GitHub PR Review MCP Server

GitHub PR Review MCP Server

Comprehensive MCP server for analyzing GitHub pull requests, detecting security vulnerabilities, assessing code quality, and providing risk ratings across multiple languages.

Category
访问服务器

README

GitHub PR Review MCP Server

An MCP (Model Context Protocol) server for comprehensive GitHub Pull Request review, code analysis, and security issue detection.

Features

  • 🔍 Comprehensive PR Analysis: Analyzes pull requests for code quality, security vulnerabilities, and best practices
  • 🛡️ Security Scanning: Detects common security issues and vulnerabilities across multiple programming languages
  • 📊 Code Quality Assessment: Evaluates code maintainability, complexity, and adherence to best practices
  • 🚨 Risk Assessment: Provides overall risk ratings and actionable recommendations
  • 🔧 Multi-language Support: Supports JavaScript, TypeScript, Python, Java, C#, PHP, and more
  • 📋 Detailed Reporting: Generates comprehensive review reports with file-level analysis

Installation

Prerequisites

  • Node.js 18.0.0 or higher
  • GitHub Personal Access Token with repository access

Setup

  1. Clone the repository:
git clone https://github.com/doraemon0905/github-review.git
cd github-review
  1. Install dependencies:
npm install
  1. Build the project:
npm run build
  1. Set up environment variables:
export GITHUB_TOKEN=your_github_personal_access_token

Usage

Running the MCP Server

npm start

The server will start and listen for MCP connections on stdio.

Configuration in Cursor/Claude

Add the following configuration to your MCP settings:

{
  "github-pr-review": {
    "command": "node",
    "args": ["/path/to/github-review/dist/index.js"],
    "env": {
      "GITHUB_TOKEN": "your_github_token_here"
    }
  }
}

Available Tools

1. get_pull_request

Fetch pull request details including metadata and file changes.

Parameters:

  • owner (string): Repository owner (username or organization)
  • repo (string): Repository name
  • pull_number (number): Pull request number

Example:

Get pull request microsoft/vscode #12345

2. review_pull_request

Perform a comprehensive review of a pull request including code analysis, issue detection, and security checks.

Parameters:

  • owner (string): Repository owner
  • repo (string): Repository name
  • pull_number (number): Pull request number
  • include_security (boolean, optional): Include security analysis (default: true)
  • include_best_practices (boolean, optional): Include best practices recommendations (default: true)
  • severity_threshold (string, optional): Minimum severity level to report - "low", "medium", "high", or "critical" (default: "medium")

Example:

Review pull request microsoft/vscode #12345 with high severity threshold

3. analyze_code_diff

Analyze specific code changes for issues and security vulnerabilities.

Parameters:

  • diff_content (string): Git diff content to analyze
  • file_path (string): Path of the file being analyzed
  • language (string, optional): Programming language (auto-detected if not provided)
  • include_security (boolean, optional): Include security analysis (default: true)

Example:

Analyze this diff for security issues:
```diff
+function validateUser(input) {
+  return eval(input.code);
+}

4. get_repository_prs

List pull requests for a repository with filtering options.

Parameters:

  • owner (string): Repository owner
  • repo (string): Repository name
  • state (string, optional): PR state filter - "open", "closed", or "all" (default: "open")
  • limit (number, optional): Maximum number of PRs to return (default: 10, max: 100)
  • sort (string, optional): Sort criteria - "created", "updated", "popularity", or "long-running" (default: "created")

Example:

List open pull requests for microsoft/vscode

Security Analysis

The server detects various security issues including:

JavaScript/TypeScript

  • Use of eval() and similar dangerous functions
  • XSS vulnerabilities via innerHTML
  • Unsafe setTimeout usage
  • TypeScript any type usage
  • Hardcoded secrets and API keys

Python

  • Use of exec() and eval()
  • Unsafe pickle usage
  • Bare except clauses
  • Input validation issues

PHP

  • SQL injection patterns
  • Use of dangerous functions
  • Unvalidated superglobal usage

General

  • Hardcoded passwords and API keys
  • Commented-out code
  • TODO/FIXME markers
  • Long lines and code complexity

Code Quality Assessment

The analyzer evaluates:

  • Complexity: Cyclomatic complexity based on decision points
  • Maintainability: Score based on line count, complexity, and readability
  • Duplicate Code: Detection of repeated code patterns
  • Best Practices: Language-specific coding standards
  • File Risk: Assessment based on file types and patterns

Risk Assessment

Each PR receives an overall risk rating:

  • Low: Minor issues, safe to merge
  • Medium: Some issues present, review recommended
  • High: Security concerns or multiple issues
  • Critical: Serious issues that block merging

Development

Project Structure

src/
├── index.ts              # Main MCP server
├── services/
│   ├── GitHubService.ts  # GitHub API interactions
│   ├── CodeAnalyzer.ts   # Code analysis engine
│   └── PRReviewer.ts     # PR review orchestrator

Building

npm run build

Development Mode

npm run dev

Linting

npm run lint

Testing

npm test

Contributing

  1. Fork the repository
  2. Create a feature branch: git checkout -b feature-name
  3. Make your changes and add tests
  4. Run the test suite: npm test
  5. Run the linter: npm run lint
  6. Commit your changes: git commit -am 'Add feature'
  7. Push to the branch: git push origin feature-name
  8. Create a Pull Request

License

This project is licensed under the MIT License - see the LICENSE file for details.

Security

If you discover a security vulnerability, please send an email to nguyentruonggiang91@gmail.com. All security vulnerabilities will be promptly addressed.

Changelog

Version 1.0.0

  • Initial release
  • GitHub PR analysis
  • Multi-language security scanning
  • Code quality assessment
  • Risk assessment and recommendations

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选