agentdesk-mcp
AgentDesk MCP — 对抗性 AI 审查
AI 流水线的质量控制 —— 一个 MCP 工具。适用于 Claude Code、Claude Desktop 以及任何 MCP 客户端。
29.5% 的团队不对 AI 输出进行任何评估。 (LangChain 调查) 知识工作者每周花费 4.3 小时核实 AI 输出。 (微软 2025)
AgentDesk MCP 解决了这个问题。在 30 秒内为任何 AI 流水线添加独立的对抗性审查。
快速开始
npm (推荐)
npx @ezark-publish/agentdesk-mcpClaude Code
claude mcp add agentdesk-mcp -- npx @ezark-publish/agentdesk-mcpClaude Desktop
{
"mcpServers": {
"agentdesk-mcp": {
"command": "npx",
"args": ["-y", "@ezark-publish/agentdesk-mcp"],
"env": { "ANTHROPIC_API_KEY": "sk-ant-..." }
}
}
}HTTP 传输 (可流式传输的 HTTP)
作为 HTTP 服务器运行,用于远程访问、Smithery 托管或多客户端设置:
# Start with HTTP transport on port 3100
MCP_HTTP_PORT=3100 npx @ezark-publish/agentdesk-mcp
# Or use the --http flag (defaults to port 3100)
npx @ezark-publish/agentdesk-mcp --httpMCP 端点:POST http://localhost:3100/mcp
健康检查:GET http://localhost:3100/health
从 GitHub 安装 (替代方案)
npm install github:Rih0z/agentdesk-mcp要求
ANTHROPIC_API_KEY环境变量(使用您自己的密钥 —— BYOK)
Related MCP server: open-code-review
工具
review_output
对任何 AI 生成的输出进行对抗性质量审查。独立的审查员会假设作者犯了错误,并主动寻找问题。
输入:
参数 | 必需 | 描述 |
| 是 | 待审查的 AI 生成输出 |
| 否 | 自定义审查标准 |
| 否 | 类别: |
| 否 | 审查员模型(默认: |
输出:
{
"verdict": "PASS | FAIL | CONDITIONAL_PASS",
"score": 82,
"issues": [
{
"severity": "high",
"category": "accuracy",
"description": "Claim about X is unsupported",
"suggestion": "Add citation or remove claim"
}
],
"checklist": [
{
"item": "Factual accuracy",
"status": "pass",
"evidence": "All statistics match cited sources"
}
],
"summary": "Overall assessment...",
"reviewer_model": "claude-sonnet-4-6"
}review_dual
双重对抗性审查 —— 两名独立的审查员从不同角度评估输出,然后由合并代理汇总结果。
如果任何一位审查员发现关键问题 → 合并后的结论为 FAIL(失败)
采用较低的分数
合并并去重所有问题
适用于质量至关重要的高风险输出。
参数与 review_output 相同。
工作原理
对抗性提示词:指示审查员假设输出存在错误。不给予任何信任。
基于证据的检查清单:每一项 PASS(通过)都需要具体证据。没有证据的项目会自动降级为 FAIL(失败)。
防作弊验证:如果超过 30% 的检查清单项目缺乏证据,整个审查将被强制判定为 FAIL,且分数上限为 50 分。
结构化输出:结论 + 数值分数 + 分类问题 + 检查清单(不仅仅是“看起来不错”)。
使用场景
代码审查:检查错误、安全问题、性能问题
内容审查:验证准确性、可读性、SEO、受众匹配度
事实核查:验证 AI 生成文本中的声明
翻译质量:检查准确性和自然度
数据提取:验证完整性和正确性
任何 AI 输出:摘要、报告、提案、电子邮件等
为什么不直接让同一个 AI 进行审查?
自我审查存在系统性的宽容偏差。审查自身输出的 LLM 共享导致错误的相同盲点。研究表明,模型在产生幻觉时使用自信语言的可能性高出 34%。
AgentDesk 使用独立的审查员调用和对抗性提示词 —— 这与自我审查有着本质区别。
对比
功能 | AgentDesk MCP | 手动提示词 | Braintrust | DeepEval |
单工具设置 | 是 | 否 | 否 | 否 |
对抗性审查 | 是 | 自行实现 | 否 | 否 |
双重审查员 | 是 | 自行实现 | 否 | 否 |
防作弊验证 | 是 | 否 | 否 | 否 |
无需 SDK | 是 | 是 | 否 | 否 |
原生 MCP | 是 | 否 | 否 | 否 |
局限性
提示词注入:与所有“LLM 作为裁判”的系统一样,对抗性输入可能会试图操纵审查员的结论。防作弊验证层可以缓解表面的作弊行为,但坚定的对抗性输入仍然是一个挑战。对于高风险用例,请结合确定性验证使用。
BYOK 成本:每次
review_output调用会进行 1 次 LLM API 调用;review_dual会进行 3 次。请将其计入您的流水线成本中。
托管 API (独立产品)
对于偏好 HTTP 集成的团队,我们提供了一个带有额外功能(代理市场、上下文学习、工作流)的托管 REST API,网址为 agentdesk.usedevtools.com。
开发
git clone https://github.com/Rih0z/agentdesk-mcp.git
cd agentdesk-mcp
npm install
npm test # 35 tests
npm run build许可证
MIT
由 EZARK Consulting 构建 | 网页版
Available Tools
4 toolsexecute_serviceC
Execute a service on the AgentDesk marketplace. Requires an AgentDesk API key for authentication. Pass service-specific input parameters.
| Name | Required | Description | Default |
|---|---|---|---|
| service_id | Yes | Service ID to execute (e.g., "review", "web_scrape", "realtime_jp", "pdf_generate", "summarize", "classify") | |
| input | Yes | Service-specific input parameters | |
| api_key | No | BYOK: Your Anthropic API key (for AI-powered services like review) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It mentions only an authentication requirement (API key) but does not describe side effects (e.g., whether executing a service modifies state), idempotency, rate limits, or error conditions. The description is insufficient for an agent to understand what happens when the tool is invoked.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is very concise at two sentences with no wasted words. However, it could be more informative within the same length by clarifying the service execution context or referencing the sibling tools. The front-loading is reasonable but the brevity sacrifices completeness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of annotations and output schema, the description is insufficiently complete. It does not explain return values, error handling, or how to properly use the api_key parameter. For a tool with nested objects and no output schema, more context is needed to guide the agent effectively.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% as all parameters have descriptions. The description adds minimal value: it notes 'service-specific input parameters' but does not elaborate on how to structure the 'input' object for different service IDs. The api_key parameter is described in the schema as 'BYOK: Your Anthropic API key', while the description mentions an 'AgentDesk API key', causing slight inconsistency. Overall, the description does little beyond what the schema already provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Execute a service') and the resource ('AgentDesk marketplace'), providing a specific verb+resource pair. However, it does not distinguish this tool from its siblings (list_services, review_dual, review_output), which could lead to confusion about when to use this generic service execution tool versus those specialized tools.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description mentions requiring an API key and passing service-specific input, but provides no guidance on when to use this tool versus alternatives like list_services or review_dual. There is no mention of prerequisites (e.g., selecting a service from list_services first) or when not to use this tool. The phrase 'service-specific input parameters' lacks detail on how to determine which parameters are appropriate for a given service_id.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_servicesA
List all available services on the AgentDesk marketplace. Returns service catalog with pricing, quality scores, and capabilities. Filter by category, minimum quality score, maximum price, or capability.
| Name | Required | Description | Default |
|---|---|---|---|
| category | No | Filter by category: quality_assurance, web_scraping, realtime_data, document_generation, text_processing | |
| min_score | No | Minimum quality score (0-100) | |
| max_price | No | Maximum price per call in USD | |
| capability | No | Filter by capability keyword |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must disclose behaviors; it mentions returning service details but omits pagination, rate limits, or any restrictions. It is adequate but not thorough.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences with no wasted words: first sentence states purpose, second adds return content and filters. Extremely concise.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple listing tool with no output schema and no annotations, the description covers the basics but lacks details on pagination, error handling, or output structure, which might be needed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Input schema has 100% description coverage, and the description merely lists the filter names without adding meaning beyond what the schema already provides, so it meets the baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'List' and resource 'available services on the AgentDesk marketplace', and distinguishes from siblings by focusing on browsing the catalog, while sibling tools execute or review services.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for browsing services with filters, but does not explicitly state when to use this tool versus alternatives like execute_service or review tools, nor provides exclusions or conditions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
review_dualA
Dual adversarial review: two independent reviewers assess the output from different angles, then a merge agent combines their findings. Stricter than single review — if either reviewer finds a critical issue, the merged verdict is FAIL. Use for high-stakes outputs where quality is critical.
| Name | Required | Description | Default |
|---|---|---|---|
| output | Yes | The AI-generated output to review (max 100K chars) | |
| criteria | No | Custom review criteria | |
| review_type | No | Review category label | |
| model | No | Reviewer model ID (default: claude-sonnet-4-6) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must cover behavior. It explains the dual review process and the merge verdict logic, but omits details like side effects, authentication needs, or output structure, leaving gaps for an agent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: the first explains the process, the second provides usage guidance and the verdict rule. No extraneous words, highly efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given 4 parameters, no output schema, and no annotations, the description adequately explains the core functionality but does not cover output format, error handling, or prerequisites, leaving room for improvement.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
With 100% schema description coverage, the schema already documents all parameters. The description adds no additional meaning beyond what is in the schema, so it does not improve understanding of parameter usage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description explicitly states the tool performs a dual adversarial review with two independent reviewers and a merge agent. It clearly distinguishes itself from the sibling tool 'review_output' by being stricter and specifying the verdict rule.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description advises using this tool for high-stakes outputs and contrasts it with single review, but does not explicitly state when not to use it or list alternatives beyond the implied single review.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
review_outputB
Adversarial quality review of any AI-generated output. An independent reviewer assumes the author made mistakes and actively looks for problems. Returns structured verdict (PASS/FAIL/CONDITIONAL_PASS), score (0-100), categorized issues with severity, and evidence-based checklist. Works for any output type: code, content, summaries, translations, data extraction, etc.
| Name | Required | Description | Default |
|---|---|---|---|
| output | Yes | The AI-generated output to review (max 100K chars) | |
| criteria | No | Custom review criteria — what specifically to check for | |
| review_type | No | Review category label (e.g., "code", "content", "factual", "translation") | |
| model | No | Reviewer model ID (default: claude-sonnet-4-6) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden for behavioral transparency. It describes the output structure (verdict, score, issues) but does not disclose any potential side effects, destructive actions, authentication needs, or rate limits. The 'adversarial' nature is mentioned but not elaborated.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise at two sentences, front-loading the core purpose and then detailing the output. Every sentence adds value; no redundant or verbose phrasing.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description effectively explains the return values (verdict, score, issues, checklist). It covers the tool's broad applicability and key inputs. Minor omissions: it does not clarify that 'criteria' is optional or describe defaults for 'review_type' and 'model'.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%—all four parameters have descriptions in the schema. The description does not add additional meaning beyond the schema; it only summarizes the output format. Baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it performs an adversarial quality review of AI-generated output, using specific verbs ('review') and a resource type ('output'). It does not differentiate from the sibling tool 'review_dual', suggesting both may perform reviews, so it misses the top score for sibling distinction.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage for quality checking of any AI output, but provides no explicit guidance on when to use this tool versus alternatives (e.g., 'review_dual') or when not to use it. It lacks clear context for exclusion or alternative selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
4 tool updates
v1.3.0- First observed
execute_service - First observed
list_services - First observed
review_dual - First observed
review_output
TDQS
Scored across 4 tools
The four tools are clearly divided into two distinct categories: marketplace services (execute_service, list_services) and output review (review_dual, review_output). Even within the review category, the two tools have well-differentiated purposes (single vs. dual adversarial review), so there is no ambiguity.
All tool names follow a consistent verb_noun pattern in snake_case: execute_service, list_services, review_dual, review_output. The naming is predictable and easy to understand.
With 4 tools, the server covers two distinct functions. While each function could benefit from more tools (e.g., more marketplace operations or review management), the current count is reasonable for a focused server and does not feel excessive or insufficient.
The marketplace side only offers list and execute, lacking create, update, or delete operations for services. The review side provides two types of reviews but no ability to list or manage past reviews. These gaps limit the server's coverage for its implied domain.
Maintenance
Related MCP Connectors
Adversarial behavioural-bias engine — audits your decisions for cognitive biases via your own AI.
Expert review for AI agents. On-chain proof of human review.
Agentic code review, no signup to try: reality gates + frontier-model review, with veto.
Devil's-advocate QC API for AIs: post a decision, get strongest counter-argument. 0.1 USDT/call
Related MCP Servers
- AlicenseNot gradedqualityNot gradedmaintenanceEnables AI-assisted code review with bias mitigation strategies through cross-model evaluation and bias-aware prompting. Detects AI-generated code from commit authors and provides structured reviews with security, performance, and maintainability analysis.-
- FlicenseAqualityCmaintenanceAI-powered code review tool that detects AI-generated code defects invisible to traditional linters — hallucinated packages, deprecated APIs, cross-file contradictions, hidden security anti-patterns, and over-engineering. Works as a standalone CLI, GitHub Action, or MCP server. Supports TypeScript, Python, Java, Go, and Kotlin. Free for individuals, no API key required.438-

HumanJudgeofficial
AlicenseNot gradedqualityBmaintenanceHuman-evaluation infrastructure for AI quality. 25,000+ blind human reviews by 200+ verified reviewers across 58 AI models — query the data via five MCP tools (get_model_scores, compare_models, get_flags, check_content, get_latest).2MIT- AlicenseNot gradedqualityCmaintenanceEnables AI-powered, zero-trust code review with multiple models, supporting single files, git diffs, and multiple files, with security, performance, and architecture checks across 10+ languages.13MIT