jev-review — security grade SAFE, quality 70/100

Security audit verdict: SAFE · quality 70/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by NiazMorshed2007 · MCP Server · ★ 177

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is jev-review safe to install? View the security audit →

About jev-review

Jev Review Continuous software-quality review for AI coding agents, powered by Jev. Quick start · Client setup · Quality dimensions · Security Jev Review runs as a local MCP server and gives Claude Code, Codex, Cursor, and OpenCode structured quality scores while they work. Your coding agent remains responsible for diagnosing weaknesses and changing the code; Jev supplies a fast scalar signal across correctness, complexity, changeability, modularity, tests, security, and other independent quality dimensions. [!IMPORTANT] Your API key stays on your machine. Jev Review has no hosted backend, database, telemetry service, or author-operated proxy. The only remote request is sent directly to the configured Jev API. Demo https://github.com/user-attachments/assets/0ff9f873-0652-4826-af3d-6bb4f42c70b1 At a glance This GitHub

agent-pluginai-agentsclaude-codecode-reviewcodexcoding-agentscursordeveloper-toolsjevlocal-first

Quick Facts

Stars177
Forks16
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score70.013971204523/100
Open Issues4
Last Updated2026-09-17
Created2026-09-17
Platformsclaude-code, codex, mcp, node
Est. Tokens~17k

Compatible Skills

These tools work well together with jev-review for enhanced workflows:

  • garcon — semantic(0.33)+complementary+same_lang+similar_pop+shared_platform (62%)
  • agentplane — semantic(0.29)+complementary+same_lang+similar_pop+shared_platform (60%)

jev-review alternative? Top 6 similar tools

Looking for a jev-review alternative? If you're comparing jev-review with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • memorix by AVIDS2 · ⭐ 791

    Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Wi

  • OpenContext by 0xranx · ⭐ 729

    A personal context store for AI agents and assistants—reuse your existing coding agent CLI (Codex/Claude/OpenC

  • sage by usetig · ⭐ 105

    An LLM council that reviews your coding agent's every move

  • Overture by SixHq · ⭐ 630

    Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server

  • roam-code by Cranot · ⭐ 518

    Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 287 comman

  • maestro by ReinaMacCredy · ⭐ 232

    Local-first coordination for human and agent work: durable work, decisions, dispatches, evidence, and prompt-f

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is jev-review?

jev-review is Local-first MCP plugin for continuous software-quality review by AI coding agents, powered by Jev.. It is categorized as a MCP Server with 177 GitHub stars.

What programming language is jev-review written in?

jev-review is primarily written in TypeScript. It covers topics such as agent-plugin, ai-agents, claude-code.

How do I install or use jev-review?

You can find installation instructions and usage details in the jev-review GitHub repository at github.com/NiazMorshed2007/jev-review. The project has 177 stars and 16 forks, indicating an active community.

What license does jev-review use?

jev-review is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to jev-review?

The top alternatives to jev-review on Agent Skills Hub include memorix, OpenContext, sage. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools