Server data from the Official MCP Registry
Check whether a coding agent's changes stayed inside the scope it was given.
About
Check whether a coding agent's changes stayed inside the scope it was given.
Security Report
Valid MCP server (2 strong, 3 medium validity signals). No known CVEs in dependencies. ⚠️ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.
17 files analyzed · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-sjh9714-mergewarden": {
"args": [
"-y",
"mergewarden-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
MergeWarden
See which pull requests need context before code review.
Paste a public GitHub repository. MergeWarden surfaces missing issue links, thin descriptions, skipped templates, and oversized changes. No login. No AI.
This is an experimental tool. Review-time savings and repeat maintainer use have not been demonstrated. Product expansion is on hold; see the roadmap and evidence limits.
Review a public repository
The getting started guide explains queue states, detailed PR results, and the Action install path.
Paste owner/repository or a full GitHub repository URL. The browser reads the
latest thirty open pull request summaries, removes trusted repository roles,
base repository branches, and known maintenance automation, then loads details
for at most ten external pull requests.
Rows are ordered by deterministic facts a maintainer would otherwise check before reading code.
| Fact | What it means |
|---|---|
| No linked issue | The body has no issue number, issue URL, or closing keyword |
| Thin description | The body has fewer than 80 characters of prose |
| Template unused | The repository has a visible PR template structure that the body did not keep |
| Oversized | The change exceeds 50 files or 1,500 changed lines |
First contribution is shown as context and never used as a score. MergeWarden does not call a contribution spam, low quality, or AI generated. It never closes, labels, scores, or comments on a pull request.
The queue uses public metadata and the base branch pull request template. It does not fetch changed file contents, execute code, use a backend, or store the target.
For a larger authenticated queue, use the CLI.
GH_TOKEN=... npx --yes mergewarden@0.10.4 triage owner/repository
Run the detailed PR risk scan
The same page accepts a full pull request URL or owner/repository#number.
Every queue row links to this detailed scan.
The detailed scan checks four security boundaries.
| Check | What deserves review |
|---|---|
| Workflow permissions | A workflow gains write access, uses a dangerous trigger, or depends on a moving Action reference |
| Agent instructions | A PR changes AGENTS.md, CLAUDE.md, .mcp.json, or another file that steers coding agents |
| Untrusted prompt inputs | Pull request text reaches an agent prompt in a workflow |
| Install scripts | A package manifest adds or changes install-time lifecycle code |
The configuration reference lists every deterministic rule and severity.
Run the same scan from a terminal without cloning the target repository.
npx --yes mergewarden@0.10.4 scan https://github.com/owner/repository/pull/123
Add the Action
The Action automates the detailed PR risk check. It does not order the review queue.
Create .github/workflows/mergewarden.yml.
name: MergeWarden PR Risk Check
on:
pull_request:
permissions:
contents: read
pull-requests: write
jobs:
mergewarden:
runs-on: ubuntu-latest
steps:
- uses: sjh9714/mergewarden@v0.10.4
with:
comment: auto
comment: auto stays quiet when there is nothing actionable and updates one
comment when a finding needs attention. Existing Action defaults are unchanged.
For an immutable install, pin the release commit.
MergeWarden does not publish or recommend a mutable v0 tag.
- uses: sjh9714/mergewarden@d63b4fc8c09c540375f039ecd30d2fce56abf31f
Safety boundaries
- The web app talks directly to the public GitHub API and has no telemetry.
- The queue reads metadata and templates at each PR's exact base commit. The detailed scan reads only the files required by deterministic rules.
- No checkout. MergeWarden does not execute pull-request code in the web app or Action.
- Policy comes from the exact base commit, never the untrusted PR head.
- Analysis never calls a language model.
- Incomplete evidence is reported as incomplete and never presented as a pass.
- Browser sample limits are explicit: reaching 30 summaries or leaving external PRs beyond the ten-detail limit does not produce a complete queue.
Read the security model and evidence model for the full trust boundary.
Evidence and advanced interfaces
Does triage help? records the existing queue measurement and its main limit. It measured whether rows discriminate, not whether maintainers save time. The current web queue remains a product experiment until maintainers confirm that value.
The documentation index includes configuration, Action and CLI references, coding-tool integrations, reproducible studies, and the MCP server.
Contributing
pnpm install --frozen-lockfile
pnpm build
pnpm test
pnpm typecheck
pnpm lint
pnpm format:check
Every new rule needs a passing fixture, a failing fixture, and a report snapshot. See the contribution guide.
License
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
