An MCP server for AI-powered coding help, debugging, and Git operations
DevGuardian has 29 tools with generally present schemas and descriptions, but significant quality gaps reduce overall effectiveness. While naming follows verb_noun patterns (debug_error, review_code, git_push), many descriptions are vague or lack actionable guidance. Parameter documentation is inconsistent, some parameters have helpful descriptions ('Analyze an error and get a fix'), others are bare type declarations ('Path to repository'). Output schemas are not documented, making it unclear what LLMs should expect back. Error handling guidance is minimal. Tool composition has issues: several git_* tools are narrowly scoped when batch operations would be more efficient for agents. Security tools like validate_env and security_scan lack clear risk categorization or recovery guidance. The swarm tools (agent_swarm, test_and_fix) invoke LangGraph agents but do not expose their composition or output structure. Overall, the server defines tools competently but lacks the refinement needed for confident production use.
🤖 3-Agent Swarm: Coder + Tester + Reviewer pipeline. Builds a feature, audits it for bugs, and returns production-ready code.
Analyze an error and get a fix (Gemini 2.0 Flash).
🐳 Generates a production-grade Dockerfile and docker-compose.yml tailored to the project's detected tech stack.
Explain code structure and logic.
Generates a Mermaid.js diagram representing the internal dependencies.
🚀 Generates a GitHub Actions CI/CD workflow (.github/workflows/ci.yml) tailored to the project's stack (tests, linting, Docker, etc.).
Git operation tools lack descriptive guidance. Tools like git_status, git_add, git_pull have descriptions of only 20-25 characters ('Check git status of repository', 'Stage files for commit'), failing the minimum 50-character baseline. LLMs cannot determine when to call these vs similar tools without more context.
Output schemas are not documented for any tool. The rubric requires 'Document the output schema. LLMs need to know what fields to expect so they can plan downstream tool calls and extract the right data.' Callers have no way to know if git_log returns commit objects, strings, or a structured array. This breaks tool chaining.
agent_swarm and test_and_fix invoke LangGraph agents (commented as 'LangGraph agent imports are intentionally lazy') but do not expose the agent's composition, state, or output structure. LLMs cannot plan multi-step invocations or understand what these tools return. Tool definitions should document the internal workflow and expected response format.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 50 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 43 | - | v1 |
Generate code from description.
🛡️ Smart .gitignore Generator: analyzes the project structure and generates a tailored .gitignore file via AI.
Generates a technical README snippet explaining the architecture.
Stage files for commit
List or manage branches
Switch or create branches
Create a commit with message
View differences between commits
View commit history
Pull commits from remote
Push commits to remote — runs security gate first.
View remote repositories
Reset repository to a previous state
Stash or restore changes
Check git status of repository
Refactor and improve existing code.
Applies a single refactoring instruction across an entire Python project.
AI code review (security, performance, style).
🌐 GitHub PR Reviewer: fetches a PR's diffs from GitHub and performs an AI-powered code review. Set GITHUB_TOKEN in .env for private repos.
Scan repo for credential leaks and gitignore issues.
Generate AI-powered commit message from staged diff and commit automatically
🧪 TDD Auto-Pilot: generates pytest tests for a file, runs them, and iteratively fixes the source until tests pass.
Validate .env format (never leaks values).
Security tools (validate_env, security_scan) lack error guidance and recovery paths. If validate_env finds credential leaks, the description says 'never leaks values' but does not explain what the tool returns or how the LLM should act on the result. No actionable error recovery or next steps.
git_* tools are narrowly scoped. Adding multiple files requires N sequential git_add calls. Patterns recommend 'Offer batch variants for tools agents call in loops.' Consider git_add_batch(files: string[]) to support efficient multi-file staging.
agent_swarm tool name violates naming conventions. 'agent_swarm' is a noun phrase, not a verb_noun action. Should be 'run_agent_swarm' or 'build_feature_with_swarm' to signal the action the tool performs.
Parameter descriptions for many code tools lack formatting guidance. improve_code, generate_code accept 'language' strings but do not specify valid values (Python, JavaScript, Go, etc.). LLMs will hallucinate unsupported languages. Use enums or explicit constraints.
Destructive git operations (git_reset with mode 'hard', git_push, git_reset) lack confirmation or dry-run support. Patterns require 'Irreversible operations should support a dry-run or confirmation step.' An agent could inadvertently push breaking changes or hard-reset a repo.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) are declared. Per the 2026-07-28 spec, tools should declare their risk profile. This helps MCP clients and agents understand which tools are safe to retry and which require user confirmation.