Enables AI code reviews through the CodeRabbit CLI by exposing a run_review tool that executes CodeRabbit with full flag coverage for analyzing committed, uncommitted, or all changes in a repository.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.CODERABBIT_CLI_PATHCODERRABBIT_MCP_CONFIGCODERRABBIT_MCP_LOCK_CONFIG_FILES— = "[\".coderabbit.yaml\"]"CODERRABBIT_MCP_LOCK_MODE— / _TYPE take plain strings.CODERRABBIT_MCP_LOCK_TYPE— = "uncommitted"CODERRABBIT_TOOL_TIMEOUT_SEC— should match the value you assign to tool_timeout_sec so this server can confirm the configuration.[](https://m8ven.ai/mcp/2001y-coderabbit-cli-mcp-00gzkt)