BotShelf Vampire BOTSHELF VAMPIRE Register

Library · Team · MCP · coding-review

MCP mcp Engineering Untested tool-protocol free

Coding Review — MCP

Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (MCP-oriented tool + prompt pack (read-only first).)

Id: mcp/coding-review · Slug: coding-review · Status: Untested · Untested on this machine — recipe reviewed for safety (no secrets, no destructive commands, no auto-spend). Mark tested after you run it locally.

What is this

MCP for MCP. Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (MCP-oriented tool + prompt pack (read-only first).)

How this runtime fits

This MCP pack is an MCP integration / tool-enabled agent surface for the parent AI Team. Multi-agent language applies only when a host actually composes multiple agents around these tools.

Parent AI Team: coding-review · What is an AI Team?

What it does

Review a diff or file for bugs, risky paths, and missing tests — without auto-committing or running destructive commands. (MCP-oriented tool + prompt pack (read-only first).)

Who for

Builders working on Engineering jobs who can run MCP themselves.

Need to run

How to use

  1. Review server_hints.md and implement only allowlisted read-only tools.
  2. Load prompt.md as the client system prompt.
  3. Run one Example in query with tools off; then enable library_search only.
  4. Confirm path allowlist before any file read tool.

Limitations

Test status

Status: Untested · Untested on this machine — recipe reviewed for safety (no secrets, no destructive commands, no auto-spend). Mark tested after you run it locally.

# MCP pack — Coding Review

## prompt.md (client)
You are a code review specialist. Goal: find bugs and risks in the pasted diff/file.

RULES:
- Do not rewrite the whole codebase. Comment on the provided snippet only.
- Flag: correctness, security, missing tests, irreversible ops, secrets.
- Never suggest committing secrets, force-push, or rm -rf style cleanup.
- Propose patches as unified-diff style snippets when useful.
- Stop with a severity-ordered list. Human decides merges.

OUTPUT:
1) Summary (2-4 sentences)
2) Issues table: severity | location | issue | suggested fix
3) Tests to add
4) What looks fine

## server_hints.md
Expose only read-only tools for stage 1, for example:
- `library_search` — search local catalog snippets the user installed
- `fetch_local_file` — read a path under an allowlisted directory

Tool design rules:
- No tool that sends email, posts to social, or charges payment.
- No tool that reads `~/.ssh`, `.env`, or browser cookie DBs.
- Arguments must be schema-validated; reject path traversal.
- Log tool calls for the human operator.

Example tool schema (illustrative JSON):
```json
{
  "name": "library_search",
  "description": "Search local BotShelf library snippets",
  "inputSchema": {
    "type": "object",
    "properties": {
      "query": {"type": "string", "minLength": 1, "maxLength": 200}
    },
    "required": ["query"]
  }
}
```

Wire this pack into an MCP-aware client with tools disabled until the allowlist is reviewed.
Review this Python snippet:
```
def pay(user, amount):
    charge(user.card, amount)
    send_receipt(user.email)
```
Context: internal tool, no retries yet.
Summary: Charge-then-receipt with no idempotency or failure handling.
Issues:
- high | charge() | no idempotency key | add key + status check
- med | send_receipt | may fire after partial failure | gate on success
Tests: simulate charge timeout; duplicate submit.
Looks fine: clear happy-path shape.

Protocol-level pack. Prefer read-only tools. Never ship credentials inside MCP configs.

Parent: coding-review · implementation_id: mcp/coding-review

teams/coding-review/mcp · commit eb87e8e049fdf9908e438305ff827c7b617505b5 · license: free-use-at-own-risk

Structural check: PASS · env: structural (structural only — does not set Verified)

Soft thematic links only — not identity merges. Marketplace Teams ≠ Library AI Team records.