Moltline Code Review
Risk-scan a diff, flag AI-generated-code tells, find secrets. 5 of 7 tools need no account.
Should I use this
Quality & Safety
Findings (5)
- HIGH
- MEDIUMin review_diff
- MEDIUMin ai_code_smell_scan
- INFOin review_diff
- INFOin ai_code_smell_scan
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"codereview": {
"url": "https://mcp.moltlinestudio.com/codereview"
}
}
}Remote endpoints
https://mcp.moltlinestudio.com/codereviewstreamable-httpWhat it can do
Tool inventory
Tools (7)
🟢review_diff(diff)
Risk-scan a unified diff the way a senior reviewer triages a PR. FREE. Flags added lines matching known risk patterns — injection sinks, disabled TLS, bare excepts, debug prints, TODOs, N+1 hints, leaked secrets — with the new-file line number and a severity (1 low - 4 high). Typical input {"diff": "<git diff output>"} returns {"added_lines": N, "risk_score": 0-100, "verdict": "...", "secrets": [...], "findings": [{"line": N, "severity": 1-4, "issue": "...", "code": "..."}], "note": "..."}. Use on a unified diff, when only the change matters. Not for whole-file analysis (complexity_report, ai_code_smell_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Input Schema
{
"type": "object",
"properties": {
"diff": {
"type": "string",
"description": "A unified diff exactly as produced by `git diff` — text with\n@@ hunk headers and +/- line prefixes. Only added (+) lines are\nscanned."
}
},
"required": [
"diff"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢ai_code_smell_scan(code)
Flag the tells of unreviewed AI-generated code in a source file. FREE. Detects comments that restate the next line, leaked assistant preambles, placeholder TODOs, shipped 'Example usage' blocks, over-broad try/except that swallows errors, and auto-named identifiers. Typical input {"code": "<file contents>"} returns {"reviewed_confidence": 0-100, "hits": [{"smell": "...", "evidence": "<quoted snippet>"}], "reading": "...", "note": "..."}. Use on a full source file suspected of unreviewed machine authorship. Not on a diff (review_diff), and the result is a signal to check, not proof of authorship. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Input Schema
{
"type": "object",
"properties": {
"code": {
"type": "string",
"description": "Full source text to scan, any language; paste the file\ncontents as a single string."
}
},
"required": [
"code"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢complexity_report(code, language)
Report structural complexity of a source file, function by function. FREE. Measures per-function length, max nesting depth, and a cyclomatic-style branch count (if/for/while/case/&&/||/except), flagging functions too long or too deeply nested to review confidently. Typical input {"code": "<file contents>"} returns {"functions": N, "detail": [{"name": ..., "start": N, "lines": N, "branches": N, "max_depth": N}], "flags": ["..."], "note": "..."}. Use when structure rather than correctness is the question. Not for vulnerabilities (security_deep_dive). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Input Schema
{
"type": "object",
"properties": {
"code": {
"type": "string",
"description": "Full source text to analyze, pasted as a single string."
},
"language": {
"default": "auto",
"type": "string",
"description": "Optional language hint, e.g. \"python\" or \"javascript\";\n\"auto\" (default) detects from syntax."
}
},
"required": [
"code"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢secret_scan(text)
Scan text for accidentally-committed machine credentials and private-key material. FREE. Reports each match's location and category so it can be rotated before it leaks. Detection is pattern-based over the common leaked-credential formats; it never echoes the matched value back. Typical input {"text": "<file, diff, or config contents>"} returns {"leaked": bool, "count": N, "findings": [{"line": N, "type": "<category>"}], "note": "..."}. Pattern matching only - a clean result is not proof, and every hit needs human confirmation before anyone acts on it. Not a general security review (security_deep_dive). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Input Schema
{
"type": "object",
"properties": {
"text": {
"type": "string",
"description": "The file, diff, or config contents to scan, pasted as a\nsingle string."
}
},
"required": [
"text"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢review_checklist(language)
Produce a focused pull-request review checklist for a language or stack. FREE. Covers the things that actually break in production, with extra items per language. Typical input {"language": "python"} returns {"language": "python", "checklist": ["...", ...], "note": "..."}. Use before a review, to decide what to look for. Not for reviewing actual code - pass code to review_diff or security_deep_dive. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Input Schema
{
"type": "object",
"properties": {
"language": {
"default": "general",
"type": "string",
"description": "Language or stack to tailor for: \"python\", \"javascript\",\n\"typescript\", \"go\", \"sql\", or \"general\" (default). Unknown values\nfall back to the general checklist."
}
},
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢security_deep_dive(code)
Run an OWASP-oriented security pass over a source file. PREMIUM (license). Checks injection sinks, auth/session handling, crypto misuse, SSRF/deserialization, and unsafe file/path handling — each finding cites the line, the OWASP risk class, and a concrete fix direction. Typical input {"code": "<file contents>"} returns {"issues": N, "findings": [{"line": N, "class": "A03 Injection", "fix": "...", "code": "..."}], "owasp_note": "..."}. Use on one source file when vulnerabilities are the question. Not for style or structure (complexity_report), and never a substitute for a security professional on high-risk code. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Input Schema
{
"type": "object",
"properties": {
"code": {
"type": "string",
"description": "Full source text to audit, pasted as a single string; any\ncommon language."
}
},
"required": [
"code"
],
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}🟢get_reviewer_persona
Load the Senior Reviewer persona for consistent, high-signal reviews. PREMIUM (license). The persona is a reviewing voice that is skeptical, specific, and kind — demands evidence over vibes and blocks only on real risk. Takes no arguments. Returns {"persona": ..., "identity": ..., "rules": ["...", ...], "opening_move": "..."} ready to adopt as a system prompt. Use to keep repeated reviews consistent in voice and rigor. Not for running a review - the scan tools do that. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Output Schema
{
"type": "object",
"additionalProperties": true
}Community
Evidence