Skip to main content
Glama

Critic-MCP — 容赦ないコード批評家

他のAIコーディングアシスタント(Cursor、OpenCode、Clineなど)が生成したコードを、読み取り専用でレビューするオープンソースのModel Context Protocol(MCP)サーバーです。

Critic-MCPは「第二の目」です。コードを修正することは決してなく、容赦なく批評するだけです。単一のツール(review_code)を公開し、ファイル書き込み機能は一切ありません。

何をするのか?

review_codeツールは、送信されたコードを元の要件(意図)と比較し、LLMを通じて以下のセクションからなるレビューレポートを生成します。

  • 判定: APPROVED | MODIFICATION_REQUIRED | REJECTED

  • 欠落している要件 — 意図とコードのギャップ

  • セキュリティ上の問題 — SQLインジェクション、XSS、権限昇格、ハードコードされたシークレット

  • エッジケースの問題 — null/空の入力、境界値、オフバイワン、競合状態

  • パフォーマンスの問題 — N+1クエリ、メモリリーク、冗長な計算

  • その他の問題 + 修正必須項目(優先順位順)

Related MCP server: codereview-mcp

インストール — 2ステップ

要件: Node.js >= 20

ステップ1: 認証(1回のみ)

インタラクティブなセットアップを実行します。これはaws configureやgh auth loginと同様に動作します。

npx -y critic-mcp auth

使用するプロバイダー(gemini / openai / deepseek)を尋ね、APIキーを入力するよう促し、両方をホームディレクトリの~/.critic-mcp.jsonに保存します(Unixではパーミッション0600)。

ステップ2: IDEに追加する

IDEのMCP設定に以下だけを追加します。

{ "command": "npx", "args": ["-y", "critic-mcp"] }

クライアント固有の詳細については、AIアシスタント統合セクションを参照してください。これで完了です。キーは1か所に保存され、すべてのIDE設定の外部に置かれます。

キーがIDE設定に書き込まれることはありません。サーバー起動時には最初にprocess.envを確認し、次に~/.critic-mcp.jsonを確認します。どちらにもキーが見つからない場合は、npx critic-mcp authを実行するよう指示されます。

ローカル開発(ソースからインストール)

git clone https://github.com/layermedya/Critic-MCP.git
cd Critic-MCP
npm ci
npm run build
node dist/index.js auth   # authenticate against your own build

コマンド

npm run build       # TypeScript compilation
npm run typecheck   # Type checking
npm test            # Vitest unit tests
npm run test:watch  # Tests in watch mode
npm start           # Start the server on stdio
npm run inspect     # Manual testing in the browser via MCP Inspector

環境変数(オプション)

これらはすべてオプションです。APIキーの通常のパスはnpx critic-mcp authです。環境変数は常に設定ファイルよりも優先されます(CI/サーバー設定用)。

変数

説明

CRITIC_PROVIDER

gemini、openai、deepseekのいずれか(~/.critic-mcp.jsonの選択肢にフォールバックし、さらにgeminiにフォールバック)

GEMINI_API_KEY

Geminiキー(設定されている場合、ファイルを上書き)

OPENAI_API_KEY

OpenAI/DeepSeekキー(設定されている場合、ファイルを上書き)

GEMINI_MODEL

Geminiモデル名(デフォルト: gemini-3.6-flash)

OPENAI_MODEL

モデル名(デフォルト: gpt-4o-mini、deepseekの場合はdeepseek-chat)

OPENAI_BASE_URL

DeepSeekなどのベースURL(deepseekのデフォルトはhttps://api.deepseek.com)

CRITIC_TIMEOUT_MS

LLMリクエストのタイムアウト(デフォルト: 120000)

CHUNK_SIZE

チャンク分割の制限(デフォルト: 30000文字)

CRITIC_CONCURRENCY

チャンクレビュー中の並列リクエスト数(デフォルト: 3)

CRITIC_CONFIG_PATH

設定ファイルの場所を上書き(デフォルト: ~/.critic-mcp.json)

AIアシスタント統合

以下の設定はいずれもキーを保持しません。authコマンド(上記ステップ1)で一度認証するだけです。npxを使用するにはパッケージがnpmに公開されている必要があります。ローカルクローンの場合は、代わりに"command": "node", "args": ["ABSOLUTE_PATH/dist/index.js"]を使用できます。

Cursor

プロジェクトレベルの.cursor/mcp.json(またはグローバルの~/.cursor/mcp.json)に以下を追加します。

{
  "mcpServers": {
    "critic": {
      "command": "npx",
      "args": ["-y", "critic-mcp"]
    }
  }
}

または、設定 → MCP → Add new MCP server に進み、JSONを貼り付けます。

OpenCode

プロジェクトレベルの.opencode/opencode.jsonまたはグローバルの~/.config/opencode/opencode.jsonに以下を追加します。

{
  "mcp": {
    "critic": {
      "type": "local",
      "command": ["npx", "-y", "critic-mcp"],
      "enabled": true
    }
  }
}

OpenCodeはmcpServersではなくmcpキーを使用し、envではなくenvironmentフィールドを使用します。commandは配列である必要があります。environmentブロックにキーを書き込む必要はなくなりました。

Cline(VS Code拡張機能)

Clineパネルを開き → MCP Serversタブ → Edit Global MCPまたはEdit Project MCPを選択し、JSONを編集します。

{
  "mcpServers": {
    "critic": {
      "command": "npx",
      "args": ["-y", "critic-mcp"],
      "disabled": false,
      "autoApprove": ["review_code"]
    }
  }
}

autoApproveを使用すると、Clineは確認なしでreview_codeを実行できます。このツールはファイルを書き込むことがないため安全です。

Continue.dev

MCPサーバーを~/.continue/config.jsonに追加します(Continueのバージョンに関係なくstdioトランスポートがサポートされています)。

{
  "experimental": {
    "modelContextProtocolServers": [
      {
        "transport": {
          "type": "stdio",
          "command": "npx",
          "args": ["-y", "critic-mcp"]
        }
      }
    ]
  }
}

手動テストシナリオ

examples/bad_code.jsは、SQLインジェクション、XSS、N+1クエリを意図的に含むExpressの例です。examples/intent.txtには元の要件が含まれています。任意のクライアントから次のように呼び出します。

"Review the code in examples/bad_code.js with the review_code tool. Requirement: examples/intent.txt"

批評家が少なくとも以下を検出することを期待します。

  • CRITICAL: db.query("SELECT * FROM users WHERE email = '" ...) — SQLインジェクション

  • CRITICAL: res.send(comment.body) — 保存型XSS

  • HIGH: ユーザーごとに個別のクエリ — N+1問題

アーキテクチャ

src/index.ts   -> MCP server, zod validation, error handling + `auth` argv routing
src/cli.ts     -> Interactive authentication flow (`critic-mcp auth`)
src/config.ts  -> Global config (~/.critic-mcp.json) + credential resolution (env → file)
src/prompt.ts  -> Ruthless Critic system prompt + chunked-review prompts
src/llm.ts     -> Provider layer + timeout protection + map-reduce orchestration
src/chunker.ts -> Line-ending based chunking (for code above the limit)

チャンクレビュー(マップリデュース)

code_snippetがCHUNK_SIZE(デフォルト30,000文字)を超えると、システムは自動的にマップリデュースフローに切り替わります。

  1. マップ: コードを行境界で分割し、各チャンクをLLMに同時に送信します(デフォルト3並列リクエスト、CRITIC_CONCURRENCYで設定可能)。単一のチャンクの失敗がレビュー全体を停止することはありません。

  2. リデュース: 返されたすべての部分分析は、「シンセサイザー」プロンプトによって統合されます。このプロンプトは、発見事項を弱めることはなく、単一の部分がCRITICALを報告した場合にAPPROVEDを返すことは決してありません。最終的に1つの最終レポートが生成されます。

サーバーは文字列レポートのみを返します。ファイル書き込み機能はなく、外部へのネットワーククライアントを公開することもありません。

ライセンス

MIT

Available Tools

1 tool
review_codeA

Read-only code critic. Analyzes the provided code snippet against its stated intent and returns a detailed, ruthless review report: missing requirements, security vulnerabilities (SQLi, XSS, privilege escalation), edge cases and performance issues (N+1, memory leaks). Never writes files — returns the report as text only.

ParametersJSON Schema
NameRequiredDescriptionDefault
intentYes
code_snippetYes

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Since no annotations are provided, the description must fully disclose behavioral traits. It does so clearly: never writes files, returns only a text report, and performs a ruthless review. It also lists specific vulnerability categories checked (SQLi, XSS, privilege escalation) and performance issues (N+1, memory leaks).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences long, front-loaded with the core purpose ('Read-only code critic'). Every phrase adds value — no filler. The first sentence establishes scope, the second disclaims side effects and clarifies output format.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool has only 2 parameters, no output schema, and no annotations, the description fairly covers the inputs, behavior, and output. An agent should be able to invoke it correctly. A minor gap: the description doesn't mention the output format structure (e.g., bullet points vs. paragraphs), but this is acceptable for a complex, free-text report.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate. The description explains the purpose of the two parameters implicitly: 'code snippet' and 'its stated intent' map directly to code_snippet and intent. It does not detail their types or constraints, but the schema already provides min/max lengths and types.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a clear verb-resource pair ('Analyzes the provided code snippet') and immediately states it is read-only. It lists specific review categories (missing requirements, security vulnerabilities, edge cases, performance issues), leaving no ambiguity about what the tool does.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states the tool is 'Read-only' and 'Never writes files', which guides when to use it (analysis without side effects). However, it does not mention when not to use it or provide alternatives, though sibling tools are absent, so there is no need for exclusion.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev1.0.0
    • First observedreview_code

TDQS

A4.3/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no possibility of confusion between tools. The single tool's purpose is clearly defined in great detail.

Naming Consistency5/5

Naming consistency is not applicable as a concept with a single tool. It cannot be penalized and defaults to the highest score.

Tool Count2/5

A single tool severely limits the server's functionality. While the tool is comprehensive, it would benefit from being broken down into more focused tools (e.g., review_security, review_performance).

Completeness2/5

The server covers only the 'review' aspect. For a code review tool, this is acceptable, but it lacks any supporting tools for follow-up actions like re-review, fetching additional context, or managing review sessions.

Maintenance

ActivitySlowing
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that provides local code quality analysis for AI coding assistants, supporting file analysis, git diff review, and full project scanning with quality scoring.
    4
    3
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    An MCP server that lets AI agents review code using language models, supporting git diffs, files, and snippets with severity levels. Works with Ollama (local) and hosted providers like OpenAI, Anthropic, and OpenRouter.
    3
    MIT