feat: implement issue #816 — Add a zero-auth MCP server (Context7) to the PR-review action agent runtime - #826
Conversation
… the PR-review action agent runtime
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughReplaces the plan-blocked ChangesContext7 MCP pilot enablement
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related issues
Possibly related PRs
Suggested labels
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
There was a problem hiding this comment.
Code Review
This pull request switches the Model Context Protocol (MCP) server configuration from the plan-gated GitHub secret-scanning server to a zero-auth Context7 endpoint, updating the initiative documentation and adding unit tests to verify the new setup. The reviewer identified a critical issue where the configuration incorrectly uses an unsupported "http" transport type instead of "sse", which would cause connection failures. Feedback recommends updating the configuration, tests, and documentation to use "sse".
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
Re: gemini-code-assist review — keep
|
|
Thank you for the detailed breakdown, @don-petry. Your assessment regarding the transport protocol is correct. If the endpoint is configured for streamable HTTP, forcing a client to use the SSE transport will indeed lead to a connection failure. Given that your testing confirms the current |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-06-20T06:21:00Z. |
Superseded by automated re-review at
|
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-06-20T08:06:07Z. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
Superseded by automated re-review at
|
The fix-reviews automation applied gemini-code-assist's http->sse suggestion,
but that suggestion is incorrect: Claude Code's MCP client recommends the
streamable-HTTP transport ("type": "http") and has DEPRECATED sse, and
Context7 serves streamable HTTP at /mcp (SSE is a separate /sse path). Pairing
"type": "sse" with the /mcp URL points an SSE client at a streamable-HTTP
endpoint -> connection failure -> silent degradation.
This matches issue #816's concrete-change spec ("type": "http"), the
pre-existing GitHub MCP server that connected in the #774 live runs, and
gemini-code-assist's own subsequent agreement to keep http. Reverts the config,
the bats assertion, and the two doc references back to http.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015VRMMWmqW9nW81jygmea3e
Resolution — transport reverted to
|
|
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 3c7c6f94d960d107cdeb3b3e10caf5c2562ff4e2
Review mode: triage-approved (single reviewer)
Summary
PR #816 switches the review MCP config from the plan-gated GitHub secret-scanning server to the zero-auth Context7 HTTP endpoint (https://mcp.context7.com/mcp, "type": "http"), and updates the initiative doc plus adds bats coverage pinning the new config shape. Small, well-scoped, docs-heavy change (+97/-18 across 3 files). Confirming the triage-approved assessment.
Linked issue analysis
Closes #816. The PR substantively implements the issue: (1) .github/review-mcp.json now configures the zero-auth Context7 endpoint instead of the advanced_security-gated github/run_secret_scanning server; (2) the doc records the Phase-2 pilot outcome, the plan-gating rationale, and a rollout recommendation that keeps downstream rollout an explicit human decision; (3) tests/dev-lead/unit/test_engine_mcp.bats pins the http transport, the /mcp URL, the absence of auth headers, and that the github entry is gone. Interim secret coverage is retained via the existing 'Secret scan (gitleaks)' CI check.
Findings
No blocking findings.
- Transport correctness (resolved): gemini-code-assist flagged "type": "http" as unsupported and asked to switch to "sse". The owner rebutted with evidence — Claude Code's MCP client recommends streamable-HTTP and has deprecated SSE, and Context7 serves streamable HTTP at /mcp (SSE is a separate /sse path). gemini explicitly agreed and marked the comments won't-fix. An automation had transiently applied the bad http→sse change; HEAD 3c7c6f9 reverts it. The committed http + /mcp pairing is internally consistent across the config, the bats assertion, and the doc.
- Secret scan: the run_secret_scanning MCP tool was not permitted in this environment, so it was skipped (not failed); the gitleaks CI check passed and the diff introduces no secret material (it removes a ${GH_TOKEN} placeholder and adds a zero-auth endpoint).
- Data egress note (non-blocking): routing review content to an external Context7 endpoint is the explicit, owner-driven intent of this pilot; tool scope is constrained via REVIEW_MCP_ALLOWED_TOOLS=mcp__context7__* and graceful degradation (single ::warning::[mcp] annotation) is regression-tested.
CI status
All required checks green. Notable passing checks: CodeQL, SonarCloud (Quality Gate passed, 0 new issues), Secret scan (gitleaks), shellcheck, bats/unit-tests, AgentShield, Agent Security Scan, validate-fixtures, caller/toplevel-permissions. Skipped checks are conditional (dependabot, language-specific dependency-audit, ci-relay) and expected. coderabbitai APPROVED at the current head; gemini's comment thread is resolved. mergeStateStatus is BLOCKED only pending this required review.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.



Closes #816
Implemented by dev-lead agent. Please review.
Summary by CodeRabbit