code-review-graph is trending because it promises a useful trade: build a persistent local map of a codebase so an AI reviewer reads relevant context instead of ingesting the whole repository. The repository is MIT-licensed and exposes MCP and CLI interfaces.
That can reduce context. It can also create a high-value index of your source tree.
Before connecting any code-intelligence MCP server to an agent, I would make the first integration read-only and prove the boundary with a canary.
Threat model
The assets are not only source files. The graph may reveal:






