Library · Team · MCP · coding-review
Coding Review — MCP
Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (MCP-oriented tool + prompt pack (read-only first).)
Id: mcp/coding-review · Slug: coding-review · Status: Untested · Untested on this machine — recipe reviewed for safety (no secrets, no destructive commands, no auto-spend). Mark tested after you run it locally.
What is this
MCP for MCP. Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (MCP-oriented tool + prompt pack (read-only first).)
How this runtime fits
This MCP pack is an MCP integration / tool-enabled agent surface for the parent AI Team. Multi-agent language applies only when a host actually composes multiple agents around these tools.
Parent AI Team: coding-review · What is an AI Team?
What it does
Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (MCP-oriented tool + prompt pack (read-only first).)
Who for
Builders working on Engineering jobs who can run MCP themselves.
Need to run
- You will run this locally or on infra you control.
- No production credentials in prompts or committed files.
- MCP-aware client
- Ability to allowlist tools
How to use
- Review server_hints.md and implement only allowlisted read-only tools.
- Load prompt.md as the client system prompt.
- Run one Example in query with tools off; then enable library_search only.
- Confirm path allowlist before any file read tool.
Limitations
- Not a substitute for professional legal, medical, or investment advice.
- Outputs can be wrong; human review required before publish or spend.
- Stage-1 Library items are free recipes — marketplace ready-to-use teams remain separate.
- Local models may omit sections; re-prompt once if needed.
Test status
Status: Untested · Untested on this machine — recipe reviewed for safety (no secrets, no destructive commands, no auto-spend). Mark tested after you run it locally.
Files
server_hints.md— MCP server/tool design notesprompt.md— Client system prompt when tools are available
Full prompt / config / code
# MCP pack — Coding Review
## prompt.md (client)
You are a code review specialist. Goal: find bugs and risks in the pasted diff/file.
RULES:
- Do not rewrite the whole codebase. Comment on the provided snippet only.
- Flag: correctness, security, missing tests, irreversible ops, secrets.
- Never suggest committing secrets, force-push, or rm -rf style cleanup.
- Propose patches as unified-diff style snippets when useful.
- Stop with a severity-ordered list. Human decides merges.
OUTPUT:
1) Summary (2-4 sentences)
2) Issues table: severity | location | issue | suggested fix
3) Tests to add
4) What looks fine
## server_hints.md
Expose only read-only tools for stage 1, for example:
- `library_search` — search local catalog snippets the user installed
- `fetch_local_file` — read a path under an allowlisted directory
Tool design rules:
- No tool that sends email, posts to social, or charges payment.
- No tool that reads `~/.ssh`, `.env`, or browser cookie DBs.
- Arguments must be schema-validated; reject path traversal.
- Log tool calls for the human operator.
Example tool schema (illustrative JSON):
```json
{
"name": "library_search",
"description": "Search local BotShelf library snippets",
"inputSchema": {
"type": "object",
"properties": {
"query": {"type": "string", "minLength": 1, "maxLength": 200}
},
"required": ["query"]
}
}
```
Wire this pack into an MCP-aware client with tools disabled until the allowlist is reviewed.
Example in
Review this Python snippet:
```
def pay(user, amount):
charge(user.card, amount)
send_receipt(user.email)
```
Context: internal tool, no retries yet.Example out
Summary: Charge-then-receipt with no idempotency or failure handling. Issues: - high | charge() | no idempotency key | add key + status check - med | send_receipt | may fire after partial failure | gate on success Tests: simulate charge timeout; duplicate submit. Looks fine: clear happy-path shape.
Model / runtime notes
Protocol-level pack. Prefer read-only tools. Never ship credentials inside MCP configs.
Canonical Team
Parent: coding-review
· implementation_id: mcp/coding-review
GitHub source
teams/coding-review/mcp · commit eb87e8e049fdf9908e438305ff827c7b617505b5
· license: free-use-at-own-risk
Structural check: PASS · env: structural (structural only — does not set Verified)
Related Library items
Related marketplace Team pages
Soft thematic links only — not identity merges. Marketplace Teams ≠ Library AI Team records.
- Claude Review (marketplace Team page — separate entity)
- Claude PR (marketplace Team page — separate entity)