cross-review
The cross-review server orchestrates API-first peer review across six AI providers (Claude, ChatGPT Codex, Gemini, DeepSeek, Grok, and Perplexity) with unanimous convergence gates. Here's what you can do:
Run & Manage Reviews
ask_peers— Run a single synchronous review round against selected peersrun_until_unanimous/session_start_unanimous— Iteratively review until all peers converge or a round limit is hit (foreground or background)session_start_round— Launch a background review round and return a job ID immediately
Session Lifecycle
Create, list, read, poll, and finalize durable review sessions
Cancel running jobs, recover interrupted sessions, and auto-finalize idle sessions via sweep
Stream session events incrementally
Evidence & Truth Management
Attach operator-custodied text evidence (append-only, SHA-256 tracked)
Update evidence checklist items and run single or consensus LLM judge passes to verify satisfaction
Re-run local truthfulness preflight checks after attaching evidence
Reporting & Observability
Generate full Markdown session reports (convergence, peer decisions, costs, events)
Pull aggregate/per-session metrics, peer reliability reports (error rates, latency, cost), and judgment precision reports (precision/recall/F1)
Audit session health via
session_doctorandsession_check_convergence
Governance & Security
Formally contest a final verdict to open a new linked deliberation cycle
Escalate issues for human operator intervention
Rotate per-agent F1 identity capability tokens
Server Inspection & Setup
Query runtime capabilities, version, and config fingerprint
Probe all provider APIs to discover available models and verify reachability
Key design properties: three deliberation modes (ship/review/circular), per-peer reasoning effort overrides, relator lottery (random non-caller lead reviewer), financial budget caps, and a CROSS_REVIEW_STUB=1 mode for no-cost CI/smoke testing.
Enables cross-review using Google's Gemini API, allowing Gemini to contribute to the review process.
Enables cross-review using OpenAI's API (ChatGPT Codex), allowing OpenAI models to participate in the review process.
Enables cross-review using Perplexity's API, allowing Perplexity to participate in the review process.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@cross-reviewcross-review my latest code changes for bugs"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
cross-review
MCP server orchestrating API-first cross-review between Claude, ChatGPT Codex, Gemini, DeepSeek, Grok, and Perplexity with unanimous convergence gates.
Upgrade from the published registry.
npm upgrade -g @lcv-ideas-software/cross-review --@lcv-ideas-software:registry=https://registry.npmjs.org --ignore-scripts --allow-git=none --allow-remote=none
# or using the GitHub Packages mirror:
npm upgrade -g @lcv-ideas-software/cross-review --@lcv-ideas-software:registry=https://npm.pkg.github.com --ignore-scripts --allow-git=none --allow-remote=nonenpm 12 global operations evaluate the whole global dependency tree, not this
package's project policy in isolation. The command therefore disables every
install-time script and keeps Git and remote-URL dependencies blocked. The
published package has no install lifecycle and is tested in this mode. Never add
--dangerously-allow-all-scripts, and do not install a locally built source
tree or tarball as a substitute for the published registry release.
Status. Stable. The current source/release target is v04.05.23 (package 4.5.23).
Use the npm badge or npm view @lcv-ideas-software/cross-review version for
registry state and server_info for the version actually loaded by an MCP
window. See
CHANGELOG.md for the full release history.
Project renamed 2026-05-15. This project was previously published as
@lcv-ideas-software/cross-review-v2(versions 0.x through 3.7.5). v4.0.0 is the first release under the shorter canonical name@lcv-ideas-software/cross-reviewafter the companioncross-review-v1project was discontinued and archived. Historical CHANGELOG entries below v4.0.0 reference the prior name verbatim.
The version history at a glance:
Release | Scope |
| Accepts npm 12's one-item |
| Decodes npm's Sigstore DSSE envelope before binding the SLSA provenance to the protected tag, publication workflow, and immutable source commit; the later cryptographic |
| Aligns the durable effective-config regression with JSON semantics: unset optional properties are omitted consistently from persisted snapshots and their SHA-256 canonical form. |
| Restores a deterministic CI fixture for the pre-publish budget/cache contract: Gemini has an explicit test rate and a manually known settlement cannot retain a stale unknown-spend marker. The production financial gate remains fail-closed. |
| Hardens the npm publication gate without weakening artifact verification: an integrity-bound temporary lock drives |
| Closes the 4.5.16–4.5.17 session-audit findings: symmetric grounding for blocking verdicts, per-peer write-through durability, terminal preflight audit trails, bounded evidence judges, complete cache/config telemetry and action-oriented compact reports. |
| Publishes the accumulated provider/toolchain maintenance, raises the Anthropic SDK range and keeps npm 12 dependency scripts fail-closed with an exact, reviewed Google Gen AI 2.12.0 no-op lifecycle permission. |
| Makes background observation compact and race-safe: summary polling by default, explicit forensic detail, real HTML-neutralized Markdown, durable cross-host job status and idempotent late-cancellation results with final state. |
| Ships the Evidence Broker continuity fix with the complete Dependabot hardgate: supported npm resolver, npm 12 build/release pin, pip-compile source+hash lock, grouped Python updates and concurrent-base merge retry. |
| Restores Evidence Broker continuity safely: clean grounded historical READY sources are replayed locally without stale prompt reuse, strict same-owner aliases collapse, |
| Eliminates a repeated ReDoS class in Evidence Broker symbol extraction and makes publication wait for CodeQL on the exact SHA plus zero actual open code-scanning alerts. |
| Fixes Evidence Broker convergence: direct rounds receive unresolved checklist IDs, grounded same-requester rechecks close the correct item, natural-language alternatives no longer deadlock, and irrelevant or partial evidence still fails closed. |
| Makes autonomous evidence routing unambiguous in the MCP contract: AI evidence is persisted automatically through review starters, while the optional operator authority-promotion tool cannot be mistaken for a mandatory human upload step. |
| Retries npm attestation propagation independently from package visibility and follows the registry-advertised pathname on the pinned npm registry origin, preventing false-negative post-publish failures without weakening SLSA provenance requirements. |
| Keeps server-authored READY remediation out of peer |
| Hash-pinned npm 12.0.1 bootstrap across CI/release jobs and trusted default-branch auto-tag checkout with exact successful-CI SHA gating; closes code-scanning alerts 32–38. |
| Complete 4.5.6 provider remediation plus CI-before-tag release ordering, npm 12.0.1 alignment, strict dependency-script review, cache exclusion and install-only StepSecurity token scope. |
| Six-provider contract remediation — provider-specific wire schemas and output budgets, controlled OpenAI/Gemini truncation recovery, safe citation/diff correlation, runtime namespace fixes, corrected FinOps, and npm 12/OIDC release hardening. |
| Clean-runner publish follow-up — make cancellation, health and accounting regression fixtures independent from private operator rate cards and reject false-green preflight coverage; production financial gates remain fail-closed. |
| Runtime-hardgate remediation — fix grounding, truthfulness namespaces, consensus judging, multi-window cancellation, accounting, session ceilings, terminal reports and cross-provider |
| Security/hardgate patch — remove exponential regex backtracking, trust integrity-checked attachment path/digest metadata, accept correlated single-quoted artifact literals and stop treating source-version bumps as historical runtime claims. |
| Patch release — publish the complete authenticated-evidence transport update with a hermetic clean-runner regression fixture; no operator central configuration is required by the test gate. |
| Patch release — restore authenticated peer evidence transport with append-only active snapshots, combined preflight parity, strict operational records, independent relator/reviewer roles and immutable terminal outcomes; no manual operator attachment is required. |
| Minor release — refresh all six provider contracts and add fail-closed provider terminals, runtime config fingerprints, operator evidence custody, peer self-attestation rejection, and grounded READY votes. |
| Patch — raise the transitive |
| Patch — promote the patched |
| Patch — close the remaining Claude re-validation tail: orchestrator attached-evidence reads now fail closed, session_doctor defaults to action-oriented findings, and T2#10 source-regex debt drops to a locked total of 160. |
| Patch — close the seven verified residual audit items: evidence fail-closed realpath handling, typed shadow-decision runtime events, derived release date, redaction-comment correction, retry/security gate verification, and a locked T2#10 smoke source-contract budget. |
| Patch — central config can now carry model-specific rate cards, so Claude Opus 4.8 and Claude Fable 5 pricing are both stored and the active Anthropic rates follow the configured Claude model automatically. |
| Patch — continue the T2#10 smoke-debt reduction by moving the lazy provider SDK import source contract into the dedicated source-contract smoke, preserving coverage while reducing broad smoke regex pins. |
| Patch — support Claude Fable 5 as an explicit Anthropic production-model option, including verified model selection, refusal handling, refusal events, docs and cost guidance. |
| Patch — complete residual audit sweep: full mutating-tool identity gate, evidence attachment cache/safety, async EventLog flush, Perplexity auth-only probe mode, cache-cost correctness, dashboard report method split, and dedicated source-contract smoke isolation. |
| Minor — consolidated audit close-out: log-level validation, realpath containment, initial-draft fabrication guard, Perplexity probe minimization, identity audit events, derived tool list, docs and metadata guards. |
| Patch — move |
| Patch — move |
| Patch — evidence preflight now blocks paid review when the submission references an external evidence/log artifact that was not attached to the session. |
| Patch — isolate |
| Patch — filter Perplexity streaming |
| Patch — harden cross-process event sequencing, exact-match fabrication checks, Gemini missing-text handling, and streaming provider error retry classification. |
| Patch — add forensic diagnostics for append/event and identity failures, flush pending events on shutdown signals, retry structured provider 5xx errors, and refresh official AI provider SDKs. |
| Patch — harden persistence redaction, finalized-session mutation guards, side-effect identity gates, caller-token rotation output, and Windows registry config fallback. |
| Patch — tighten skip-peer classification so non-retryable provider errors block, while Anthropic overload events remain retryable and better surfaced in skip diagnostics. |
| Minor — P1/P2/P3 follow-up with unresolved-evidence close-out visibility, an offline fixture eval harness, and a read-only peer reliability report. |
| Patch — harden session auditability with terminal events, cost split reporting, |
| Patch — harden truthfulness preflight auditability, add a read-only preflight retest tool, and reduce false parser warnings for attached/log evidence. |
| Patch — promote the Gemini canonical default to |
| Patch — provider-doc refresh, Perplexity probe repair, current model pins, and rate-card guidance. |
| Patch — publish the workspace hard-gate cleanup as a package release. |
| Minor — bounded MCP session listing and cancellation semantics cleanup. |
| Patch — release the hard-gate cleanup as a published package. |
| Minor — security hardening of session-store concurrency, write-path DoS surface, and credential redaction. |
| Patch — eliminate the recurring |
| Patch — bounded npm registry fetch in the post-publish verifier. |
| Patch — Windows-safe registry verifier. |
| Patch — hard-gate close-out for the Codex v4.0.4 audit. |
| Patch — restore prettier coverage of |
| Patch — biome/check gate wiring after the v4 rename. |
| Patch — Codex second-pass audit close-out (6 findings). |
| Patch — close-out of post-v4.0.0 audit (eight surfaces left stale by the rename bulk-replace). |
| Major — project renamed to |
| Patch — logs+sessions study 2026-05-15 close-out (4 surgical fixes from 244-session/429-round corpus). |
| Patch — "sem fallback é sem fallback" directive + Codex v3.7.2 parecer residuals. |
| Patch — Codex 3rd super-audit close-out of v3.7.1 |
| Patch — Codex super-audit close-out of v3.7.0 |
| Minor — Codex super-audit close-out 2026-05-14 |
| Minor — observability + caller-discipline close-out 2026-05-14 |
| Minor — Codex operational-report close-out 2026-05-14: 5 findings from sessions |
| Minor — Perplexity multi-failure-mode close-out 2026-05-13: 3 coordinated fixes covering 7 production sessions Codex flagged ( |
| Minor — Caller peer-selection lock (operator directive 2026-05-12: "TODOS OS AGENTES/PEERS SEMPRE PARTICIPAM, INDEPENDENTE DA ESCOLHA OU VONTADE DO CALLER"). |
| Patch — Codex bug-report close-out 2026-05-12: three surgical fixes (Perplexity |
| Minor — Central config file ( |
| Major — Perplexity joins the sexteto. Quinteto (5 peers) → sexteto (6). |
| Minor — Cold-start hardening Part 3: Windows registry env-var lookup bulk-cached (3-7 s → ~100 ms). |
| Patch — Cold-start hardening Part 2: lazy-load 5 provider SDKs + defer 6 startup sweeps to setTimeout(30s). |
| Minor — Cold-start hardening Part 1: corrupted meta.json auto-quarantine + finalized-session auto-prune. |
| Patch — |
| Minor — Full pricing-model schema: base + extended-tier + cache (read/write) + promo (limited-time discount), all env-configurable, graceful fallback when fields are absent or promo expires. |
| Patch — |
| Third deliberation mode |
| Evidence-provenance lock for the ship-mode relator (Codex bug report 2026-05-10). |
| Anthropic empty-revision degenerate path detection. |
|
|
| Cross-provider prompt caching across all 5 peers (OpenAI, Anthropic, Gemini, DeepSeek, Grok). |
| Site sponsor card iteration. |
| Patch — |
| Patch — Gemini API function-declaration compatibility for MCP tool inputSchemas. |
| Patch — anti-drift smoke drivers for v2.18.4 audit closure (operator directive 2026-05-07). |
| Patch — Codex external audit 2026-05-07 outcome: 6 surgical fixes (P1.1, P1.2, P1.3, P1.4, P2.1, P2.4). |
| Patch — Gemini default pin bump |
| Tier 5 — Windows process-tree introspection (coordinated with cross-review-v1 v1.12.2). |
| Hotfix: closes Dependabot security advisory GHSA-v2v4-37r5-5v8g (medium severity) — |
| F1 caller capability tokens (coordinated with cross-review-v1 v1.11.0). |
| HARD GATE — identity forgery rejection (operator directive 2026-05-05). |
| Tribunal protocol repair plus operational doctor. |
|
|
| Backlog bundle for operational judge controls. |
| Grok reasoning model hotfix. |
| Grok joins the tribunal. |
| Lead meta-review drift fix. |
| Shadow judge observability. |
| Relator lottery plus shadow auto-wire. |
| LLM evidence-judge pass. |
| Per-peer health and Evidence Broker lifecycle. |
| Evidence Broker. |
| Fallback/recovery budget hard gate. |
| Token-delta compaction plus v2.5 format hotfix bundle. |
| Evidence and budget hardening pass. |
| CI stub fail-fast hotfix. |
| Audit-closure hardening pass. |
| Prompt shielding and financial safety. |
| CI-green README/docs cleanup. |
| README organizational standardization. |
| Provider-neutral |
| Provider token streaming. |
| CodeQL and model-selection hardening. |
| First stable |
| Session event race hotfix. |
| Background sessions and durable reports. |
| Publishing and dashboard sanitization. |
| Public npm/package metadata alignment. |
| Development package line hardening. |
| Durable session recovery alpha. |
| Model attestation and store hardening alpha. |
| Initial API/SDK-only MCP server. |
What It Does
cross-review is the stable API-first implementation of the cross-review
pattern. It orchestrates provider API clients (OpenAI/Codex, Anthropic/Claude,
Google Gemini, DeepSeek, xAI/Grok, and Perplexity Sonar) and provides an
MCP-compatible server surface.
Runtime calls are real provider calls by default. Stubs exist only for smoke
tests and CI when CROSS_REVIEW_STUB=1.
OpenAI client library for the Codex/OpenAI peer.
Anthropic TypeScript client library for Claude.
Google Gen AI client library for Gemini.
OpenAI-compatible DeepSeek API through the OpenAI client library.
OpenAI-compatible xAI Grok API through the OpenAI client library.
OpenAI-compatible Perplexity Sonar API through the OpenAI client library.
Related MCP server: Multi-MCP
Quick Start
# Set API keys (PowerShell example)
[Environment]::SetEnvironmentVariable("OPENAI_API_KEY", "<OPENAI_API_KEY>", "User")
[Environment]::SetEnvironmentVariable("ANTHROPIC_API_KEY", "<ANTHROPIC_API_KEY>", "User")
[Environment]::SetEnvironmentVariable("GEMINI_API_KEY", "<GEMINI_API_KEY>", "User")
[Environment]::SetEnvironmentVariable("DEEPSEEK_API_KEY", "<DEEPSEEK_API_KEY>", "User")
[Environment]::SetEnvironmentVariable("GROK_API_KEY", "<GROK_API_KEY>", "User")
[Environment]::SetEnvironmentVariable("PERPLEXITY_API_KEY", "<PERPLEXITY_API_KEY>", "User")Restart your terminal after changing environment variables.
Run the MCP host only from the package published by the registry; do not point a production host at this checkout:
npm upgrade -g @lcv-ideas-software/cross-review --@lcv-ideas-software:registry=https://registry.npmjs.org --ignore-scripts --allow-git=none --allow-remote=noneFor local smoke tests (no-cost):
$env:CROSS_REVIEW_STUB = "1"
npm --registry=https://registry.npmjs.org testConfiguration
Model selection and runtime behaviour can be controlled with environment variables. Example overrides (PowerShell):
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_OPENAI_MODEL", "gpt-5.6-sol", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_OPENAI_REASONING_EFFORT", "max", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_ANTHROPIC_MODEL", "claude-fable-5", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_ANTHROPIC_REASONING_EFFORT", "max", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_GEMINI_MODEL", "gemini-3.1-pro-preview", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_DEEPSEEK_MODEL", "deepseek-v4-pro", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_GROK_MODEL", "grok-4.5", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_GROK_REASONING_EFFORT", "high", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_PERPLEXITY_MODEL", "sonar-reasoning-pro", "User")ultra is a Codex product/CLI execution mode, not a literal OpenAI Responses
API reasoning.effort. Cross-review nevertheless accepts it in central config,
environment variables and per-call overrides as a compatibility alias, then
normalizes it inside each provider adapter. For gpt-5.6-sol, the wire value is
the official max; ultra is never sent to the Responses API. Using max
directly remains equivalent and makes the API value explicit. The shared
legacy value minimal is likewise translated to GPT-5.6's lowest active API
effort, low. Explicit older-model overrides use a family-aware compatibility
matrix: GPT-5.5/5.4/5.2 map minimal to low and max/ultra to xhigh;
GPT-5.1 maps minimal to low and xhigh/max/ultra to high; original
GPT-5 maps none to minimal and xhigh/max/ultra to high. Supported
native values pass through unchanged.
Claude Fable 5 is the canonical Anthropic pin. Its request deliberately omits
the explicit thinking field: Fable applies adaptive thinking automatically,
while output_config.effort controls depth. Anthropic documents a 30-day data
retention posture and no zero-data-retention option for this model. A response
with stop_reason="refusal" is recorded as provider_refusal, and partial
refusal output is not accepted as a review.
For Grok, GROK_API_KEY is canonical. The default pin is grok-4.5; xAI
accepts only low, medium, or high reasoning effort for it, so the adapter
clamps the shared scale before sending the request.
Central configuration is loaded once when the MCP server process starts. Use
server_info.config_load to inspect the loaded path, parse result, loaded and
current SHA-256/mtime, and reload_required. live_reload_supported is
false: after editing config.json or host environment variables, restart or
reload the MCP host/window. A stale or invalid central config blocks paid calls
instead of silently spending under fallback defaults.
Evidence judges have independent compact controls:
evidence_judge_autowire.max_output_tokens defaults to 2048 and
evidence_judge_autowire.reasoning_effort defaults to medium. Unknown
in-flight provider cost blocks judge dispatch rather than being treated as
zero. Their environment-variable equivalents are
CROSS_REVIEW_EVIDENCE_JUDGE_MAX_OUTPUT_TOKENS and
CROSS_REVIEW_EVIDENCE_JUDGE_REASONING_EFFORT; as with the other central
settings, an explicit host environment value takes precedence over
config.json.
Financial and budget controls are required for paid provider calls. Configure these environment variables before running real sessions (example):
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_MAX_SESSION_COST_USD", "20", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_PREFLIGHT_MAX_ROUND_COST_USD", "20", "User")
[Environment]::SetEnvironmentVariable("CROSS_REVIEW_UNTIL_STOPPED_MAX_COST_USD", "20", "User")MCP Tools
server_inforuntime_capabilitiesprobe_peerssession_initsession_listsession_readask_peerssession_start_roundrun_until_unanimoussession_start_unanimoussession_cancel_jobsession_recover_interruptedsession_pollsession_eventssession_metricssession_doctorsession_reportsession_peer_reliability_reportsession_check_convergencesession_preflight_checksession_truthfulness_preflight_checksession_attach_evidence— optional operator-only authority promotion; AI callers use the automaticevidencefield on review starterssession_evidence_checklist_updatesession_evidence_judge_passsession_evidence_judge_consensus_passsession_judgment_precision_reportcontest_verdictescalate_to_operatorregenerate_caller_tokenssession_sweepsession_finalize
session_poll uses detail="summary" by default. The compact response keeps
operational progress, verdicts, bounded peer summaries and convergence data,
but omits complete prior-round peer text, raw and structured
payloads. Use detail="full" or session_read only for deliberate forensic
inspection. active_round_number names the round executing now, whereas
latest_completed_round_number names the newest round already appended to
durable history; during a live round these values can differ.
Every tool that accepts response_format="markdown" returns actual Markdown,
not a JSON object serialized inside a text block. Strings from callers, peers
and persisted sessions are HTML-neutralized before rendering.
session_cancel_job is idempotent around settlement races. A late request
for a known completed, failed or cancelled job returns requested=false,
reason="job_already_terminal", terminal_job and final_state. When
the session itself is already terminal, the reason is
session_already_terminal. Compact job status is persisted per session so a
sibling MCP host or a restarted runtime can return the same answer without
requiring process-local memory.
session_doctor separates real and stub sessions, flags terminal outcomes that
lack terminal events, and reports peer-call cost separately from generation
artifact cost. Terminal max-rounds and terminal not_resurfaced history stay
in totals but are omitted from default operational findings; pass
include_terminal_findings=true to enumerate that historical inventory.
session_report uses the same cost split and calls out not_resurfaced
evidence checklist items as inference-only, not proof that the requested
evidence was satisfied. If a session otherwise reaches unanimity with open or
not_resurfaced checklist items, finalization records an
*_with_unresolved_evidence outcome reason and emits a durable unresolved
evidence event. session_peer_reliability_report is read-only and aggregates
per-peer parser warnings, evidence ask status, provider failures, cost and
latency.
Anti-deception and evidence custody
The runtime does not treat a peer's claim that work was completed as proof.
Before paid calls and again during convergence, it checks runtime/model claims,
workflow and authorization assertions, test/build/hash claims, concrete source
correspondence, unresolved evidence asks, model attestation, and structured
status completeness. Authenticated caller evidence supplied inline or through
the evidence field is persisted with an integrity digest and transported to
every reviewer as PEER-SUBMITTED / UNVERIFIED; no manual operator attachment
is required. Each external submission atomically supersedes the active caller
snapshot while preserving prior manifests for audit, so retries cannot inherit
old failures or replay old successes. Every READY vote must cite sources traceable to the reviewed
artifact or admitted evidence. When operational claims depend only on
peer-submitted material, at least two independent non-author reviewers must use
confidence="verified" and cite the attachment path, SHA-256 and correlated raw
lines; one voter, inferred confidence or narrative repetition cannot converge.
Relator output that invents operational evidence is rejected rather than
propagated.
READY is intentionally not free-form. Its summary must be exactly
No blocking objections remain., caller_requests and follow_ups must be
empty, and no narrative may appear outside the JSON/status envelope. Detail
belongs in evidence_sources. This removes synonym/negation ambiguity: any
noncanonical READY becomes NEEDS_EVIDENCE and cannot converge.
Each attachment-backed evidence_sources item has one canonical string format:
Attachment: evidence/review.txt
sha256=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Artifact quote: "Tests 74 passed (74)"This block shows the decoded string; a raw JSON response encodes its two line
breaks as \n.
The path and full 64-character lowercase digest identify the same persisted
attachment, and Artifact quote is a literal from that attachment. The quote
must be at least 12 characters and must end the item. Cite the smallest
sufficient literal (normally no more than 500 characters); the hard limits are
2,500 characters per whole item and 30 items. Multiple sources belong in
separate array items—never join attachments or append rationale after a quote.
The wire type deliberately remains string[], so existing string-producing
clients remain compatible; the runtime does not require citation objects.
These limits are both anti-verbosity and anti-shortcut controls. A peer must
inspect the artifact and cite the decisive raw value, but must not replace a
review with a full-file, full-log, or provider-output dump. A bare filename,
digest, generic assurance, or empty code fence cannot sustain READY.
Only the human operator may call the optional session_attach_evidence
authority-promotion surface or mutate terminal state and security
configuration. This tool is never required for an ordinary AI-initiated
review: the runtime tool descriptions and rejected-call remediation direct AI
callers to the automatically persisted evidence field. Each new attachment
records the verified caller, origin, timestamp, byte count and SHA-256, emits a
durable custody event, and is re-hashed on every read.
Tampering fails closed. Peer-attributed material remains reviewable but cannot
grant operator authority; a generic attachment does not by itself prove an
unrelated claim.
An evidence requester may automatically withdraw only its own earlier ask after
a strictly grounded READY/verified recheck. That transition is recorded as
requester_reverified; silence remains not_resurfaced, and no peer can close
another peer's ask or an operator-terminal item.
On an existing session, review starters require the persisted petitioner token
or the dedicated operator token. Evidence is attributed to the authenticated
invoker rather than inherited from the session owner, so a peer cannot turn its
submission into operator_verified by continuing an operator-owned session.
Caller identity uses seven distinct local capabilities: one for each peer and
one for operator. Operator tools require the operator token even when token
enforcement for peers is otherwise permissive. Keep that token only in a
dedicated human-console MCP host—placing it in a model host grants that model
operator authority. host-tokens.json contains secrets and assumes the local
OS account/data directory is trusted.
session_cancel_job and contest_verdict accept only the explicitly persisted
session petitioner with its peer token, or the dedicated operator. Legacy
sessions without an explicit petitioner require the operator token.
Repository conventions
License: Apache-2.0. See NOTICE and THIRDPARTY.
Security disclosure: see SECURITY.md.
Code of conduct: see CODE_OF_CONDUCT.md.
Changelog: CHANGELOG.md.
Contributing: see CONTRIBUTING.md.
Sponsorship: see the repo's
Sponsorbutton or central sponsor page.Action pinning: all GitHub Actions are pinned by full SHA per supply-chain hardening baseline.
Code owners: .github/CODEOWNERS.
Links
License
Apache-2.0. See LICENSE, NOTICE, and THIRDPARTY.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/LCV-Ideas-Software/cross-review'
If you have feedback or need assistance with the MCP directory API, please join our Discord server