Skip to main content
Glama

Critic-MCP — 무자비한 코드 비평가

오픈소스 Model Context Protocol (MCP) 서버로, 다른 AI 코딩 어시스턴트(Cursor, OpenCode, Cline 등)가 생성한 코드를 읽기 전용으로 검토합니다.

Critic-MCP는 '두 번째 눈'입니다: 코드를 절대 수정하지 않고, 무자비하게 비판만 합니다. 단일 도구(review_code)를 제공하며 파일 쓰기 기능이 전혀 없습니다.

무엇을 하나요?

review_code 도구는 보낸 코드를 원래 요구사항(의도)과 비교하여 LLM을 통해 다음 섹션으로 구성된 검토 보고서를 생성합니다:

  • 판정: APPROVED | MODIFICATION_REQUIRED | REJECTED

  • 누락된 요구사항 — 의도와 코드 간의 차이

  • 보안 발견사항 — SQL 인젝션, XSS, 권한 상승, 하드코딩된 비밀

  • 엣지 케이스 발견사항 — null/빈 입력, 경계값, 오프바이원, 경쟁 조건

  • 성능 발견사항 — N+1 쿼리, 메모리 누수, 중복 계산

  • 기타 발견사항 + 필수 수정 항목 (우선순위 순)

Related MCP server: codereview-mcp

설치 — 두 단계

요구사항: Node.js >= 20

1단계: 인증 (한 번)

대화형 설정을 실행합니다. aws configure 또는 gh auth login과 동일하게 작동합니다:

npx -y critic-mcp auth

사용할 제공자(gemini / openai / deepseek)를 묻고, API 키를 입력받아 홈 디렉토리의 ~/.critic-mcp.json에 저장합니다(Unix에서는 0600 권한).

2단계: IDE에 추가

IDE의 MCP 설정에 다음만 추가하세요:

{ "command": "npx", "args": ["-y", "critic-mcp"] }

클라이언트별 세부 사항은 AI 어시스턴트 통합 섹션을 참조하세요. 이게 전부입니다 — 이제 키는 모든 IDE 구성 외부의 한 곳에 저장됩니다.

키는 IDE 구성에 절대 기록되지 않습니다. 서버가 시작되면 먼저 process.env를 확인한 다음 ~/.critic-mcp.json을 확인합니다. 어디에서도 키를 찾을 수 없으면 npx critic-mcp auth를 실행하도록 안내합니다.

로컬 개발 (소스에서 설치)

git clone https://github.com/layermedya/Critic-MCP.git
cd Critic-MCP
npm ci
npm run build
node dist/index.js auth   # authenticate against your own build

명령어

npm run build       # TypeScript compilation
npm run typecheck   # Type checking
npm test            # Vitest unit tests
npm run test:watch  # Tests in watch mode
npm start           # Start the server on stdio
npm run inspect     # Manual testing in the browser via MCP Inspector

환경 변수 (선택 사항)

모든 변수는 선택 사항입니다. API 키의 일반적인 경로는 npx critic-mcp auth입니다. 환경 변수는 항상 구성 파일보다 우선합니다(CI/서버 설정의 경우).

Variable

Description

CRITIC_PROVIDER

gemini, openai 또는 deepseek (~/.critic-mcp.json의 선택으로 폴백, 그 다음 gemini)

GEMINI_API_KEY

Gemini 키 (설정 시 파일보다 우선)

OPENAI_API_KEY

OpenAI/DeepSeek 키 (설정 시 파일보다 우선)

GEMINI_MODEL

Gemini 모델 이름 (기본값: gemini-3.6-flash)

OPENAI_MODEL

모델 이름 (기본값: gpt-4o-mini, deepseek의 경우 deepseek-chat)

OPENAI_BASE_URL

DeepSeek 등의 기본 URL (deepseek 기본값: https://api.deepseek.com)

CRITIC_TIMEOUT_MS

LLM 요청 시간 초과 (기본값: 120000)

CHUNK_SIZE

청크 제한 (기본값: 30000 문자)

CRITIC_CONCURRENCY

청크 검토 중 병렬 요청 수 (기본값: 3)

CRITIC_CONFIG_PATH

구성 파일 위치 재정의 (기본값: ~/.critic-mcp.json)

AI 어시스턴트 통합

아래 구성에는 키가 포함되지 않습니다. auth 명령(위 1단계)을 통해 한 번 인증합니다. npx는 패키지가 npm에 게시되어 있어야 합니다. 로컬 클론의 경우 대신 "command": "node", "args": ["ABSOLUTE_PATH/dist/index.js"]를 사용할 수 있습니다.

Cursor

프로젝트 수준의 .cursor/mcp.json(또는 전역 ~/.cursor/mcp.json)에 다음을 추가합니다:

{
  "mcpServers": {
    "critic": {
      "command": "npx",
      "args": ["-y", "critic-mcp"]
    }
  }
}

또는: 설정 → MCP → 새 MCP 서버 추가 후 JSON을 붙여넣습니다.

OpenCode

프로젝트 수준의 .opencode/opencode.json 또는 전역 ~/.config/opencode/opencode.json에 다음을 추가합니다:

{
  "mcp": {
    "critic": {
      "type": "local",
      "command": ["npx", "-y", "critic-mcp"],
      "enabled": true
    }
  }
}

OpenCode는 mcp 키(mcpServers 아님)와 environment 필드(env 아님)를 사용합니다. command는 배열이어야 합니다. 더 이상 environment 블록에 키를 작성할 필요가 없습니다.

Cline (VS Code 확장)

Cline 패널 → MCP 서버 탭 → 전역 MCP 편집 또는 프로젝트 MCP 편집을 열고 JSON을 편집합니다:

{
  "mcpServers": {
    "critic": {
      "command": "npx",
      "args": ["-y", "critic-mcp"],
      "disabled": false,
      "autoApprove": ["review_code"]
    }
  }
}

autoApprove를 사용하면 Cline이 확인 없이 review_code를 실행할 수 있습니다. 도구가 파일을 절대 쓰지 않으므로 안전합니다.

Continue.dev

MCP 서버를 ~/.continue/config.json에 추가합니다(Continue 버전에 관계없이 stdio 전송이 지원됩니다):

{
  "experimental": {
    "modelContextProtocolServers": [
      {
        "transport": {
          "type": "stdio",
          "command": "npx",
          "args": ["-y", "critic-mcp"]
        }
      }
    ]
  }
}

수동 테스트 시나리오

examples/bad_code.js는 의도적으로 SQL 인젝션, XSS, N+1 쿼리를 포함하는 Express 예제입니다. examples/intent.txt에는 원래 요구사항이 있습니다. 다음과 같이 클라이언트에서 호출합니다:

"review_code 도구를 사용하여 examples/bad_code.js의 코드를 검토하세요. 요구사항: examples/intent.txt"

비평가가 최소한 다음을 잡아낼 것으로 예상합니다:

  • CRITICAL: db.query("SELECT * FROM users WHERE email = '" ...) — SQL 인젝션

  • CRITICAL: res.send(comment.body) — 저장된 XSS

  • HIGH: 사용자당 별도 쿼리 — N+1 문제

아키텍처

src/index.ts   -> MCP server, zod validation, error handling + `auth` argv routing
src/cli.ts     -> Interactive authentication flow (`critic-mcp auth`)
src/config.ts  -> Global config (~/.critic-mcp.json) + credential resolution (env → file)
src/prompt.ts  -> Ruthless Critic system prompt + chunked-review prompts
src/llm.ts     -> Provider layer + timeout protection + map-reduce orchestration
src/chunker.ts -> Line-ending based chunking (for code above the limit)

청크 검토 (맵-리듀스)

code_snippet이 CHUNK_SIZE(기본값 30,000 문자)를 초과하면 시스템이 자동으로 맵-리듀스 흐름으로 전환합니다:

  1. 맵: 코드가 줄 경계에서 분할됩니다. 각 청크는 동시에 LLM으로 전송됩니다(기본 3개의 병렬 요청, CRITIC_CONCURRENCY로 구성 가능). 단일 청크 실패가 전체 검토를 중단시키지 않습니다.

  2. 리듀스: 반환된 모든 부분 분석은 "Synthesizer" 프롬프트에 의해 병합되어 하나의 최종 보고서로 만들어집니다. 이 프롬프트는 발견사항을 약화시키지 않으며, 단일 부분이 CRITICAL을 보고할 때 APPROVED를 반환하지 않습니다.

서버는 문자열 보고서만 반환합니다. 파일 쓰기 기능이 없으며 외부로 네트워크 클라이언트를 노출하지 않습니다.

라이선스

MIT

Available Tools

1 tool
review_codeA

Read-only code critic. Analyzes the provided code snippet against its stated intent and returns a detailed, ruthless review report: missing requirements, security vulnerabilities (SQLi, XSS, privilege escalation), edge cases and performance issues (N+1, memory leaks). Never writes files — returns the report as text only.

ParametersJSON Schema
NameRequiredDescriptionDefault
intentYes
code_snippetYes

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Since no annotations are provided, the description must fully disclose behavioral traits. It does so clearly: never writes files, returns only a text report, and performs a ruthless review. It also lists specific vulnerability categories checked (SQLi, XSS, privilege escalation) and performance issues (N+1, memory leaks).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences long, front-loaded with the core purpose ('Read-only code critic'). Every phrase adds value — no filler. The first sentence establishes scope, the second disclaims side effects and clarifies output format.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool has only 2 parameters, no output schema, and no annotations, the description fairly covers the inputs, behavior, and output. An agent should be able to invoke it correctly. A minor gap: the description doesn't mention the output format structure (e.g., bullet points vs. paragraphs), but this is acceptable for a complex, free-text report.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate. The description explains the purpose of the two parameters implicitly: 'code snippet' and 'its stated intent' map directly to code_snippet and intent. It does not detail their types or constraints, but the schema already provides min/max lengths and types.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a clear verb-resource pair ('Analyzes the provided code snippet') and immediately states it is read-only. It lists specific review categories (missing requirements, security vulnerabilities, edge cases, performance issues), leaving no ambiguity about what the tool does.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states the tool is 'Read-only' and 'Never writes files', which guides when to use it (analysis without side effects). However, it does not mention when not to use it or provide alternatives, though sibling tools are absent, so there is no need for exclusion.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev1.0.0
    • First observedreview_code

TDQS

A4.3/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no possibility of confusion between tools. The single tool's purpose is clearly defined in great detail.

Naming Consistency5/5

Naming consistency is not applicable as a concept with a single tool. It cannot be penalized and defaults to the highest score.

Tool Count2/5

A single tool severely limits the server's functionality. While the tool is comprehensive, it would benefit from being broken down into more focused tools (e.g., review_security, review_performance).

Completeness2/5

The server covers only the 'review' aspect. For a code review tool, this is acceptable, but it lacks any supporting tools for follow-up actions like re-review, fetching additional context, or managing review sessions.

Maintenance

ActivitySlowing
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that provides local code quality analysis for AI coding assistants, supporting file analysis, git diff review, and full project scanning with quality scoring.
    4
    3
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    An MCP server that lets AI agents review code using language models, supporting git diffs, files, and snippets with severity levels. Works with Ollama (local) and hosted providers like OpenAI, Anthropic, and OpenRouter.
    3
    MIT