Moltline Code Review

Risk-scan a diff, flag AI-generated-code tells, find secrets. 5 of 7 tools need no account.

Should I use this

Quality & Safety

B
Description quality
94%
Schema completeness
89%
Naming quality
89%
Poisoning risk
60%
Permission match
100%
Protocol compliance
100%

Findings (5)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool 'review_diff' description contains placeholder textin review_diff
  • MEDIUMTool 'ai_code_smell_scan' description contains placeholder textin ai_code_smell_scan
  • INFOTool description contains placeholder or incomplete textin review_diff
  • INFOTool description contains placeholder or incomplete textin ai_code_smell_scan

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~2,249Tokens (tool definitions)
~803 BTypical response size
Moderate attention impact (1.76% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "codereview": {
      "url": "https://mcp.moltlinestudio.com/codereview"
    }
  }
}

Remote endpoints

https://mcp.moltlinestudio.com/codereviewstreamable-http

What it can do

Tool inventory

Tools (7)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢review_diff(diff)

Risk-scan a unified diff the way a senior reviewer triages a PR. FREE. Flags added lines matching known risk patterns — injection sinks, disabled TLS, bare excepts, debug prints, TODOs, N+1 hints, leaked secrets — with the new-file line number and a severity (1 low - 4 high). Typical input {"diff": "<git diff output>"} returns {"added_lines": N, "risk_score": 0-100, "verdict": "...", "secrets": [...], "findings": [{"line": N, "severity": 1-4, "issue": "...", "code": "..."}], "note": "..."}. Use on a unified diff, when only the change matters. Not for whole-file analysis (complexity_report, ai_code_smell_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input Schema

{
  "type": "object",
  "properties": {
    "diff": {
      "type": "string",
      "description": "A unified diff exactly as produced by `git diff` — text with\n@@ hunk headers and +/- line prefixes. Only added (+) lines are\nscanned."
    }
  },
  "required": [
    "diff"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢ai_code_smell_scan(code)

Flag the tells of unreviewed AI-generated code in a source file. FREE. Detects comments that restate the next line, leaked assistant preambles, placeholder TODOs, shipped 'Example usage' blocks, over-broad try/except that swallows errors, and auto-named identifiers. Typical input {"code": "<file contents>"} returns {"reviewed_confidence": 0-100, "hits": [{"smell": "...", "evidence": "<quoted snippet>"}], "reading": "...", "note": "..."}. Use on a full source file suspected of unreviewed machine authorship. Not on a diff (review_diff), and the result is a signal to check, not proof of authorship. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input Schema

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Full source text to scan, any language; paste the file\ncontents as a single string."
    }
  },
  "required": [
    "code"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢complexity_report(code, language)

Report structural complexity of a source file, function by function. FREE. Measures per-function length, max nesting depth, and a cyclomatic-style branch count (if/for/while/case/&&/||/except), flagging functions too long or too deeply nested to review confidently. Typical input {"code": "<file contents>"} returns {"functions": N, "detail": [{"name": ..., "start": N, "lines": N, "branches": N, "max_depth": N}], "flags": ["..."], "note": "..."}. Use when structure rather than correctness is the question. Not for vulnerabilities (security_deep_dive). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input Schema

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Full source text to analyze, pasted as a single string."
    },
    "language": {
      "default": "auto",
      "type": "string",
      "description": "Optional language hint, e.g. \"python\" or \"javascript\";\n\"auto\" (default) detects from syntax."
    }
  },
  "required": [
    "code"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢secret_scan(text)

Scan text for accidentally-committed machine credentials and private-key material. FREE. Reports each match's location and category so it can be rotated before it leaks. Detection is pattern-based over the common leaked-credential formats; it never echoes the matched value back. Typical input {"text": "<file, diff, or config contents>"} returns {"leaked": bool, "count": N, "findings": [{"line": N, "type": "<category>"}], "note": "..."}. Pattern matching only - a clean result is not proof, and every hit needs human confirmation before anyone acts on it. Not a general security review (security_deep_dive). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input Schema

{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "description": "The file, diff, or config contents to scan, pasted as a\nsingle string."
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢review_checklist(language)

Produce a focused pull-request review checklist for a language or stack. FREE. Covers the things that actually break in production, with extra items per language. Typical input {"language": "python"} returns {"language": "python", "checklist": ["...", ...], "note": "..."}. Use before a review, to decide what to look for. Not for reviewing actual code - pass code to review_diff or security_deep_dive. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input Schema

{
  "type": "object",
  "properties": {
    "language": {
      "default": "general",
      "type": "string",
      "description": "Language or stack to tailor for: \"python\", \"javascript\",\n\"typescript\", \"go\", \"sql\", or \"general\" (default). Unknown values\nfall back to the general checklist."
    }
  },
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢security_deep_dive(code)

Run an OWASP-oriented security pass over a source file. PREMIUM (license). Checks injection sinks, auth/session handling, crypto misuse, SSRF/deserialization, and unsafe file/path handling — each finding cites the line, the OWASP risk class, and a concrete fix direction. Typical input {"code": "<file contents>"} returns {"issues": N, "findings": [{"line": N, "class": "A03 Injection", "fix": "...", "code": "..."}], "owasp_note": "..."}. Use on one source file when vulnerabilities are the question. Not for style or structure (complexity_report), and never a substitute for a security professional on high-risk code. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input Schema

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Full source text to audit, pasted as a single string; any\ncommon language."
    }
  },
  "required": [
    "code"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢get_reviewer_persona

Load the Senior Reviewer persona for consistent, high-signal reviews. PREMIUM (license). The persona is a reviewing voice that is skeptical, specific, and kind — demands evidence over vibes and blocks only on real risk. Takes no arguments. Returns {"persona": ..., "identity": ..., "rules": ["...", ...], "opening_move": "..."} ready to adopt as a system prompt. Use to keep repeated reviews consistent in voice and rigor. Not for running a review - the scan tools do that. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded7 tools
verifiedversion not recorded7 tools