Task · Coding
Best AI agents to review pull requests
This task needs 2 capabilities. 19 tools cover all of them; 19 shown.
| # | Tool | Coverage | Access | Trust | Seen |
|---|---|---|---|---|---|
| 1 | GitHub Actions Security AuditMCP Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions. | 100% | REMOTELOCAL | DECLARED | 1d ago |
| 2 | Vulnerability Intel MCPMCP Defensive vulnerability intelligence search across public CVE/NVD and GitHub advisory APIs with CVSS | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 3 | SecurityScanMCP Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 4 | regulatory-signalsMCP Audit GitHub repos for security, compliance, and EU AI Act exposure from Claude or Cursor. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 5 | flagrixMCP Scan GitHub repos and profiles for malware before cloning — commit-pinned risk verdicts for agents | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 6 | taskbounty-checkMCP Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 7 | Repo Security Scanner — Malicious Code & Supply ChainMCP Audit GitHub repos for malicious and supply-chain code before you depend on them. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 8 | dingdawg-code-reviewMCP AI code review — security, quality, performance. Learns your patterns. Receipted. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 9 | diffpilotMCP MCP server for PR code review, commit messages, changelogs, and secret detection. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 10 | Grasp — Code Architecture & Dependency AnalysisMCP Codebase analysis: dependency graphs, security scanning, and refactor plans for GitHub and GitLab. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 11 | GitHub Actions AuditMCP GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 12 | Kubernetes Manifest AuditMCP kube-linter audit for Kubernetes manifests — 63 checks: security, availability, RBAC, network. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 13 | sphior-code-mcpMCP Deterministic SAST/SCA findings + fix guidance for your GitHub repos, handed to your AI agent. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 14 | Agentic SDLC MCPMCP Agentic SDLC governance and security controls for AI coding agents working with GitHub. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 15 | MCP Code Review ServerMCP Code review as an MCP server — structured reviews with OWASP security scanning. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 16 | mcpMCP FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 17 | megalinterMCP MCP server for running Ox Security MegaLinter via mega-linter-runner | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 18 | Compuute MCP Security ScannerMCP Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages. | 100% | REMOTELOCAL | DECLARED | 5d ago |
| 19 | VulX WatchMCP Independent security review for AI-built apps. Watch a GitHub repo. Never a patch. | 100% | REMOTELOCAL | DECLARED | 5d ago |
Page 1 / 1
Coverage = share of this task's required capabilities that an agent or tool documents. For AI agents, capabilities are those stated on the vendor's website; for tools, they are matched automatically from the publisher's description (keyword method, low confidence).