# Moltline Code Review (remote · mcp.moltlinestudio.com)

Risk-scan a diff, flag AI-generated-code tells, find secrets. 5 of 7 tools need no account.

- Trust score: 87/100 (high trust)
- Change this week: +1
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-21

## Components

- remote · `mcp.moltlinestudio.com`: 87/100 (this document), [markdown](https://verifymcp.io/servers/com-moltlinestudio-codereview/codereview.md), [page](https://verifymcp.io/servers/com-moltlinestudio-codereview/codereview)

## Channel facts

- Endpoint: `https://mcp.moltlinestudio.com/codereview`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-21.

- **Endpoint Security**: 83/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 68/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1702 tokens (~243/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 100/100
  - No destabilizing schema changes in the last 30 days.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Moltline Code Review MCP server?

Moltline Code Review is a hosted endpoint at https://mcp.moltlinestudio.com/codereview, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-moltlinestudio-codereview 'https://mcp.moltlinestudio.com/codereview'
```

### Cursor

```json
{
  "mcpServers": {
    "com-moltlinestudio-codereview": {
      "url": "https://mcp.moltlinestudio.com/codereview"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-moltlinestudio-codereview": {
      "type": "http",
      "url": "https://mcp.moltlinestudio.com/codereview"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-moltlinestudio-codereview]
url = "https://mcp.moltlinestudio.com/codereview"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-moltlinestudio-codereview": {
      "type": "remote",
      "url": "https://mcp.moltlinestudio.com/codereview",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-moltlinestudio-codereview --url 'https://mcp.moltlinestudio.com/codereview' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-moltlinestudio-codereview:
    url: "https://mcp.moltlinestudio.com/codereview"
```

### Netclaw

```json
{
  "McpServers": {
    "com-moltlinestudio-codereview": {
      "Transport": "http",
      "Url": "https://mcp.moltlinestudio.com/codereview"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-moltlinestudio-codereview -t streamable-http -u 'https://mcp.moltlinestudio.com/codereview'
```

### Other

```json
{
  "mcpServers": {
    "com-moltlinestudio-codereview": {
      "type": "http",
      "url": "https://mcp.moltlinestudio.com/codereview"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-16 (score 87, 0)

- [security] Stability: 0.97 → pass

### 2026-09-15 (score 87, +1)

No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-12 (score 86, +1)

No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-10 (score 85, +1)

No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-08 (score 84, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-06 (score 83, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-04 (score 82, +1)

No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-02 (score 81, +1)

No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (7)

### `review_diff` (~275 tokens)

Review Diff

Risk-scan a unified diff the way a senior reviewer triages a PR. FREE.

Flags added lines matching known risk patterns — injection sinks, disabled
TLS, bare excepts, debug prints, TODOs, N+1 hints, leaked secrets — with
the new-file line number and a severity (1 low - 4 high). Typical input
{"diff": "<git diff output>"} returns {"added_lines": N, "risk_score":
0-100, "verdict": "...", "secrets": [...], "findings": [{"line": N,
"severity": 1-4, "issue": "...", "code": "..."}], "note": "..."}.

Use on a unified diff, when only the change matters. Not for whole-file
analysis (complexity_report, ai_code_smell_scan). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input parameters:

- `diff` (string, required): A unified diff exactly as produced by `git diff` — text with @@ hunk headers and +/- line prefixes. Only added (+) lines are scanned.

### `ai_code_smell_scan` (~246 tokens)

Ai Code Smell Scan

Flag the tells of unreviewed AI-generated code in a source file. FREE.

Detects comments that restate the next line, leaked assistant preambles,
placeholder TODOs, shipped 'Example usage' blocks, over-broad try/except
that swallows errors, and auto-named identifiers. Typical input
{"code": "<file contents>"} returns {"reviewed_confidence": 0-100,
"hits": [{"smell": "...", "evidence": "<quoted snippet>"}], "reading":
"...", "note": "..."}.

Use on a full source file suspected of unreviewed machine authorship. Not
on a diff (review_diff), and the result is a signal to check, not proof of
authorship. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input parameters:

- `code` (string, required): Full source text to scan, any language; paste the file contents as a single string.

### `complexity_report` (~253 tokens)

Complexity Report

Report structural complexity of a source file, function by function. FREE.

Measures per-function length, max nesting depth, and a cyclomatic-style
branch count (if/for/while/case/&&/||/except), flagging functions too
long or too deeply nested to review confidently. Typical input
{"code": "<file contents>"} returns {"functions": N, "detail":
[{"name": ..., "start": N, "lines": N, "branches": N, "max_depth": N}],
"flags": ["..."], "note": "..."}.

Use when structure rather than correctness is the question. Not for
vulnerabilities (security_deep_dive). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input parameters:

- `code` (string, required): Full source text to analyze, pasted as a single string.
- `language` (string): Optional language hint, e.g. "python" or "javascript"; "auto" (default) detects from syntax.

### `secret_scan` (~231 tokens)

Secret Scan

Scan text for accidentally-committed machine credentials and private-key material. FREE.

Reports each match's location and category so it can be rotated before it
leaks. Detection is pattern-based over the common leaked-credential
formats; it never echoes the matched value back. Typical input
{"text": "<file, diff, or config contents>"} returns {"leaked": bool,
"count": N, "findings": [{"line": N, "type": "<category>"}], "note": "..."}.

Pattern matching only - a clean result is not proof, and every hit needs
human confirmation before anyone acts on it. Not a general security review
(security_deep_dive). Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input parameters:

- `text` (string, required): The file, diff, or config contents to scan, pasted as a single string.

### `review_checklist` (~202 tokens)

Review Checklist

Produce a focused pull-request review checklist for a language or stack. FREE.

Covers the things that actually break in production, with extra items per
language. Typical input {"language": "python"} returns {"language":
"python", "checklist": ["...", ...], "note": "..."}.

Use before a review, to decide what to look for. Not for reviewing actual
code - pass code to review_diff or security_deep_dive. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input parameters:

- `language` (string): Language or stack to tailor for: "python", "javascript", "typescript", "go", "sql", or "general" (default). Unknown values fall back to the general checklist.

### `security_deep_dive` (~237 tokens)

Security Deep Dive

Run an OWASP-oriented security pass over a source file. PREMIUM (license).

Checks injection sinks, auth/session handling, crypto misuse,
SSRF/deserialization, and unsafe file/path handling — each finding cites
the line, the OWASP risk class, and a concrete fix direction. Typical
input {"code": "<file contents>"} returns {"issues": N, "findings":
[{"line": N, "class": "A03 Injection", "fix": "...", "code": "..."}],
"owasp_note": "..."}.

Use on one source file when vulnerabilities are the question. Not for
style or structure (complexity_report), and never a substitute for a
security professional on high-risk code. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

Input parameters:

- `code` (string, required): Full source text to audit, pasted as a single string; any common language.

### `get_reviewer_persona` (~170 tokens)

Get Reviewer Persona

Load the Senior Reviewer persona for consistent, high-signal reviews. PREMIUM (license).

The persona is a reviewing voice that is skeptical, specific, and kind —
demands evidence over vibes and blocks only on real risk. Takes no
arguments. Returns {"persona": ..., "identity": ..., "rules": ["...",
...], "opening_move": "..."} ready to adopt as a system prompt.

Use to keep repeated reviews consistent in voice and rigor. Not for
running a review - the scan tools do that. Errors: on invalid, missing, or malformed input this tool never raises a protocol error — it returns {"error": "<what is wrong and how to fix it>"}. Every call is read-only and idempotent, so after correcting the input it is always safe to retry.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-moltlinestudio-codereview/codereview#diagnostics

## Score history

- 2026-09-21: 87
- 2026-09-20: 87
- 2026-09-19: 87
- 2026-09-18: 87
- 2026-09-17: 87
- 2026-09-16: 87
- 2026-09-15: 87
- 2026-09-14: 86
- 2026-09-13: 86
- 2026-09-12: 86
- 2026-09-11: 85
- 2026-09-10: 85
- 2026-09-09: 84
- 2026-09-08: 84
- 2026-09-07: 83
- 2026-09-06: 83
- 2026-09-05: 82
- 2026-09-04: 82
- 2026-09-03: 81
- 2026-09-02: 81
- 2026-09-01: 80
- 2026-08-31: 80
- 2026-08-30: 79
- 2026-08-29: 79
- 2026-08-28: 79
- 2026-08-27: 78
- 2026-08-26: 78
- 2026-08-25: 76
- 2026-08-24: 75
- 2026-08-23: 75

## Common questions

### What is the Moltline Code Review MCP server?

Moltline Code Review is an MCP server listed in the public MCP registry as com.moltlinestudio/codereview. Risk-scan a diff, flag AI-generated-code tells, find secrets. 5 of 7 tools need no account. This page covers its hosted endpoint (https://mcp.moltlinestudio.com/codereview).

### Is the Moltline Code Review MCP server safe to use?

Moltline Code Review scores 87 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Moltline Code Review MCP server expose?

Moltline Code Review exposes 7 tools: review_diff, ai_code_smell_scan, complexity_report, secret_scan, review_checklist, and 2 more. Their descriptions and schemas cost roughly 1,614 tokens of context every time the server is loaded.

### Does the Moltline Code Review MCP server require authentication?

No. We connected to Moltline Code Review without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Moltline Code Review MCP server still maintained?

Moltline Code Review is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.moltlinestudio.com/codereview
- Repository: https://github.com/GarphenGate/moltline-mcp
- Website: https://moltlinestudio.com/servers.html#codereview
- Changelog RSS feed: https://verifymcp.io/servers/com-moltlinestudio-codereview/codereview.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-moltlinestudio-codereview/codereview.json
- HTML version of this page: https://verifymcp.io/servers/com-moltlinestudio-codereview/codereview
