Gluecron
AI-native git hosting — repos, PRs, issues, CI gates, and AI code review over MCP (60 tools).
- 1.0.0
- Version
- remote
- Transport
- 71
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 71 tools scanned
- metadata: scanned
No findings.
Tools (71)
gluecron_repo_search
Search Gluecron repositories by keyword (name + description), case-insensitively. Returns public repos plus any private repos owned by the authenticated caller. Default 20 per page, max 50; `total` is the full match count and `nextOffset` pages through it.
gluecron_repo_read_file
Read a single file from a repository at a given ref (branch / tag / commit). Private repos are readable when the authenticated caller has access. Returns the text content (binary files rejected).
gluecron_repo_list_issues
List open issues for a public repository. Returns up to 50 ordered by most-recent.
gluecron_repo_explain_codebase
Return the cached AI 'explain this codebase' Markdown for a public repo (most recent commit). Returns null when no cached explanation exists yet.
gluecron_repo_health
Compute the current health report for a public repo: overall score (0-100), letter grade, per-category breakdown (security/testing/complexity/dependencies/documentation/activity), and a list of insights to fix next. Backed by computeHealthScore in src/lib/intelligence.ts.
gluecron_create_issue
Create a new issue on a Gluecron repository. Requires authenticated caller with write access on the target repo. Returns {number, url}.
gluecron_comment_issue
Add a comment to an existing issue. Requires authenticated caller with write access. Returns {commentId}.
gluecron_close_issue
Close an open issue. Requires authenticated caller with write access. Idempotent — closing an already-closed issue is a no-op. Returns {state}.
gluecron_reopen_issue
Reopen a previously closed issue. Requires authenticated caller with write access. Idempotent. Returns {state}.
gluecron_create_pr
Open a new pull request. `head_branch` is required; `base_branch` defaults to the repo default branch. Requires authenticated caller with write access. Returns {number, url}.
gluecron_get_pr
Fetch the full detail record of a pull request (title, body, state, branches, draft, author, timestamps). Authenticated callers only (the read tool surface still works anonymously).
gluecron_list_prs
List pull requests on a repo, filtered by state (open|closed|merged|all). Authenticated callers only. Returns up to 50 summary rows.
gluecron_comment_pr
Add a comment to a pull request. Requires authenticated caller with write access. Returns {commentId}.
gluecron_merge_pr
Merge an open PR. Enforces the same checks as the HTTP merge flow: not a draft, head SHA resolves, GateTest+AI-review hard gates pass, branch-protection rules satisfied. M3: soft-blocks when the pre-merge risk score is `critical` unless `confirm_high_risk: true` is passed. Returns {merged, sha?, reason?, riskScore?}.
gluecron_close_pr
Close an open pull request without merging. Requires authenticated caller with write access. Idempotent. Returns {state}.
gluecron_fork_repo
Fork a repository to the authenticated caller's namespace. Mirrors POST /:owner/:repo/fork. Returns {owner, repo, url}. Requires 'repo' scope.
gluecron_delete_repo
Permanently delete a repository row (git data on disk is left untouched). Requires 'admin' access on the repo (owner, org owners/admins, admin collaborators) AND 'admin' token scope. Returns {deleted: true}.
gluecron_update_repo
Update repository description / visibility / default_branch. Requires 'admin' access on the repo (owner, org owners/admins, admin collaborators) and 'repo' scope. Returns {ok: true}.
gluecron_search_repos
Search repositories by owner, name, owner/name or description, case-insensitively: every public repo, plus the private ones you own or collaborate on when authenticated. Omit `query` (authenticated) to list YOUR repositories — the ones you own or were invited to — instead of searching. Mirrors GET /api/v2/search/repos. `total` is the full match count (not the page size) and `nextOffset` pages through it.
gluecron_whoami
Who this connector is on this Gluecron instance: the signed-in username and email, whether that account is a site admin, the token's scopes, and how many repositories it owns or collaborates on. Call it first when a repository seems missing — the answer is usually which account authorized the connector. Anonymous callers get authenticated:false and a hint.
gluecron_clone_url
Return the authenticated HTTPS clone URL for a repo + a credential-helper hint. Use this instead of embedding tokens in URLs. Returns {url, owner, repo, defaultBranch, hint} using the repo's stored casing.
gluecron_label_issue
Attach one or more labels to an issue. Labels are created if they don't yet exist on the repo. Requires 'repo' scope. Returns {labels}.
gluecron_unlabel_issue
Detach a label from an issue. Idempotent. Requires 'repo' scope. Returns {removed: boolean}.
gluecron_assign_issue
Assign an issue to a user. Gluecron does not yet have a dedicated assignee table; assignment is modelled as an `assignee:<username>` label so it integrates with existing label tooling. Requires 'repo' scope.
gluecron_search_issues
Search issues by title/body keyword on a single repo, filtered by state. Returns ranked rows.
gluecron_request_changes
Post a 'changes requested' AI-review comment on a PR. The comment is tagged with isAiReview=true so the gate-checker recognises it. Requires 'repo' scope.
gluecron_search_prs
Search pull requests by title/body keyword on a repo.
gluecron_open_draft_pr
Open a draft pull request. Same payload as gluecron_create_pr but forces is_draft=true. Useful for AI-in-progress PRs that shouldn't run mergeability checks yet.
gluecron_generate_pr_description
Generate an AI commit-message-style description for a diff. Uses src/lib/ai-commit-message.ts under the hood; gracefully degrades to a heuristic when ANTHROPIC_API_KEY is missing. Returns {subject, body}.
gluecron_read_file
Read a file from a repo at a given ref. Mirrors GET /api/v2/repos/:owner/:repo/contents/:path. Returns {path, size, content, encoding}.
gluecron_write_file
Create or update a file on a branch via git plumbing. Wraps `createOrUpdateFileOnBranch`. Pass `content` as a UTF-8 string OR `content_base64` for binary. Meets the same branch protection, rulesets and secret scan as a git push, and fires CI/webhooks like one. Requires 'repo' scope.
gluecron_delete_file
Delete a file from a branch via git plumbing. Requires the existing blob sha (optimistic concurrency) and 'repo' scope. Meets the same branch protection, rulesets and secret scan as a git push, and fires CI/webhooks like one. Mirrors DELETE /api/v2/contents.
gluecron_list_tree
List directory contents at a ref. `path` scopes the listing to a subtree and is honoured in BOTH modes; `recursive: true` walks the whole subtree instead of one level. Always returns the same shape: {path, ref, recursive, entries, truncated, totalCount}. Recursive entries carry full repo-relative paths; non-recursive entries carry names. A ref that does not exist is an error, never an empty listing.
gluecron_get_commit
Fetch a single commit by SHA: metadata plus the list of files it changed (path, status, additions, deletions). Mirrors GET /api/v2/repos/.../commits/:sha. Patch bodies are NOT included — use gluecron_get_diff for those.
gluecron_get_diff
Read the actual changes in a commit or a branch range. Pass `sha` for one commit against its first parent, or `base`+`head` for everything head adds since the merge base (what a PR proposes). Returns {files:[{path, oldPath?, status, additions, deletions, binary, patch, patchTruncated}], stats, truncated}. Patch text is byte-capped; set include_patch=false for a files-changed summary only.
gluecron_create_branch
Create a new branch ref pointing at an existing sha. Mirrors POST /api/v2/repos/.../git/refs. Gated like a push of the new branch (rulesets, secret scan of commits no other ref reaches) and fires CI/webhooks. Requires 'repo' scope. Returns {ref, sha}.
gluecron_atomic_multi_file_commit
Apply a set of file writes + deletes as a single atomic commit on a branch (creates the branch if it doesn't exist). The killer agent tool: blob/tree/commit/ref-update sequence. Each change is `{path, content?, content_base64?, deleted?}`. Meets the same branch protection, rulesets and secret scan as a git push, and fires CI/webhooks like one. Requires 'repo' scope.
gluecron_apply_patch
Commit a patch to a branch without sending whole files — the way to change a few lines of a large file. `patch` is a unified diff as `git diff` prints it (one commit, `message` required) OR `git format-patch` mbox output (each patch becomes its own commit with the patch's own message and author, like `git am`; `message` is ignored). Applied server-side with `git apply --cached` against the branch head (created from `base_branch` if missing); `expected_head_sha` makes it compare-and-swap (all zeros = branch must not exist yet). Meets the same branch protection, rulesets and secret scan as a git push, and fires CI/webhooks like one. Patch limit 2 MiB. Requires 'repo' scope. Returns {branch, commit_sha, parent_sha, files_changed, files, commits, created}.
gluecron_ship_spec
Drop a spec file in .gluecron/specs/ with status: ready so the autopilot picks it up. Wraps voice-to-pr.shipAsSpec — handle both voice + manual specs. Requires 'repo' scope.
gluecron_voice_to_pr
Interpret a free-form voice transcript and either ship it as a spec or create an issue (caller picks via `as`). Wraps src/lib/voice-to-pr.ts. Requires 'repo' scope.
gluecron_refactor_across_repos
Plan + execute a refactor that spans multiple repos owned by the caller. Wraps src/lib/multi-repo-refactor.ts. `dry_run: true` returns the plan only. Requires 'repo' scope.
gluecron_explain_repo
Return the cached AI 'explain this codebase' Markdown for a repo. Pure read — never triggers a new generation (use the web UI for that).
gluecron_chat_with_repo
Start a new chat with a repo: creates a chat row, sends the first user message, streams + persists the assistant reply. Returns {chat_id, reply}. If the AI service does not answer this fails with a JSON-RPC error carrying {chat_id, ai_error} — it never returns apology copy as a reply. Requires authentication.
gluecron_chat_continue
Send another message to an existing repo chat. Returns the assistant's reply. If the AI service does not answer this fails with a JSON-RPC error carrying {chat_id, ai_error} rather than returning apology copy as a reply.
gluecron_generate_tests
Generate tests for a PR via Claude. Wraps src/lib/ai-test-generator.generateTestsForPr. Mode 'follow-up-pr' opens a new PR; 'append-commit' commits onto the head branch. Requires 'repo' scope.
gluecron_generate_commit_message
Generate a commit message for a diff. Same engine as gluecron_generate_pr_description but explicit for the commit-message use case.
gluecron_generate_release_notes
Generate release notes between two tags. Wraps src/lib/ai-release-notes.generateReleaseNotes. Returns the rendered Markdown + section data.
gluecron_propose_migration
Propose a dependency-upgrade PR. Wraps src/lib/migration-assistant.proposeMajorMigration. Requires 'repo' scope.
gluecron_propose_doc_update
Manual trigger for the AI doc-update flow: scans tracked sections on the default branch and opens a PR rewriting stale prose. Requires 'repo' scope.
gluecron_trigger_workflow
Dispatch a workflow_dispatch run. Mirrors POST /api/v2/repos/.../actions/workflows/:filename/dispatches. Requires 'repo' scope.
gluecron_get_workflow_run
Fetch a workflow run's metadata + status. Mirrors GET /api/v2/repos/.../actions/runs/:id.
gluecron_list_workflow_runs
List a repository's workflow runs, newest first, with optional branch/status/event filters. Mirrors GET /api/v2/repos/.../actions/runs. The companion to gluecron_get_workflow_run / gluecron_cancel_workflow_run — this is how an agent finds the run ids to inspect or cancel (issue #10493: without it, stale queued runs could not be discovered from the tool surface at all).
gluecron_get_workflow_logs
Return concatenated per-job logs for a workflow run, plus per-job metadata. JSON-friendly companion to the ZIP-download endpoint.
gluecron_cancel_workflow_run
Cancel a queued/running workflow run. Requires 'repo' scope.
gluecron_prioritize_workflow_run
Move a QUEUED workflow run into the priority lane: the runner claims it ahead of the fair-share order across repositories (issue #10898). Only queued runs; a running or finished run is reported, not changed. Requires 'repo' scope and write access.
gluecron_create_runner_registration_token
Create a one-time CI runner registration token for an owner (your username, an org you own or admin, or 'platform' as a site admin). A runner started with RUNNER_REGISTRATION_TOKEN=<token> registers once and gets its own long-lived credential; that owner's CI then runs on it. Expires in an hour. Returns {owner, token, expiresAt, gluecronUrl}.
gluecron_list_runners
List the CI runners registered to an owner (username, org slug, or 'platform'): id, name, url, labels, slots, online, last seen, revoked; allowSharedOverflow (the setting); and sharedLane, whether the owner's jobs actually run on shared runners: 'used (no own runners)', 'overflow allowed' or 'not used (own runners only)', explained in sharedLaneDetail.
gluecron_revoke_runner
Revoke a CI runner by id: nothing is dispatched to it from now on, its next heartbeat is refused and it stops accepting jobs. Cannot be undone — register a new runner instead. Returns {id, revoked}.
gluecron_get_preview_url
Return the branch-preview URL + status for a (repo, branch) pair. Wraps branch-previews.getPreviewForBranch. Returns {ok:false, reason:'not enabled on this host'} when the host has no PREVIEW_DOMAIN (no preview would ever resolve).
gluecron_provision_pr_sandbox
Provision (or re-provision) a sandbox for a PR. Wraps pr-sandbox.provisionSandbox. Requires 'repo' scope. Returns {ok:false, reason:'not enabled on this host'} when no sandbox provisioner runs on the host.
gluecron_create_agent_session
Mint a new agent-multiplayer session. Returns the plaintext `token` exactly once (store it). Requires 'admin' scope.
gluecron_acquire_lease
Grab an exclusive lease on a PR, issue, branch or file path in a repository you can write, for one of your agent sessions. Pass owner+repo with a bare key (PR/issue number, branch name, path), or target_id '<repository id>:<key>'. Returns lease null when another agent holds an active lease.
gluecron_release_lease
Release a lease by id. Idempotent. Returns {released}.
gluecron_get_agent_budget
Return spent / cap / remaining cents for an agent session.
gluecron_semantic_search
Query the per-repo vector index (Voyage embeddings when configured, hash fallback otherwise). Reads the live per-push index (code_embeddings) first, falling back to the manually-reindexed chunk index (code_chunks). Returns {hits, source, indexed, indexedFiles} — `indexed: false` means the repo has never been indexed (empty hits are NOT 'no match'); `indexedFiles` is the live-index row count.
gluecron_search_code
Literal / regex code search (git grep, basic regex) across a repo at a ref. The dependable way to find code on this host — works on every repo, indexed or not. Returns {owner, repo, ref, total, truncated, matches: [{file, line, text}]}. Omit `ref` for the default branch.
gluecron_find_symbol
Find definitions of a symbol by name within a repo. Wraps src/lib/symbols.findDefinitions.
gluecron_pr_status_summary
Compute a one-shot status summary for a PR: state, risk score (and whether it describes the current head), CI state for the head commit as the merge gate sees it, AI-review verdicts (trio), gate signals. Read-only.
gluecron_ci_queue_status
How full the shared CI queue is, and what to do about it: level (ok / busy / saturated), runs queued and running, runner slots, estimated minutes before a new run starts, and — with owner+repo — that repository's queued/running runs, its share of CI work, the slots it may hold while others wait, and a recommendation (e.g. batch changes into fewer pushes). The same `ciQueue` block the write tools return. Ask before a burst of pushes. Read-only.
gluecron_ai_cost_summary
Return AI spend rollups. Scope by one of: user_id (self), repo {owner,repo}, or agent_session_id. Defaults to caller's user spend.
gluecron_security_scan
Everything Gluecron actually knows about a repository's security, in one honest call: OSV.dev CVE/GHSA advisories against the indexed dependency graph (with FIXED VERSIONS), Gluecron's supplemental advisory list, a full-tree committed-secret scan, and optionally a Claude semantic code review. Unlike gluecron_repo_health, an empty result is NEVER reported as a pass: every category returns status 'assessed' | 'partial' | 'not_assessed' | 'error' with a machine-readable reason code, so you can tell 'we checked and it is clean' from 'we never looked'. In particular, a repo whose dependency graph was never indexed returns dependency_advisories.status='not_assessed' (reason 'dependency_graph_not_indexed'), not an empty advisory list. Read-only.