Skip to main content
Glama

safe-fix-mcp

Python 저장소에서 데드 코드를 찾고, 실제로 안전하게 자동 제거할 수 있는 한 가지 유형(단일 이름 가져오기 줄의 사용되지 않는 import)에 대해 브랜치 + PR을 제안하는 실제 MCP 서버입니다. 그 외에 찾은 것들(사용되지 않는 함수, 클래스, 사용되지 않는 의존성)은 보고만 합니다. 병합은 항상 사람이 합니다. 이 도구는 스스로 아무것도 병합하지 않습니다.

왜 이게 필요한가

대부분의 "데드 코드" 도구는 보고에서 멈춥니다. 더 나아가는 도구들도 대개 안전장치 없이 삭제합니다. 이 도구는 둘 다 아닙니다: 제거 후 대상 저장소의 전체 테스트 스위트가 실제로 통과하는지 확인한 뒤에만, 실제적이고 최소한의 검토 가능한 PR을 초안으로 작성합니다. 휴리스틱이 아니라 실제 pytest 실행입니다. 스위트가 실패하면 아무것도 커밋하거나 푸시하지 않으며, 저장소는 처음과 똑같이 남습니다.

Related MCP server: Python Code Guardian MCP Server

도구

scan_dead_code(repo_path=".", min_confidence=60)

읽기 전용입니다. vulture(데드 코드)와 deptry(의존성 문제)를 실행하고 사람이 읽을 수 있는 결과 목록을 반환합니다. 아무것도 수정하지 않습니다.

propose_removal_pr(repo_path=".")

  • 작업 트리가 더티하면 거부합니다. 커밋되지 않은 작업 위에서 절대 편집하지 않습니다.

  • 단일 이름 가져오기 줄에서만 vulture 신뢰도 ≥90%인 사용되지 않는 import로 필터링합니다(from x import y, z는 건너뜁니다. 전체 줄을 제거하면 z도 조용히 제거되기 때문입니다).

  • 실제 브랜치를 만들고, 해당하는 import를 제거하고, 저장소의 실제 전체 테스트 스위트를 실행합니다.

  • 실제 통과 시에만: 커밋, 푸시, gh pr create로 PR 열기를 시도합니다.

  • gh가 설치/인증되지 않은 경우에도 브랜치는 실제로 커밋되고 푸시됩니다. PR 생성만 실패하며, 실제 오류가 반환되므로 수동으로 열 수 있습니다.

설치

pip install -e .

MCP 클라이언트 구성에 추가합니다(예: Claude Code):

claude mcp add safe-fix-mcp -- safe-fix-mcp

또는 로컬 테스트를 위해 직접 실행:

python -m safe_fix_mcp.server

요구 사항

  • Python ≥ 3.10

  • PATH에 git

  • propose_removal_pr가 실제로 PR을 열려면 PATH에 gh(GitHub CLI)가 설치·인증되어 있어야 합니다. 없어도 브랜치는 실제로 푸시되며, 도구가 수동으로 PR을 열라고 안내합니다.

개발

pip install -e ".[dev]"
pytest

알려진 제한 사항

vulture는 scan_dead_code/propose_removal_pr 자체를 "사용되지 않음"으로 표시합니다. 알려진 오탐 클래스이지 실제 버그가 아닙니다. 이들은 런타임에 @mcp.tool() 데코레이터로 디스패치되며 소스 어디에서도 직접 호출되지 않으므로 정적 호출 그래프 분석으로는 실제 호출자(MCP 프레임워크 자체)를 볼 수 없습니다.

실제 검증

scripts/verify_real_client.py는 패키징된 서버를 실제 하위 프로세스로 실행하고 실제 mcp.client.ClientSession으로 통신합니다. 실제 MCP 클라이언트가 사용하는 것과 동일한 경로입니다. 변경 후 스모크 테스트로 유용합니다:

python scripts/verify_real_client.py

Available Tools

2 tools
propose_removal_prA

Propose a real branch+PR removing only unused imports (single-name import lines, >= 90% vulture confidence) from a Python repository. Runs the repo's own full test suite as a safety gate before ever committing or pushing — a failure there reverts everything and nothing is committed or pushed. If gh isn't available or PR creation otherwise fails, the branch is still committed and pushed for real; only the PR itself needs opening manually. A human always merges — this never merges anything itself.

repo_path: path to a real git repository with a clean working tree (uncommitted changes are refused, not overwritten).

ParametersJSON Schema
NameRequiredDescriptionDefault
repo_pathNo.

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description fully carries the behavioral burden, and it does so well. It explains that the test suite is a safety gate, that failures revert all changes, that branch commits/pushes persist if only PR creation fails, and that human merge is always required.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is somewhat long but every sentence earns its place, covering prerequisites, side effects, failure modes, and parameter meaning. The critical safety guarantees are front-loaded, and there is no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with one optional parameter and an output schema, the description is remarkably complete. It covers prerequisites, refused inputs, failure behavior, push semantics, and merge policy, so an agent has enough to call it correctly without additional context.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, but the description compensates by explaining repo_path as a real git repository with a clean working tree and noting uncommitted changes are refused. This adds meaningful semantics beyond the bare schema field, though it does not mention optionality/default behavior beyond what the schema already shows.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's specific action: propose a real branch and PR that removes unused imports from a Python repository. It adds precise scoping (single-name import lines, >=90% vulture confidence) that makes its purpose concrete and distinct from a general cleanup tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage context by specifying criteria for eligible imports and requiring a clean git repository with a full test suite. However, it never explicitly addresses when to use this tool versus scan_dead_code or mentions exclusions, leaving the routing partially to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

scan_dead_codeA

Scan a Python repository for real dead code (vulture) and dependency issues (deptry). Read-only — never modifies anything. Returns a human-readable list of findings, or "No real candidates found."

repo_path: path to the repository to scan (must contain a pyproject.toml for the dependency checks to run; dead-code scanning works regardless). min_confidence: vulture's own confidence threshold (0-100). Lower values surface more candidates but more false positives.

ParametersJSON Schema
NameRequiredDescriptionDefault
repo_pathNo.
min_confidenceNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
resultYes

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations present, the description carries full burden and does so well: it states the tool is read-only, never modifies anything, and describes the exact output (human-readable findings or 'No real candidates found.'). It also discloses the pyproject.toml dependency for deptry and explains the confidence threshold's trade-off. No annotation contradiction.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact—three sentences for behavior plus two parameter explanations—and all content earns its place, with read-only status front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a two-parameter tool with an output schema and a single sibling, this description covers input semantics, prerequisites, behavioral safety, and result format. The only omitted piece is explicit sibling differentiation, which belongs to usage guidelines. Combined with schema and output schema, an agent has everything needed to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema has 0% description coverage, and the description fills in all of it: repo_path is the path to the repository and must contain pyproject.toml for dependency checks, and min_confidence maps to vulture's 0-100 threshold with a false-positive trade-off. This goes well beyond the parameter names and defaults.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb-resource pair: scan a Python repository, and names the two tools (vulture, deptry) and the two classes of findings (dead code, dependency issues). This clearly distinguishes it from the sibling propose_removal_pr, whose action is proposing a PR, not scanning.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No explicit guidance on when to use this tool versus propose_removal_pr, nor any when-not conditions. However, the read-only declaration and human-readable output imply this is an analysis step, and the requirement about pyproject.toml provides some context. This makes usage predictable but not explicitly ruled for alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 2 tool updatesv0.1.2
    • First observedpropose_removal_pr
    • First observedscan_dead_code

TDQS

A4.4/5.0

Scored across 2 tools

Disambiguation5/5

scan_dead_code is purely read-only analysis, while propose_removal_pr actually creates a branch and PR. Their purposes are complementary and unlikely to be confused.

Naming Consistency4/5

Both tool names use lower_snake verb-first conventions: scan_dead_code and propose_removal_pr. The pattern is predictable, though the second name is slightly less clean because 'removal_pr' bundles an action and an object into one noun phrase.

Tool Count3/5

Two tools is on the thin side and sits at the borderline of feeling complete. However, each tool has a distinct role in a focused analyze-then-propose workflow, so the small count is plausible for a narrow server.

Completeness3/5

The scan surfaces both dead code and dependency issues, but propose_removal_pr only handles unused imports. Dependency fixes and non-import dead-code removals are therefore dead ends, creating a notable gap in the advertised safe-fix domain.

Maintenance

ActivitySlowing
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers