Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for judgevet

Pod holds 9 of 9 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to judgevet.

Most discussed

fix(cli): handled input errors exit 0 from the installed command

Observed on published 0.4.0

The installed CLI reports malformed question JSON on stderr but exits0. A shell pipeline or CI step can therefore treat this failure as success.

Independent reproduction used the exact downloaded PyPI wheel from release verification, SHA256 cc41725f53066430a725116f6c932338c31f7b1e5bbd6602a5bfc533c2344497, through uv tool run --from <wheel> judgevet test '{' --json. The subprocess environment supplied only a dummy JEV_API__KEY for settings. No real key or…

Read the thread · 2026-09-22 · closed · 12 comments

Investigate intermittent first fresh published-launcher probe failure

Observed evidence

The first fresh published uvx launcher probe for0.5.0 raised the sanitized mcp_smoke: transport validation failed error. A separate empty-cache installed help probe succeeded. A new empty-cache transport probe then verified version0.5.0, exactly three tools and all three live calls. No product or configuration change occurred between these checks. STATUS records the same observed sequence during0.4.1 verification.

Command under test: direnv exec uvx…

Read the thread · 2026-09-22 · closed · 3 comments

fix(mcp): server advertises 0.1.0 from the 0.2.0 package

Observed failure

The 0.2.0 workspace MCP server initialized successfully but advertised judgevet-mcp 0.1.0. SERVER_VERSION in the MCP adapter is a hard-coded "0.1.0". Wire evidence; released source.

This issue owns runtime identity, not the broad public-versioning research in #66.

Scope and acceptance

-…

Read the thread · 2026-09-22 · closed · 3 comments

feat(mcp): package and verify a Claude Desktop extension

Deferred outside #165

The user approved deferring this bundle on 2026-09-23. The release uses documented manual Desktop setup with explicit host-evidence limits. This issue is future work, not a prerequisite of #163, #164 or #165. The original proposed acceptance contract below is retained for that future round; its historical release dependency is superseded. #167 tracks testing on another machine.

Outcome

Child of #165, required by the #162 survey and before Desktop onboarding in…

Read the thread · 2026-09-24 · open · 2 comments

fix(mcp): judgevet-mcp collapses every startup and serving failure into one message

Problem

judgevet-mcp reports every startup or serving failure with the same line (src/judgevet/adapters/inbound/mcp_entrypoint.py:141-149):

except (
    JudgevetError,
    OSError,
    RuntimeError,
    ValueError,
    TypeError,
    ExceptionGroup,
):
    raise SystemExit("judgevet-mcp: startup or runtime failure") from None

A credential file that cannot be read, a key command that fails, a bad gateway configuration, a provider factory that returns nothing, a failed…

Read the thread · 2026-09-27 · closed · 1 comment

feat(mcp): give evaluate_policy's policy argument a schema and name unknown fields in errors

Problem

On main, evaluate_policy declares its policy argument as a bare object (src/judgevet/adapters/inbound/mcp_schemas.py:184):

"policy": {"type": "object"},

There is no description and no shape. The tool description (mcp_schemas.py:165) is one line: "Evaluate keyed judgment questions against an acceptance policy." A model building a call has nothing to work from except guessing, and the policy grammar is strict: the root must be exactly {"rules": [...]}, each…

Read the thread · 2026-09-27 · closed · 1 comment

fix(mcp): ask_* tools report missing arguments as JSON-RPC errors (code 0) instead of isError results

Problem

ask_noul, ask_choice and ask_score report a missing argument by raising ValueError from the handler:

The SDK turns the exception into a JSON-RPC protocol error rather than a tool result. Against the published 0.13.0 package, a tools/call to…

Read the thread · 2026-09-27 · closed · 1 comment

fix(mcp): a close() failure after a serving failure hides the serving error's type

Found in the #222 acceptance review (acceptance-reviewer, claude-opus-5-5). Source: https://github.com/Alberto-Codes/judgevet/issues/222#issuecomment-5863581248 and the review note posted on #222.

On the hosted path, _run_hosted in src/judgevet/adapters/inbound/mcp_entrypoint.py calls adapter.close() in a finally. When serving raises and close() also raises, the exception from finally replaces the serving exception. The diagnostic then reads `judgevet-mcp: serving failed…

Read the thread · 2026-09-28 · open · 0 comments

Most recent

fix: a plaintext base_url sends the API key in the clear

base_url is an unvalidated str. Demonstrated:

$ JEV_API__BASE_URL='http://evil.example' python -c '...'
  accepted base_url: http://evil.example
  -> the bearer token would go over cleartext

One environment variable, and every request carries Authorization: Bearer <key> over an unencrypted connection to an attacker-chosen host. Nothing warns, nothing fails.

This matters more than a normal misconfiguration because TYPESAFE_BASE_URL is also accepted as an alias, so an unrelated…

Read the thread · 2026-09-21 · closed · 0 comments

The remaining reports are on the project's issue tracker.