Agent Review MCP Server
Publishes the review package as a GitHub Draft PR through the user's own authenticated gh CLI: it builds a PR body plus a preview of inline comments under .agent-review/github/, then (only with explicit confirmed: true) commits, pushes, opens/reuses a Draft PR, and posts grouped review comments. Inline comments attach only to added lines of the current PR diff, at most one per logical change and capped by maxInlineComments (default 8), skipping generated files, lockfiles and formatting-only changes. Updates after a new push are surgical — a hidden marker (agent-review:session=…;change=…) ensures only Agent Review's own comments are replaced, leaving human and other-bot comments untouched. Also exposes read-only status checks (gh availability/auth, remote, branches, existing PR) and a matching CLI (github status|prepare-pr|publish-pr|update-review).
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Agent Review MCP Serverwrap up this session into a change package and review summary"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Agent Review
Local, verifiable review trails for AI coding agents.
When an AI agent builds a feature for you, the diff shows what changed but not why, which tests actually ran, or what risks the agent knew about. Agent Review records that evidence while the agent works and turns it into a review package you (and your reviewers) can trust:
a review session bound to a task and a git branch;
an append-only event journal of edits and commands;
restorable checkpoints (file snapshots, never
git reset);structured intents per logical change: what, why, expected behavior, risk, alternatives, limitations;
test evidence: exact command, exit code, duration, capped and redacted output;
a machine-readable Change Package (
change-package.json, schemaagent-review/v1) and a human-readablereview.md;optional: a GitHub Draft PR with a summary and a few inline comments placed on the exact diff lines they explain.
It runs on plain Git with no backend, no GitHub App and no extra VCS. Everything stays on your machine until you explicitly confirm a publish.
Works with OpenCode (native plugin) and Claude Code (and any other MCP host) via an MCP stdio server.
Example output
An excerpt of a generated review.md (from npm run demo):
## Logical Changes
### 1. refresh token rotation
- What changed: added in `src/token.ts`
- Why: refresh tokens were static; rotation limits replay windows
- Expected behavior: every refresh rotates the token
- Risk: medium
## Test Evidence
### Run 1
- Command: `npm test`
- Result: **passed** (exit code: 0)
- Duration: 412 ms
## Risks
- Branch was created from protected branch "main".Related MCP server: ITHZ MCP
Safety model
Agent Review is built to be safe to hand to an autonomous agent:
No destructive git. It never runs
reset --hard,clean, force-push, history rewrites or branch deletion. Rollback restores snapshotted files only, after taking a safety checkpoint, and never deletes files.Confirmation gates. Creating a branch from a protected branch (
main/master/develop), restoring a checkpoint, and every GitHub publish require an explicitconfirm/confirmed: truepassed after the user agrees. Without it the tools only return a preview.Evidence, not reasoning. Only observed facts, explicit decisions, command results and statically computed risks are recorded. No chain-of-thought.
Redaction. Tokens, keys and credentials are redacted before anything is written to the journal or the package; test output is size-capped.
No code leaves the machine for comment generation; GitHub publishing goes through your own authenticated
ghCLI only.Restricted test runner.
run_teststakes a single command with no shell metacharacters and rejects destructive programs.
Install
Requirements: Git, Node ≥ 22.6, and for GitHub publishing the
GitHub CLI (gh auth login).
git clone https://github.com/frxnxtic/agent-review.git
cd agent-review
npm installClaude Code (or any MCP host)
Register the MCP server in your project's
.mcp.json:{ "mcpServers": { "agent-review": { "command": "node", "args": ["/abs/path/to/agent-review/bin/agent-review-mcp.js"] } } }Add the journaling hook to
.claude/settings.json. It records edits and shell commands, but only while a review session is active:{ "hooks": { "PostToolUse": [ { "matcher": "Edit|Write|MultiEdit|NotebookEdit|Bash", "hooks": [ { "type": "command", "command": "node /abs/path/to/agent-review/bin/agent-review-claude-hook.js", "timeout": 10 } ] } ] } }Add the skill that teaches the agent the workflow:
mkdir -p .claude/skills ln -s /abs/path/to/agent-review/skills/agent-review .claude/skills/agent-reviewRestart Claude Code. The tools appear as
mcp__agent-review__agent_review_*.
The project root is resolved from AGENT_REVIEW_PROJECT_ROOT, then
CLAUDE_PROJECT_DIR, then the server's working directory.
OpenCode
Symlink the plugin and the skill into your project (file symlinks in
.opencode/plugins/ load like regular plugin files), then restart OpenCode:
ln -s /abs/path/to/agent-review/src/plugin.ts .opencode/plugins/agent-review.ts
ln -s /abs/path/to/agent-review/skills/agent-review .opencode/skills/agent-reviewThe plugin journals file edits and tool calls through OpenCode's own hooks.
Tools
Tool | What it does | Side effects |
| Start a session for a task; propose an | Creates a branch only with |
| Record HEAD, status, changed files and a restorable snapshot | Local only |
| Record one logical change: entity, files, kind, reason, expected behavior, risk, alternatives, limitations | Local only |
| Run one explicit test command and store the evidence | Runs the command |
| Write | Local only |
| Show the session state and counts | Read-only |
| List checkpoints, or restore one with | Restores snapshotted files |
| Check | Read-only |
| Build the PR body and inline-comment preview under | Local only |
| Commit (opt-in), push, open a Draft PR, post the grouped review | External, only with |
| After a new push, replace only Agent Review's own PR comments | External, only with |
Typical workflow
Start:
agent_review_start { task }. On a protected branch the tool proposes a branch name; after the user approves, call again withconfirm: true. A dirty working tree is recorded as a risk, never reset.Work. Take checkpoints before risky edits, and call
agent_review_record_intentonce per logical change.Test:
agent_review_run_tests { command: "npm test", reason }.Build:
agent_review_build_package, then read.agent-review/review.md.Optional PR:
agent_review_prepare_pr, show the preview to the user, thenagent_review_publish_pr { confirmed: true, allowPush: true }.
Tip: if your working tree contains unrelated changes, commit your feature
yourself and publish with allowCommit: false. The tool's own commit step
stages everything (git add -A).
GitHub Draft PR reviews
Enable publishing in .agent-review/config.json ("github": { "enabled": true }).
With it disabled, status and prepare-pr still work and publishing fails.
Draft PRs only by default. It never merges, never changes the base branch, never assigns reviewers or labels, and reuses an existing open PR instead of creating a duplicate.
Inline comments attach only to added lines of the current PR diff, at most one per logical change, capped by
maxInlineComments(default 8). They skip generated files, lockfiles and formatting-only changes. A change with no mappable line becomes a note in the PR body; the mapper never guesses.Updates are surgical. Each comment carries a hidden marker (
agent-review:session=…;change=…); after a new push, only Agent Review's own comments are replaced. Human and other-bot comments are never touched.The summary and comments are review context, not guarantees of correctness.
Manual end-to-end test guide: docs/manual-github-test.md.
CLI
The GitHub workflow is also available from the shell (run from your project directory):
node /abs/path/to/agent-review/bin/agent-review.js github status [--base main]
node /abs/path/to/agent-review/bin/agent-review.js github prepare-pr [--base main] [--max 8]
node /abs/path/to/agent-review/bin/agent-review.js github publish-pr [--allow-commit] [--allow-push] [--no-draft] --confirm
node /abs/path/to/agent-review/bin/agent-review.js github update-review [--pr <n>] --confirmNothing is published without --confirm.
Where data lives
.agent-review/
├── config.json # committable configuration
├── change-package.json # committable review artifact
├── review.md # committable review summary
├── github/ # committable PR preview artifacts
├── events.jsonl # gitignored journal (append-only)
├── session.json # gitignored current/last session
├── checkpoints/ # gitignored checkpoint metadata
└── snapshots/ # gitignored file snapshotsAdd the runtime files to your project's .gitignore:
/.agent-review/events.jsonl
/.agent-review/session.json
/.agent-review/checkpoints/
/.agent-review/snapshots/Configuration
.agent-review/config.json is created on first use:
Key | Default | Meaning |
|
| Branches that need confirmation before branching off |
|
| Prefix for proposed branch names |
|
| Cap on stored test output |
|
| Cap on per-file diff embedded in the package |
|
| Embed the diff into |
|
| Redact secrets before writing anything |
|
| Allow publishing |
|
| Inline comment cap per PR |
|
| How updates treat previous comments |
Limitations
Snapshots cover only files that were changed at checkpoint time.
Symbol extraction is regex-based, not AST-based.
The Change Package reflects the working tree, so uncommitted unrelated changes are counted; the dirty state at session start is recorded as a risk.
Automatic journaling depends on host hooks (OpenCode plugin hooks, Claude Code
PostToolUse); other MCP hosts get the tools without automatic journaling.
Development
npm run typecheck # tsc --noEmit
npm test # unit + mock-integration tests (node --test)
npm run test:integration # full local arc + mock-GitHub publish arc
npm run demo # runs a demo arc and prints review.mdDomain logic lives in src/*.ts. The host adapters are src/plugin.ts
(OpenCode), src/mcp.ts (MCP server) and src/claude-hook.ts (Claude Code
hook), all built on the shared handlers in src/handlers.ts.
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Deterministic AI code review, with an audit record. Governance inside the agent loop.
Versioned artifact review for people and AI agents, with contextual comments and human control.
Hand tasks, bugs and finished work to AI coding agents, and get back a write-up with evidence.
1Cross-agent artifact workspace with provenance across Claude Code, Codex, Cursor, LangGraph.
Related MCP Servers
- AlicenseAqualityAmaintenanceChange tracking for AI-era codebases. AI agents call it to log structured change events (entity + diff + reasoning) before the session ends, then query history with diff, blame, history, changeset, and search. Captures the intent that would otherwise evaporate.8249 PyPI24MIT
- FlicenseNot gradedqualityCmaintenanceLocal-first deterministic project memory for AI coding agents, with context packs, decisions, gates, risks, scoped claims and explicit checkpoints in project-owned files.-
- FlicenseNot gradedqualityAmaintenanceCaptures a coding agent's session into an Intent Document, enabling guided and verifiable pull-request reviews on GitHub.-
- AlicenseBqualityAmaintenanceCommit-time audit engine for AI coding agents. Scans git diffs with 24 audit rules, writes HMAC-signed tamper-evident audit history, and ships MCP tools for governance aggregation.10451MIT