PluginBench
MCP Server
Active
MIT

io.github.sjh9714/mergewarden MCP Server

io.github.sjh9714/mergewarden

Check whether a coding agent's changes stayed inside the scope it was given.

What is the io.github.sjh9714/mergewarden MCP server?

MergeWarden is an MCP server that analyzes pull requests to surface missing context before code review. It checks for missing issue links, thin descriptions, skipped templates, oversized changes, workflow permission risks, agent instruction changes, untrusted prompt inputs, and install scripts—without requiring login or AI analysis.

MergeWarden helps maintainers triage pull requests by identifying deterministic facts that deserve attention before code review. It surfaces missing issue links, thin descriptions, template violations, oversized changes, and security boundaries like workflow permissions and agent instruction modifications. Use it to streamline review queues and catch scope violations in coding agent changes.

How to install io.github.sjh9714/mergewarden

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mergewarden": {
      "command": "npx",
      "args": [
        "-y",
        "mergewarden-mcp"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • PR triage analysis — Analyze pull requests to identify missing issue links, thin descriptions, unused templates, and oversized changes
  • Security boundary checks — Check workflow permissions, agent instructions, untrusted prompt inputs, and install scripts in pull requests
  • Repository queue review — Generate a deterministic queue of pull requests ordered by facts a maintainer would check before reading code
  • Detailed PR risk scan — Run comprehensive security and scope checks on individual pull requests via URL or owner/repository#number

Use cases

  • Triage pull requests to identify which ones need context before code review
  • Detect when a coding agent's changes exceed the scope defined in its instructions
  • Verify that pull requests include proper issue links and descriptions before review
  • Identify security risks like workflow permission changes or agent instruction modifications
  • Automate PR risk checks in GitHub Actions workflows with automatic commenting

io.github.sjh9714/mergewarden MCP server FAQ

What is MergeWarden?

MergeWarden is a tool that analyzes pull requests to surface missing context and scope violations before code review. It checks for missing issue links, thin descriptions, oversized changes, and security boundaries like workflow permissions and agent instruction changes.

Is MergeWarden free?

Yes, MergeWarden is open-source (MIT license) and free to use. The web app has no login requirement and no telemetry.

How do I use MergeWarden as an MCP server?

Install via npm with `mergewarden-mcp` and configure it in your MCP client. The MCP server provides tools to analyze pull requests and check scope compliance for coding agents.

Does MergeWarden require authentication?

The web app requires no login. For a larger authenticated queue, you can use the CLI with a GitHub token: `GH_TOKEN=... npx mergewarden@0.10.4 triage owner/repository`.

What security checks does MergeWarden perform?

MergeWarden checks workflow permissions, agent instructions (AGENTS.md, CLAUDE.md, .mcp.json), untrusted prompt inputs in workflows, and install-time lifecycle scripts in package manifests.

Does MergeWarden use AI analysis?

No. MergeWarden uses only deterministic rules and public GitHub metadata. It never calls a language model and does not execute pull request code.

README (reference)

Source of truth, from the repository.

MergeWarden

Release CI MergeWarden License

See which pull requests need context before code review.

Paste a public GitHub repository. MergeWarden surfaces missing issue links, thin descriptions, skipped templates, and oversized changes. No login. No AI.

This is an experimental tool. Review-time savings and repeat maintainer use have not been demonstrated. Product expansion is on hold; see the roadmap and evidence limits.

Review a public repository

Open the public review queue

The getting started guide explains queue states, detailed PR results, and the Action install path.

Paste owner/repository or a full GitHub repository URL. The browser reads the latest thirty open pull request summaries, removes trusted repository roles, base repository branches, and known maintenance automation, then loads details for at most ten external pull requests.

Rows are ordered by deterministic facts a maintainer would otherwise check before reading code.

FactWhat it means
No linked issueThe body has no issue number, issue URL, or closing keyword
Thin descriptionThe body has fewer than 80 characters of prose
Template unusedThe repository has a visible PR template structure that the body did not keep
OversizedThe change exceeds 50 files or 1,500 changed lines

First contribution is shown as context and never used as a score. MergeWarden does not call a contribution spam, low quality, or AI generated. It never closes, labels, scores, or comments on a pull request.

The queue uses public metadata and the base branch pull request template. It does not fetch changed file contents, execute code, use a backend, or store the target.

For a larger authenticated queue, use the CLI.

GH_TOKEN=... npx --yes mergewarden@0.10.4 triage owner/repository

Run the detailed PR risk scan

The same page accepts a full pull request URL or owner/repository#number. Every queue row links to this detailed scan.

The detailed scan checks four security boundaries.

CheckWhat deserves review
Workflow permissionsA workflow gains write access, uses a dangerous trigger, or depends on a moving Action reference
Agent instructionsA PR changes AGENTS.md, CLAUDE.md, .mcp.json, or another file that steers coding agents
Untrusted prompt inputsPull request text reaches an agent prompt in a workflow
Install scriptsA package manifest adds or changes install-time lifecycle code

The configuration reference lists every deterministic rule and severity.

Run the same scan from a terminal without cloning the target repository.

npx --yes mergewarden@0.10.4 scan https://github.com/owner/repository/pull/123

Add the Action

The Action automates the detailed PR risk check. It does not order the review queue.

Create .github/workflows/mergewarden.yml.

name: MergeWarden PR Risk Check

on:
  pull_request:

permissions:
  contents: read
  pull-requests: write

jobs:
  mergewarden:
    runs-on: ubuntu-latest
    steps:
      - uses: sjh9714/mergewarden@v0.10.4
        with:
          comment: auto

comment: auto stays quiet when there is nothing actionable and updates one comment when a finding needs attention. Existing Action defaults are unchanged.

For an immutable install, pin the release commit.

MergeWarden does not publish or recommend a mutable v0 tag.

- uses: sjh9714/mergewarden@d63b4fc8c09c540375f039ecd30d2fce56abf31f

Safety boundaries

  • The web app talks directly to the public GitHub API and has no telemetry.
  • The queue reads metadata and templates at each PR's exact base commit. The detailed scan reads only the files required by deterministic rules.
  • No checkout. MergeWarden does not execute pull-request code in the web app or Action.
  • Policy comes from the exact base commit, never the untrusted PR head.
  • Analysis never calls a language model.
  • Incomplete evidence is reported as incomplete and never presented as a pass.
  • Browser sample limits are explicit: reaching 30 summaries or leaving external PRs beyond the ten-detail limit does not produce a complete queue.

Read the security model and evidence model for the full trust boundary.

Evidence and advanced interfaces

Does triage help? records the existing queue measurement and its main limit. It measured whether rows discriminate, not whether maintainers save time. The current web queue remains a product experiment until maintainers confirm that value.

The documentation index includes configuration, Action and CLI references, coding-tool integrations, reproducible studies, and the MCP server.

Contributing

pnpm install --frozen-lockfile
pnpm build
pnpm test
pnpm typecheck
pnpm lint
pnpm format:check

Every new rule needs a passing fixture, a failing fixture, and a report snapshot. See the contribution guide.

简体中文

License

MIT

Related MCP servers

RORoutineKit logo

Capture tool workflows, save typed tools, and replay with human approval. Includes an MCP Apps UI.

1
JavaScript
MIT
View repository →

MCP server for managing Naver Cloud Platform (Ncloud) infrastructure

2
TypeScript
MIT
View repository →

MCP server for managing Naver Cloud Platform Government (Ncloud 공공존) infrastructure

1
TypeScript
MIT
View repository →

AI-powered reverse engineering, malware analysis, and security auditing via 120 integrated tools

188
Python
MIT
View repository →

AI agent-to-agent SLA agreements on Base with insurance, reputation, and x402 payments.

Free, private skill discovery for AI agents — find vetted practices without sharing your work.

13
JavaScript
MIT
View repository →