Review Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Review Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
AI-powered code review using Zhipu GLM. The server gathers git diffs and optional source context, then asks the model for a focused review.
Install dependencies:
git clone https://github.com/Enferlain/antigravity-review-mcp.git
cd antigravity-review-mcp
cp .env.example .env
# Optional: edit .env and add your API key
uv syncThen add it to your MCP client.
For local development, use uv run from your clone:
{
"mcpServers": {
"review-mcp": {
"command": "uv",
"args": [
"--directory",
"/absolute/path/to/antigravity-review-mcp",
"run",
"review-mcp"
]
}
}
}For day-to-day use from Git, uvx avoids hardcoding a local install path:
{
"mcpServers": {
"review-mcp": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/Enferlain/antigravity-review-mcp",
"review-mcp"
]
}
}
}The MCP caller should pass the repository being reviewed as working_directory on each review_with_context call. If your MCP client cannot pass a per-call workspace, you can still start the server with a fixed fallback:
"args": [
"--from",
"git+https://github.com/Enferlain/antigravity-review-mcp",
"review-mcp",
"--workspace-dir",
"/absolute/path/to/the-repo-you-want-reviewed"
]Environment variables (in .env):
AI_API_KEY (required): Your API keyZHIPU_API_KEY (optional): Backward-compatible fallback key nameZHIPU_BASE_URL (optional): Override API endpointAI_MODEL / ZHIPU_MODEL (optional): Override the review model (default: GLM-4.7)MAX_REVIEW_ITERATIONS (optional): Max tool-calling iterations (default: 20, capped at 50)REVIEW_MCP_INCLUDE_TRACE (optional): Append diagnostic trace details to review responses (true/false)The MCP exposes 1 tool: review_with_context
Parameters:
diff_target: 'staged' (default), 'unstaged', or a git ref like 'HEAD~1'context_files: Additional files or OpenSpec change folders to include as contextfocus_files: Specific files to focus the review ontask_description: Description of what you're trying to accomplishworking_directory: Git repository root to review (required unless the server was started with --workspace-dir)include_trace: Include a compact diagnostic trace in the returned review (optional, defaults to REVIEW_MCP_INCLUDE_TRACE)When called, it automatically:
context_filesrender_diffs() and file:/// links inside those context filesfocus_files or context-file render_diffs() links identify filesOpenSpec change folders are included only when the MCP caller passes the folder path in context_files, for example:
{
"context_files": [
"/home/imi/Projects/sd-scripts/openspec/changes/resource-intelligence-system"
]
}If MCP calls feel opaque, set include_trace to true for a single call or set REVIEW_MCP_INCLUDE_TRACE=true in the environment. The returned review will include a compact trace with the workspace, diff target, context-file count, payload sizes, model iterations, and tool calls.
This server now starts cleanly under MCP hosts because it avoids doing heavy work at import time. A few setup notes still matter:
working_directory per tool call so one MCP config can review any repo.--workspace-dir in the config as a fixed fallback.AI_API_KEY as a system/user environment variable instead of storing it in MCP config.working_directory argument still overrides the configured workspace when your agent provides it.Example Windows fallback path:
"args": [
"--directory",
"D:/Projects/antigravity-review-mcp",
"run",
"review-mcp",
"--workspace-dir",
"D:/Projects/myrepo"
]Example prompt to your AI assistant:
"Review my staged changes"
The reviewer agent can read any file accessible from the working directory. This is by design for comprehensive reviews, but be aware of this when using in sensitive environments.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.