AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP unreviewed MIT Self-run

Devops Bot

mcp-xxxxxccc-devops-bot · by xxxxxccc

Chat-driven AI coding agent — discuss requirements in group chat, get automated code changes and pull requests

No reviews yet
0 installs
18 views
0.0% view→install

Install

$ agentstack add mcp-xxxxxccc-devops-bot

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

2 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Destructive filesystem operation.
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Devops Bot? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

DevOps Bot

[](LICENSE) [](https://github.com/xxxxxccc/devops-bot/actions/workflows/pr-check.yml) [](https://github.com/xxxxxccc/devops-bot/actions/workflows/release.yml)

Chat-driven AI coding agent — discuss requirements in group chat, get automated code changes and pull requests.

Supports multiple AI providers (Anthropic, OpenAI, and any OpenAI-compatible API) and multiple IM platforms (Feishu/Lark, Slack).

Architecture

System Overview

flowchart LR
    subgraph im [IM Platform]
        Msg["User Message\n(text + images + links)"]
    end

    subgraph parse [Message Parser]
        Parser["Download attachments\nExtract links\nParse text"]
    end

    subgraph layer1 [Layer 1 - Smart Dispatcher]
        Router["Intent Router AI\n(fast model, single-turn)"]
        Memory["Memory Store"]
    end

    subgraph layer2 [Layer 2 - Executors]
        ChatReply["Chat Reply"]
        MemoryQuery["Memory Query"]
        TaskExec["DevOps Task Executor\n(powerful model, multi-turn + MCP)"]
    end

    Msg -->|"WebSocket / Socket"| Parser
    Parser --> Router
    Router -->|"chat"| ChatReply
    Router -->|"query_memory"| MemoryQuery
    Router -->|"execute_task"| TaskExec
    Router -->|"propose_task"| TaskExec
    Router -->|"create_issue"| TaskExec
    Router -->|"review_pr"| ReviewAI["PR Review AI\n(TASK_MODEL)"]
    Router -->|"add_project / add_workspace"| TaskExec
    Router |"read/write"| Memory
    MemoryQuery |"retrieve"| Memory
    TaskExec -->|"enriched description"| Executor["AIExecutor"]
    ChatReply -->|"reply"| Msg
    MemoryQuery -->|"reply"| Msg
    TaskExec -->|"status update"| Msg
    Executor -->|"task desc + summary"| Memory
    ReviewAI -->|"review result"| Msg
    ReviewAI -->|"review feedback"| Memory

Memory Feedback Loop

flowchart TB
    subgraph input [Task Input]
        TaskDesc["Task Description\n(title + description)"]
        TaskMeta["Task Metadata\n(createdBy, attachments, jira link)"]
    end

    subgraph exec [Task Execution]
        AI["AIExecutor"]
    end

    subgraph output [Task Output]
        Summary["Task Summary\n(thinking + modified_files)"]
        Error["Task Error\n(if failed)"]
    end

    subgraph memory [Memory Store]
        TaskInput_Mem["task_input\n(what was requested)"]
        TaskResult_Mem["task_result\n(what was done)"]
        Decision_Mem["decision\n(extracted decisions)"]
        Issue_Mem["issue\n(discovered issues)"]
    end

    subgraph dedup [Dedup Pipeline]
        HashDedup["Hash Dedup\n(SHA-256)"]
        SemanticDedup["Semantic Dedup\n(LLM: ADD/UPDATE/NOOP/DELETE)"]
        History["Audit History\n(memory_history)"]
    end

    TaskDesc --> AI
    TaskMeta --> AI
    AI --> Summary
    AI --> Error

    TaskDesc -->|"on task created"| TaskInput_Mem
    Summary -->|"on task completed"| TaskResult_Mem
    Summary -->|"AI extract"| Decision_Mem
    Error -->|"AI extract"| Issue_Mem

    TaskInput_Mem --> HashDedup
    TaskResult_Mem --> HashDedup
    Decision_Mem --> HashDedup
    Issue_Mem --> HashDedup
    HashDedup -->|"new"| SemanticDedup
    HashDedup -->|"duplicate"| memory
    SemanticDedup --> History

Three-Tier Task Execution

The dispatcher AI assesses risk level and routes tasks through three tiers:

flowchart TD
  msg["User Message"] --> ai["Dispatcher AI\n(risk assessment)"]
  ai -->|"Low risk"| tier1["Tier 1: execute_task\nImmediate execution"]
  ai -->|"Medium risk"| tier2["Tier 2: propose_task\nIssue + approval"]
  ai -->|"High risk / unclear"| tier3["Tier 3: create_issue\nDiscussion only"]

  tier1 --> exec1["Execute + Create Issue\n+ PR links to Issue"]
  tier2 --> issue2["Create Issue\n(wait for ✅ reaction)"]
  issue2 -->|"Approved"| exec2["Execute Task"]
  tier3 --> issue3["Create Issue\n(human discussion)"]

Tier 1: execute_task (Low Risk)

Executes immediately without human approval. Best for:

  • Copy/text updates, config tweaks
  • Simple bug fixes with clear scope
  • Style adjustments, typo fixes

An Issue is auto-created for tracking, and the resulting PR links to it.

Tier 2: propose_task (Medium Risk)

Creates an Issue and waits for approval before executing. A background poller checks for approval reactions (+1, heart, or hooray) every 30 minutes (configurable via APPROVAL_POLL_INTERVAL_MS). When approved, an independent Issue AI (using the Dispatcher model) reads the full issue discussion and synthesizes a clear, actionable task description -- filtering out meta-discussion and focusing on the latest consensus. The synthesized task is then executed by the Task AI. Used for:

  • New features
  • Refactoring across multiple files
  • Adding dependencies
  • Multi-module changes

External Issue Support

The poller also scans all registered projects for open issues labeled devops-bot (configurable via ISSUE_SCAN_LABELS). Any issue with an approval reaction is processed by the Issue AI the same way. This means users can create issues directly on GitHub/GitLab, label them, and approve them -- no chat interaction required. The bot posts a comment on the issue when execution starts or when it determines the issue is not feasible for automated execution.

Cross-Repo Triage (Workspace Mode)

When workspace context is available, the Issue AI uses a two-phase cross-repo triage flow instead of the default single-phase synthesis:

Phase 1 — Triage: Quality gate + cross-repo routing

  • Assesses if the issue is suitable for automated execution (verdict: actionable / needs_info / reject)
  • Rejects issues with fabricated or hallucinated analysis (common in bot-generated issues)
  • Determines which project(s) in the workspace should handle the issue
  • Uses workspace context (project list + workspace CLAUDE.md)

Phase 2 — Synthesis: Per-repo task content generation

  • Generates a targeted task description for each identified project
  • When the target repo differs from the filing repo, creates a sub-issue in the target repo with a backlink to the original

Three issue discovery paths feed into this flow:

| Path | Source | Description | |------|--------|-------------| | A | Bot-created issues | pending_approvals table — issues created via propose_task | | B | External issues | Project repos scanned for ISSUE_SCAN_LABELS label | | C | Workspace issues | Workspace repo scanned; distributed to sub-projects via triage |

Key behaviors:

  • Without workspace context, the legacy single-phase Issue AI behavior is unchanged
  • Sub-issues created during triage are auto-approved (the original issue's approval covers all targets)
  • The workspace repo itself is never a task target — issues filed there are always distributed to sub-projects

Tier 3: create_issue (High Risk / Unclear)

Creates an Issue for discussion only — no automatic execution. Used for:

  • Architecture changes
  • Vague or open-ended requests
  • Data migrations
  • Breaking API changes

Risk Assessment Criteria

The AI evaluates:

  • Specificity: Is it clear exactly what to change?
  • Scope: How many files/modules are affected?
  • Reversibility: Can it be easily reverted?
  • Breaking potential: Could it break existing functionality?
  • Design decisions: Are there multiple valid approaches?

PR Review

AI-powered code review that provides both high-level summary and line-level comments on pull requests. Uses the TASK_MODEL for review analysis.

Trigger Modes

| Trigger | How it works | IM Notification | |---------|-------------|-----------------| | Self-review | Automatically reviews bot-created PRs after task completion (ENABLE_SELF_REVIEW=true). If critical/warning issues are found, triggers an auto-fix loop (up to 2 rounds) that pushes fixes to the same PR branch and re-reviews. | Yes (originating chat) | | IM command | User sends "review PR #123" in chat → review_pr intent | Yes (originating chat) | | Polling | Background poller scans registered projects for open PRs (REVIEW_TRIGGER_MODE=polling, default) | No (GitHub PR comment only) | | Webhook | GitHub webhook on PR open/update (REVIEW_TRIGGER_MODE=webhook) | No (GitHub PR comment only) |

Memory Isolation

Review memories are stored in a separate review namespace to avoid polluting task context. Two review-specific memory types are used:

  • review_feedback — per-PR review results
  • review_pattern — recurring patterns extracted across reviews

When ENABLE_REVIEW_CROSS_INJECT=true, review_pattern memories are selectively injected into task dispatcher context, creating a feedback loop where common review findings improve future code generation.

Auto-Fix Loop (Self-Review Only)

When self-review detects critical or warning issues, it automatically attempts to fix them:

  1. Review — ReviewEngine analyzes the PR, posts GitHub review comments
  2. Fix — Creates a sandbox on the existing PR branch, AI fixes critical/warning issues, pushes to the same branch
  3. Re-review — Reviews the fixed PR again; if issues remain, repeats step 2
  4. Max 2 rounds — Hard limit prevents infinite loops; after 2 fix rounds, stops regardless of remaining issues

Safety measures:

  • Verifies PR is still open before each fix attempt (skips if merged/closed)
  • Fetches full PR discussion context (issue comments + review summaries) as additional fix context
  • Only triggers for self-review (bot-created PRs); external reviews only post comments

Controlled by ENABLE_SELF_REVIEW=true — no additional configuration needed.

Workspace Mode

Instead of registering individual projects one by one, you can register a single workspace meta-repo that describes all your organization's projects. The dispatcher AI reads the manifest and selects the correct sub-project per task, cloning on demand.

Setup

  1. Create a workspace.json in your workspace repo root:
{
  "defaultBranch": "dev",
  "projects": [
    {
      "id": "my-app",
      "gitUrl": "git@github.com:org/my-app.git",
      "branch": "dev",
      "lang": "TypeScript",
      "description": "Main web application"
    },
    {
      "id": "my-api",
      "gitUrl": "git@github.com:org/my-api.git",
      "branch": "dev",
      "lang": "Go",
      "description": "Backend API service"
    }
  ]
}
  1. Optionally add a CLAUDE.md with development guidelines, conventions, and project relationships — injected into the dispatcher AI as context.
  1. In chat, say: add workspace https://github.com/org/my-workspace

How It Works

  • The dispatcher AI sees all sub-projects from the manifest and workspace guidelines
  • When a task targets a sub-project, the system clones it on demand (lazy)
  • Sub-projects are registered in the same projects table, reusing all existing task/review/approval infrastructure
  • The workspace's branch field overrides auto-detected default branches (e.g. dev instead of main)
  • Already-cloned sub-projects are synced, not re-cloned

Workspace vs Multi-Project

| Mode | Registration | When to use | |------|-------------|-------------| | Single-project | TARGET_PROJECT_PATH env var | One repo, simple setup | | Multi-project | add project per repo | Few repos, manual control | | Workspace | add workspace once | Many repos, org-wide AI agent |

Features

  • Multi-provider AI: Anthropic (Claude), OpenAI, or any OpenAI-compatible API (DeepSeek, Groq, Together, etc.)
  • Multi-platform IM: Feishu/Lark (WebSocket) or Slack (Socket Mode) — no public IP needed
  • Two-Layer AI: Fast model routes intents, powerful model executes tasks — cost optimized
  • Project Memory: AI remembers decisions, context, and past work — with semantic dedup (LLM-driven), change audit trail, periodic pruning, and per-project custom extraction
  • Sandbox Execution: Tasks run in isolated Git worktree sandboxes, changes submitted as Draft PRs
  • Parallel Execution: Per-project serial, cross-project parallel task execution (configurable concurrency)
  • Multi-Project: Manage multiple git repositories from a single chat group
  • Workspace Mode: Register a workspace meta-repo (workspace.json) to manage all org sub-projects from one entry point, with on-demand cloning
  • GitHub App Auth: Secure authentication via GitHub App (replaces PAT)
  • Three-Tier Tasks: AI-driven risk assessment routes tasks through execute/propose/issue tiers
  • PR Review: AI code review with self-review (+ auto-fix loop), IM command, polling, and webhook triggers
  • Jira Integration: Auto-fetch issue details when Jira link detected
  • Figma Integration: Fetch design context from Figma links
  • File Attachments: Screenshots and files from IM messages are passed to Task AI

Prerequisites

| Dependency | Required | Purpose | |-----------|----------|---------| | Node.js ≥ 18 or Bun | Yes | Runtime environment | | git | Yes | Repository management, branch/commit/push operations | | curl or wget | Yes | Download release artifacts during install | | Python 3 | Recommended | Required by node-gyp to compile native modules (better-sqlite3, node-pty) | | make + gcc/g++ | Recommended | C/C++ build toolchain for native modules |

Install commands by platform

Debian / Ubuntu

sudo apt update && sudo apt install -y git curl python3 make g++
# Node.js (via NodeSource)
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs

RHEL / Amazon Linux

sudo yum install -y git curl python3 make gcc-c++
# Node.js (via NodeSource)
curl -fsSL https://rpm.nodesource.com/setup_22.x | sudo bash -
sudo yum install -y nodejs

macOS

# Xcode command line tools (includes git, make, clang)
xcode-select --install
# Node.js (via Homebrew)
brew install node

Any platform (via nvm)

curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.3/install.sh | bash
nvm install 22

> Note: Pre-built binaries for native modules are bundled in release artifacts. > Python and build tools are only needed if pre-built binaries are unavailable for your platform.

Quick Start

Option 1: One-line Install (Recommended)

# Interactive mode (recommended for first-time setup)
bash  **Note:** The interactive mode (`bash  as it guides you through AI provider, project path, and IM platform configuration.
> The piped mode (`curl ... | bash`) will install with defaults and skip the setup wizard.

The installer will:
- Download the latest pre-built release from GitHub
- Detect your runtime (Node.js ≥ 18 or Bun)
- Guide you to configure AI provider, project path, and IM platform (interactive mode)
- Optionally configure Jira, Figma, and local vector search
- Set up `devops-bot` command globally

Then start:
```bash
devops-bot start

Upgrade anytime:

devops-bot upgrade

Option 2: Manual Install (Development)

git clone https://github.com/xxxxxccc/devops-bot.git
cd devops-bot
pnpm install
cp .env.example .env.local

Edit .env.local:

# Single-project mode (backward compatible):
# TARGET_PROJECT_PATH=/path/to/your/project

# Multi-project mode: projects added via chat ("add project ")
# Workspace mode: "add workspace " for meta-repo with workspace.json
# No TARGET_PROJECT_PATH needed

# GitHub App (recommended for GitHub repos):
# GITHUB_APP_ID=123456
# GITHUB_APP_PRIVATE_KEY_PATH=/path/to/private-key.pem

# AI provider: anthropic | openai (default: anthropic)
# AI_PROVIDER=anthropic
AI_API_KEY=your-api-key

# IM platform: feishu | slack (default: feishu)
# IM_PLATFORM=feishu

# Feishu
FEISHU_APP_ID=your-feishu-app-id
FEISHU_APP_SECRET=your-feishu-app-secret

# Or Slack
# SLACK_BOT_TOKEN=xoxb-...
# SLACK_APP_TOKEN=xapp-...

Build and start:

pnpm build
pnpm start

Prerequisites

  1. AI API Key — pick one:

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.