Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
OCR_MCP_TIMEOUTNo单次扫描超时(秒)120
OCR_MCP_SEMGREP_BINNo分析器可执行文件semgrep
OCR_MCP_MAX_FINDINGSNo单次返回的命中上限50
OCR_MCP_SEMGREP_CONFIGNo规则集。可用 p/security-audit、p/python 或本地规则文件p/default

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
semgrep_scanA

Run deterministic static analysis (Semgrep) over repository files and return findings with exact line numbers plus the matched source snippet.

Use this to substantiate a suspected defect rather than guessing at it: the results are rule matches, so a hit is a fact. The snippet can be reused directly as existing_code when emitting a comment.

Scope paths to the file currently under review. OpenCodeReview only allows comments on the file being reviewed, so findings in other files cannot be reported even when the tool returns them.

An empty result is not a clean bill of health — it means no configured rule matched. The ruleset is broad but not exhaustive.

semgrep_scan_diffA

Run deterministic static analysis (Semgrep) restricted to the lines changed between two revisions, and return findings with exact line numbers plus the matched source snippet.

Prefer this over semgrep_scan when reviewing a pull request. OpenCodeReview reviews a diff and only permits comments on changed lines, so a finding on an untouched line cannot be reported — this tool does not return those at all, which keeps the result short and entirely actionable.

base and head are any git revisions (abc123, main, HEAD~1). Pass paths to narrow the scan to specific changed files.

semgrep_statusA

Report whether deterministic analysis is available: the Semgrep binary in use, its version, the active ruleset, and the per-call limits. Call this once if a scan reports that it is unavailable.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.4/5.0

Scored across 3 tools

Disambiguation5/5

All three tools have clearly distinct purposes: one scans an entire repository, one scans only changed lines, and one reports tooling status. The descriptions explicitly clarify when to prefer scan_diff over scan, eliminating meaningful ambiguity.

Naming Consistency5/5

Every tool follows the same snake_case `semgrep_*` prefix pattern, making the family instantly recognizable. The verb-like suffixes `_scan`, `_scan_diff`, and `_status` are consistent and predictable.

Tool Count5/5

Three tools is well-scoped for a focused analysis server: two scanning modes plus a status endpoint cover the core workflow without redundancy. Each tool earns its place; adding more would likely dilute the server's purpose.

Completeness5/5

The tool surface covers full-repo scanning, PR/diff scanning, and availability reporting, with no obvious dead ends. The status tool fills the operational gap for diagnosing unavailable scans, making the workflow self-contained.

Maintenance

ActivityMaintained
ResponsivenessNo issues