-turn processing for large codebases - seamlessly integrated with all Git workflows.

Table of Contents

  • ✨ Key Features
  • 🚀 Quick Start
  • 🎯 Practical Usage Guide
  • MCP Mode Usage
  • ⌨️ CLI Usage
  • 🌐 Smart Context Analysis and Supported AI Models
  • 🎯 Smart Context Analysis
  • Supported AI Models
  • [📄 Review Result S
Read from source at commit f334a6dfb67cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add selvage -- None selvage==0.4.1
03

Trust audit

SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (23)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/review/SKILL.md
.claude/skills/review/SKILL.md
Why it matters. link not followed
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmessage
.gitmessage
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
.claude/agents/selvage-reviewer.md
.claude/agents/selvage-reviewer.md
Why it matters. link not followed
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/multiturn/test_multiturn_review_executor_integration.py:35
prompt = pickle.load(f)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/utils/test_get_file_path.py:31
("../../../root/.ssh/id_rsa", "/tmp/repo", None, True),
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/mcp/test_context_store.py:147
assert store.load_metadata('../../etc/passwd') is None
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/mcp/test_context_store.py:166
assert not store._validate_context_id('../../etc/passwd')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/utils/test_get_file_path.py:30
("../../etc/passwd", "/tmp/repo", None, True),  # 심각한 path traversal
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/utils/test_get_file_path.py:31
("../../../root/.ssh/id_rsa", "/tmp/repo", None, True),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/utils/test_get_file_path.py:32
("subdir/../../../outside.txt", "/tmp/repo", None, True),
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
assets/data-convert-flow.png
assets/data-convert-flow.png
Why it matters. 1340639 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/demo-en.gif
assets/demo-en.gif
Why it matters. 8162070 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
llm_eval/data_set/test_data.json
llm_eval/data_set/test_data.json
Why it matters. 2843978 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
llm_eval/data_set/test_data_20250513_200023.json
llm_eval/data_set/test_data_20250513_200023.json
Why it matters. 3287133 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
llm_eval/data_set/test_data_20250515_190917.json
llm_eval/data_set/test_data_20250515_190917.json
Why it matters. 1211594 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG_EN.md:135
- **OpenRouter First Usage Approach**: Transitioned to OpenRouter First approach enabling access to all AI models with a single API key
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:69
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:546
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README_KR.md:69
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README_KR.md:546
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/uv_배포_가이드.md:19
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f334a6dfb67cfull audit observations/trust-audit/mcp-server/selvage-lab__selvage.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f334a6dfb67cSAFEB87first audit
05

Questions

What is the Selvage MCP server?

An LLM-based code review MCP server with AST-powered smart context extraction

Is Selvage safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Selvage need?

It reads ANTHROPIC_API_KEY, GEMINI_API_KEY, OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Selvage run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as selvage.

How current is this page?

The grade is for one exact copy of the source (f334a6dfb67c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement