Skip to main content

mergesafe-mcp

MergeSafe's findings for your own coding agent (Claude Code, Cursor, or anything else that speaks MCP over stdio). Your agent reads what MergeSafe found on a pull request, fixes it on your machine, replies on the thread, and asks for a new review.

Tool What it does
get_findings(repo, pr_number) The latest review's findings, each with a self-contained agent_prompt read from its inline comment
request_review(repo, pr_number, tier?, addons?) Asks MergeSafe to review the PR's current head
reply(repo, pr_number, comment_id, body) Replies on a finding's thread, as you
report_reproduction(repo, pr_number, comment_id, command, exit_code, output_tail) Posts the result of reproducing a finding (the command, its exit code, the last lines of output) on its thread, as you

Install

uvx mergesafe-mcp                 # run without installing
uv tool install mergesafe-mcp     # or install it

From source: uv tool install git+https://github.com/mergesafe-ai/mergesafe-mcp

Configure

Variable
MERGESAFE_API_KEY An organization API key from the MergeSafe app (ms_live_…)
MERGESAFE_API_URL Optional. Defaults to https://app.mergesafe.ai
GITHUB_TOKEN Optional. Defaults to gh auth token. Used to read MergeSafe's comments and to post your replies

Claude Code

claude mcp add mergesafe --env MERGESAFE_API_KEY=ms_live_... -- mergesafe-mcp

Cursor (~/.cursor/mcp.json or .cursor/mcp.json)

{
  "mcpServers": {
    "mergesafe": {
      "command": "mergesafe-mcp",
      "env": { "MERGESAFE_API_KEY": "ms_live_..." }
    }
  }
}

Then ask your agent: "Fix MergeSafe's blocking findings on PR 42 in acme/widgets."

What leaves your machine

  • To MergeSafe: your API key, the repo name and the PR number. MergeSafe's API returns the review's index (severity, title, file, line) and no code.
  • To GitHub: your own token, to read comments you can already see on github.com and to post your replies.
  • Your agent writes the fixes locally, with your tokens. MergeSafe never generates or applies a patch.

Metadata

Release files for mergesafe-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mergesafe-mcp 0.1.0
File Size Uploaded
mergesafe_mcp-0.1.0.tar.gz 50.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mergesafe-mcp 0.1.0
File Interpreter ABI Platform
mergesafe_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 60.5 kB

Release files / mergesafe_mcp-0.1.0.tar.gz

Download URL mergesafe_mcp-0.1.0.tar.gz
Size 50.2 kB
Tags Source
SHA-256 checksum
How to use checksums
8c67c0afe9bcd6b8ef82dbceed8e6336a067000088b067dea6a47049e5a18a3f
BLAKE2b-256 checksum
How to use checksums
e6c8e9ef174439827c6e3c2f78f9130e294c33993c4d0513218f932208035ebd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / mergesafe_mcp-0.1.0-py3-none-any.whl

Download URL mergesafe_mcp-0.1.0-py3-none-any.whl
Size 10.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
17f9f34cf7e9f21ff342a6cb9c636105c64c053fdf25a1122b65f6123ae89f3d
BLAKE2b-256 checksum
How to use checksums
1e6b57aa0eeee9f2f84b77355b3c14201a5b3a76ae0b42382b70f6a2135cbc1e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page