Reported issues for judgevet
Pod holds 9 of 9 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to judgevet.
Most discussed
fix(cli): handled input errors exit 0 from the installed command
Observed on published 0.4.0
The installed CLI reports malformed question JSON on stderr but exits0. A shell pipeline or CI step can therefore treat this failure as success.
Independent reproduction used the exact downloaded PyPI wheel from release verification, SHA256 cc41725f53066430a725116f6c932338c31f7b1e5bbd6602a5bfc533c2344497, through uv tool run --from <wheel> judgevet test '{' --json. The subprocess environment supplied only a dummy JEV_API__KEY for settings. No real key or…
Read the thread · 2026-09-22 · closed · 12 comments
Investigate intermittent first fresh published-launcher probe failure
Observed evidence
The first fresh published uvx launcher probe for0.5.0 raised the sanitized mcp_smoke: transport validation failed error. A separate empty-cache installed help probe succeeded. A new empty-cache transport probe then verified version0.5.0, exactly three tools and all three live calls. No product or configuration change occurred between these checks. STATUS records the same observed sequence during0.4.1 verification.
Command under test: direnv exec
Read the thread · 2026-09-22 · closed · 3 comments
fix(mcp): server advertises 0.1.0 from the 0.2.0 package
Observed failure
The 0.2.0 workspace MCP server initialized successfully but advertised
judgevet-mcp 0.1.0. SERVER_VERSION in the MCP adapter is a hard-coded
"0.1.0". Wire evidence;
released source.
This issue owns runtime identity, not the broad public-versioning research in #66.
Scope and acceptance
-…
Read the thread · 2026-09-22 · closed · 3 comments
feat(mcp): package and verify a Claude Desktop extension
Deferred outside #165
The user approved deferring this bundle on 2026-09-23. The release uses documented manual Desktop setup with explicit host-evidence limits. This issue is future work, not a prerequisite of #163, #164 or #165. The original proposed acceptance contract below is retained for that future round; its historical release dependency is superseded. #167 tracks testing on another machine.
Outcome
Child of #165, required by the #162 survey and before Desktop onboarding in…
Read the thread · 2026-09-24 · open · 2 comments
fix(mcp): judgevet-mcp collapses every startup and serving failure into one message
Problem
judgevet-mcp reports every startup or serving failure with the same line (src/judgevet/adapters/inbound/mcp_entrypoint.py:141-149):
except (
JudgevetError,
OSError,
RuntimeError,
ValueError,
TypeError,
ExceptionGroup,
):
raise SystemExit("judgevet-mcp: startup or runtime failure") from None
A credential file that cannot be read, a key command that fails, a bad gateway configuration, a provider factory that returns nothing, a failed…
Read the thread · 2026-09-27 · closed · 1 comment
feat(mcp): give evaluate_policy's policy argument a schema and name unknown fields in errors
Problem
On main, evaluate_policy declares its policy argument as a bare object (src/judgevet/adapters/inbound/mcp_schemas.py:184):
"policy": {"type": "object"},
There is no description and no shape. The tool description (mcp_schemas.py:165) is one line: "Evaluate keyed judgment questions against an acceptance policy." A model building a call has nothing to work from except guessing, and the policy grammar is strict: the root must be exactly {"rules": [...]}, each…
Read the thread · 2026-09-27 · closed · 1 comment
fix(mcp): ask_* tools report missing arguments as JSON-RPC errors (code 0) instead of isError results
Problem
ask_noul, ask_choice and ask_score report a missing argument by raising ValueError from the handler:
src/judgevet/adapters/inbound/mcp_handlers.py:53-56(handle_ask_noul)src/judgevet/adapters/inbound/mcp_handlers.py:146-149(handle_ask_choice)src/judgevet/adapters/inbound/mcp_handlers.py:249-252(handle_ask_score)
The SDK turns the exception into a JSON-RPC protocol error rather than a tool result. Against the published 0.13.0 package, a tools/call to…
Read the thread · 2026-09-27 · closed · 1 comment
fix(mcp): a close() failure after a serving failure hides the serving error's type
Found in the #222 acceptance review (acceptance-reviewer, claude-opus-5-5). Source: https://github.com/Alberto-Codes/judgevet/issues/222#issuecomment-5863581248 and the review note posted on #222.
On the hosted path, _run_hosted in src/judgevet/adapters/inbound/mcp_entrypoint.py calls adapter.close() in a finally. When serving raises and close() also raises, the exception from finally replaces the serving exception. The diagnostic then reads `judgevet-mcp: serving failed…
Read the thread · 2026-09-28 · open · 0 comments
Most recent
fix: a plaintext base_url sends the API key in the clear
base_url is an unvalidated str. Demonstrated:
$ JEV_API__BASE_URL='http://evil.example' python -c '...'
accepted base_url: http://evil.example
-> the bearer token would go over cleartext
One environment variable, and every request carries
Authorization: Bearer <key> over an unencrypted connection to an
attacker-chosen host. Nothing warns, nothing fails.
This matters more than a normal misconfiguration because TYPESAFE_BASE_URL is
also accepted as an alias, so an unrelated…
Read the thread · 2026-09-21 · closed · 0 comments
The remaining reports are on the project's issue tracker.