Orangepro MCP agent

OrangePro local-first CLI + MCP server for behavior mapping, grounded test generation, and dynamic proof.

by OrangeproAI·MIT license·★ 18 Stars on the repo·GitHub ↗

Files of Orangepro MCP

OrangeproAI/main1 file
README.md
Show the full text399 lines

OrangePro

Find the behaviors your tests miss. Generate grounded tests that actually run.

npm version MIT License npm downloads Glama score MCP Registry


OrangePro maps every public behavior in your codebase, scores each one by real test evidence, and shows you the structural blind spots before your users find them. Runs locally. Your code never leaves your machine.

npx -y @orangepro/mcp-server@latest start .

Table of Contents


What you get

One command produces an interactive HTML report:

npx -y @orangepro/mcp-server@latest start .
open .orangepro/behavior-coverage.html

The report has two modes: Simple (integration-level blind spots, plain English) and Expert (full behavior list, evidence tiers, flows, system map). Toggle with the pill switch at the top.

→ Live example: Twenty CRM (5,237 behaviors mapped)

OrangePro system map — entry lanes, services, evidence tiers

System map — entry lanes (GraphQL, HTTP, Jobs) flowing into services, sized by traffic, colored by evidence tier, red-ringed by risk.

Priority gaps

Priority gaps of another open source Project HONO — top 20 unproven behaviors ranked by blast radius, with generated test drafts.


Evidence tiers

Every behavior gets exactly one tier. Nothing is labeled "tested" on faith.

Tier Color What it means
Dynamically Proven 🟢 A real test kills a targeted mutation of this behavior
Runtime-covered 🟢 Coverage tool executed this code
Statically Linked 🟡 A test imports and calls this code — structural link, not proof
Unconfirmed Candidate ⚪ A similar test file exists — a lead, not evidence
No Signal 🔴 Nothing tests this behavior

"Dynamically Proven 0" is normal on first run. Proof requires running tests against targeted mutations. That's the trust model.


Quick start

cd /path/to/your/repo
npm install          # install the repo's own dependencies first

npx -y @orangepro/mcp-server@latest start .
open .orangepro/behavior-coverage.html

No API key needed. The report shows your system map, evidence tiers, priority gaps, and delta since last run.

Want test generation? Add a model key (BYOK):

export ANTHROPIC_API_KEY="..."   # or OPENAI_API_KEY / OLLAMA_BASE_URL
npx -y @orangepro/mcp-server@latest start .

AI output never changes evidence tiers. Only the mutation-kill oracle can mint Dynamically Proven.

Output:

.orangepro/
├── behavior-coverage.html   ← open this
├── graph.json               ← deterministic evidence graph
├── COVERAGE_REPORT.md       ← coverage and gap summary
└── ai/                      ← candidate flows (when a key is configured)

orangepro_generated/         ← generated tests; your source files are never touched

Each rerun shows a delta banner: what entered the codebase, what moved up in risk, what got resolved.


Use with your coding agent

OrangePro runs as an MCP server. Add to your client's config:

{
  "mcpServers": {
    "orangepro-local": {
      "command": "npx",
      "args": ["-y", "@orangepro/mcp-server@latest", "mcp"]
    }
  }
}
Client Where to put it
Claude Code .mcp.json or ~/.claude.json
Cursor ~/.cursor/mcp.json or Settings → MCP
VS Code / Copilot MCP settings
Codex / OpenCode Run npx -y @orangepro/mcp-server@latest agent --client codex

The workflow: Tell your agent:

"Use orangepro_start, then orangepro_generate_tests with base_ref=main. Write each test to its suggested_path, run it, and report pass/fail."

The agent writes the test, runs it, calls orangepro_prove, and the behavior turns Dynamically Proven. One prompt, full loop.


Works with

Claude Code · Cursor · GitHub Copilot · Codex · Windsurf · OpenCode · VS Code

Any MCP-compatible agent can drive OrangePro. No vendor lock-in.


How it works

┌─────────────┐     ┌──────────────┐     ┌─────────────┐
│  Your Code  │ ──► │  Knowledge   │ ──► │  Evidence   │
│  (any lang) │     │    Graph     │     │   Tiers     │
└─────────────┘     └──────────────┘     └─────────────┘
                           │
                    ┌──────┴──────┐
                    ▼             ▼
             ┌───────────┐  ┌──────────┐
             │ Gap Report│  │ Generate │
             │ + Risks   │  │  Tests   │
             └───────────┘  └──────────┘
Phase What happens Needs a model key?
Analyze AST walk → behaviors, flows, evidence tiers No
Score Graph readiness score (0–100) No
Generate Grounded tests for top gaps Yes (BYOK)
Prove Mutation-kill oracle confirms test breaks if behavior changes No

Same code = same score. Deterministic. Always.


Language support

Language Static mapping Generated tests Dynamic proof
TypeScript / JavaScript ✓ ✓ Jest / Vitest / Mocha ✓
Python ✓ ✓ pytest ✓
Go ✓ ✓ *_test.go ✓
Java ✓ ✓ JUnit 4/5 ✓
Kotlin, Rust, PHP, C#, Ruby, Swift, C, C++ ✓ planned planned

Static mapping works across many languages via tree-sitter. Dynamic proof is deliberately narrower — each language needs a runner, mutation locator, and sandbox profile.


Highest-value local run

Use the repository's own setup and test commands first, and keep unit and integration coverage in separate artifacts. Then run opro start; it performs analysis, ingests the artifacts, attempts targeted proof, generates report-visible drafts, and writes the final report. A separate opro analyze is unnecessary when opro start follows it.

# 1. Install/build exactly as the repository documents.
# 2. Run the repository's unit and integration coverage commands separately.
# 3. Record artifact provenance (example paths and commands):
mkdir -p .orangepro
# create .orangepro/coverage-suites.json using the schema below

opro coverage .                    # optional preflight: discover/generate artifacts
opro start . --proof-limit 5 --generate-limit 20
{
  "artifacts": {
    ".orangepro/coverage/unit.coverprofile": {
      "suite": "unit",
      "command": "make unit-test-coverage"
    },
    ".orangepro/coverage/integration.coverprofile": {
      "suite": "integration",
      "command": "make integration-test-coverage"
    }
  }
}

Without this manifest, OrangePro conservatively infers clear unit/integration names and labels everything else unclassified; it never guesses that an aggregate profile is unit-only. The report shows unit, integration, their overlap, unclassified coverage, and the combined union separately. --proof-limit controls dynamic proof attempts (which may draft a test for proof); --generate-limit independently controls the additional report-visible risk-gap drafting lane. A generation run also records its terminal status and exact reason, so a compiler/import failure is not misreported as a generic dependency problem.


Privacy

  • No stored source. Reads code in-process. Never uploads to an OrangePro server.
  • No existing-source mutation. Never edits your source or test files.
  • Your keys stay yours. Read from env at call time, never persisted.
  • BYOK is direct. Code context goes to the model provider you configure. OrangePro is not in that path.

CLI reference
opro                          # analyze + report + agent next actions
opro start --base main        # same, scoped to a branch diff
opro analyze                  # build the evidence graph
opro score                    # graph readiness (0–100)
opro gaps --limit 10          # top 10 untested behaviors
opro generate --base main     # tests for PR diff
opro generate --single        # top gap, whole repo
opro prove                    # mutation-kill oracle
opro rtm                      # traceability matrix
opro export                   # metadata-only evidence pack
opro mcp                      # run as MCP server (stdio)
opro doctor                   # what evidence to add next
opro coverage                 # discover/generate artifacts; analyze or start ingests them

Add --json to any read command for machine output. Run opro help for the full reference.

MCP tools (18 total)
Tool What it does
orangepro_start One-command setup: analyze + report + next actions
orangepro_analyze_sources Build/refresh the evidence graph
orangepro_generate_tests Generate grounded tests for gaps
orangepro_prove Run mutation-kill oracle on a behavior
orangepro_prove_loop Setup + dynamic proof + report refresh for one behavior
orangepro_find_test_gaps List behaviors with weak/missing tests, ranked by risk
orangepro_graph_score Graph readiness score (0–100)
orangepro_status Workspace state without generating anything
orangepro_doctor Recommend next evidence to improve quality
orangepro_rtm Requirements traceability matrix
orangepro_stats Aggregate statistics
orangepro_changed_impact What a diff touches (requires git + base ref)
orangepro_record_run Record a test run result
orangepro_explain_test Explain why a test was generated
orangepro_export_evidence_pack Export metadata-only evidence pack
orangepro_update_graph Incremental graph update
orangepro_ai_links Weak behavior→symbol suggestions (optional AI)
orangepro_ai_flows Candidate flow discovery (optional AI)
PR workflow
opro generate --base main              # tests for what this branch changed
opro generate --pr 1234                # checks out PR #1234
opro generate --changed                # current branch diff vs main

Each generated test includes:

  • Grounding — the real files, symbols, and existing tests it cites
  • Run hints — where to write it, how to run it
  • Scenario bucket — what failure mode it targets

If dependencies aren't installed, tests are kept as Manual tests (Given/When/Then steps with the blocker named). Install dependencies and re-run to convert them to runnable tests.

Test categories

Generation is evidence-gated. A category is produced only when the graph has supporting evidence.

Category What it targets
Happy path Primary expected behavior
Validation error Bad/invalid input handling
Edge case Boundaries, empty/null, concurrency, retries
Integration flow Multi-step behavior across services
Security / privacy Auth, injection, data leakage
Regression Pinning a previously-broken behavior
Model setup (BYOK)

Analysis, scoring, and proof need no model key. Generation does.

Provider Environment variable
OpenAI-compatible OPENAI_API_KEY (optional: OPENAI_BASE_URL, OPENAI_MODEL)
Anthropic ANTHROPIC_API_KEY (optional: ANTHROPIC_MODEL)
Ollama (local, no key) OLLAMA_BASE_URL (optional: OLLAMA_MODEL)

Auto-detect order: OpenAI → Ollama → Anthropic. Override with --provider and --model. The defaults are gpt-5.3-codex for OpenAI and claude-sonnet-5 for Anthropic.

Run opro setup to configure interactively. Keys stay in your environment — never written to graph, config, or artifacts.

AI candidate lanes

With a provider key, OrangePro stages weak AI behavior→symbol links and AI-suggested candidate flows. These are review/generation worklists, not evidence:

  • AI links appear as AI-linked suggestions.
  • AI flows are stored separately from deterministic flows.
  • Neither lane changes evidence tiers or denominator counts.

Use them when you want the agent to find likely service-boundary flows faster; ignore them for a deterministic-only report.


What's on the hosted platform

This repo is the free local tool. The OrangePro platform adds:

  • Persistent knowledge graph across PRs and repos
  • PR/CI policy gates over evidence tiers and risk deltas
  • Jira / Confluence / TestRail / OpenAPI enrichment
  • Cross-repo intelligence and recurring-flow memory
  • Production incident correlation and regression targeting
  • Team dashboards and test lifecycle management

Contributing

git clone https://github.com/OrangeproAI/orangepro-mcp.git
cd orangepro-mcp && npm ci && npm run build
npm test

PRs welcome. Please open an issue first for large changes.


MIT License · orangepro.ai

1<p align="center">
2 <img src="https://github.com/OrangeproAI/orangepro-mcp/raw/main/docs/logo-horizontal.svg" alt="OrangePro" width="320" />
3</p>
4 
5<p align="center">
6 <strong>Find the behaviors your tests miss. Generate grounded tests that actually run.</strong>
7</p>
8 
9<p align="center">
10 <a href="https://www.npmjs.com/package/@orangepro/mcp-server"><img src="https://badge.fury.io/js/@orangepro%2Fmcp-server.svg" alt="npm version" /></a>
11 <a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-green.svg" alt="MIT License" /></a>
12 <a href="https://www.npmjs.com/package/@orangepro/mcp-server"><img src="https://img.shields.io/npm/dw/@orangepro/mcp-server.svg" alt="npm downloads" /></a>
13 <a href="https://glama.ai/mcp/servers/OrangeproAI/orangepro-mcp"><img src="https://glama.ai/mcp/servers/OrangeproAI/orangepro-mcp/badges/score.svg" alt="Glama score" /></a>
14 <a href="https://registry.modelcontextprotocol.io/?q=orangepro"><img src="https://img.shields.io/badge/MCP_Registry-orangepro-orange.svg" alt="MCP Registry" /></a>
15</p>
16 
17---
18 
19OrangePro maps every public behavior in your codebase, scores each one by real test evidence, and shows you the structural blind spots before your users find them. Runs locally. Your code never leaves your machine.
20 
21```bash
22npx -y @orangepro/mcp-server@latest start .
23```
24 
25<!-- TODO: Replace with a terminal GIF showing the command running and report opening -->
26 
27---
28 
29## Table of Contents
30 
31- [What you get](#what-you-get)
32- [Evidence tiers](#evidence-tiers)
33- [Quick start](#quick-start)
34- [Use with your coding agent](#use-with-your-coding-agent)
35- [How it works](#how-it-works)
36- [Language support](#language-support)
37- [Privacy](#privacy)
38- [CLI reference](#cli-reference)
39- [MCP tools](#mcp-tools-18-total)
40- [Platform](#whats-on-the-hosted-platform)
41- [Contributing](#contributing)
42 
43---
44 
45## What you get
46 
47One command produces an interactive HTML report:
48 
49```bash
50npx -y @orangepro/mcp-server@latest start .
51open .orangepro/behavior-coverage.html
52```
53The report has two modes: **Simple** (integration-level blind spots, plain English) and **Expert** (full behavior list, evidence tiers, flows, system map). Toggle with the pill switch at the top.
54 
55**<a href="https://orangeproai.github.io/orangepro-mcp/twenty-crm-behavior-coverage.html" target="_blank">→ Live example: Twenty CRM (5,237 behaviors mapped)</a>**
56 
57<img width="895" alt="OrangePro system map — entry lanes, services, evidence tiers" src="https://github.com/user-attachments/assets/1ceba779-e0ec-4ec1-99ce-001bc3589b42](https://github.com/user-attachments/assets/a4d85b98-4f19-4647-8dd9-db5911574f49" />
58 
59*System map — entry lanes (GraphQL, HTTP, Jobs) flowing into services, sized by traffic, colored by evidence tier, red-ringed by risk.*
60 
61 
62<img width="818" alt="Priority gaps" src="https://github.com/user-attachments/assets/30a512b6-7830-48db-a00f-a616e7176ea8" />
63 
64*Priority gaps of another open source Project HONO — top 20 unproven behaviors ranked by blast radius, with generated test drafts.*
65 
66---
67 
68## Evidence tiers
69 
70Every behavior gets exactly one tier. Nothing is labeled "tested" on faith.
71 
72| Tier | Color | What it means |
73|------|-------|---------------|
74| **Dynamically Proven** | 🟢 | A real test kills a targeted mutation of this behavior |
75| **Runtime-covered** | 🟢 | Coverage tool executed this code |
76| **Statically Linked** | 🟡 | A test imports and calls this code — structural link, not proof |
77| **Unconfirmed Candidate** | ⚪ | A similar test file exists — a lead, not evidence |
78| **No Signal** | 🔴 | Nothing tests this behavior |
79 
80> **"Dynamically Proven 0" is normal on first run.** Proof requires running tests against targeted mutations. That's the trust model.
81 
82---
83 
84## Quick start
85 
86```bash
87cd /path/to/your/repo
88npm install # install the repo's own dependencies first
89 
90npx -y @orangepro/mcp-server@latest start .
91open .orangepro/behavior-coverage.html
92```
93 
94No API key needed. The report shows your system map, evidence tiers, priority gaps, and delta since last run.
95 
96**Want test generation?** Add a model key (BYOK):
97 
98```bash
99export ANTHROPIC_API_KEY="..." # or OPENAI_API_KEY / OLLAMA_BASE_URL
100npx -y @orangepro/mcp-server@latest start .
101```
102 
103AI output never changes evidence tiers. Only the mutation-kill oracle can mint Dynamically Proven.
104 
105**Output:**
106 
107```
108.orangepro/
109├── behavior-coverage.html ← open this
110├── graph.json ← deterministic evidence graph
111├── COVERAGE_REPORT.md ← coverage and gap summary
112└── ai/ ← candidate flows (when a key is configured)
113 
114orangepro_generated/ ← generated tests; your source files are never touched
115```
116 
117Each rerun shows a **delta banner**: what entered the codebase, what moved up in risk, what got resolved.
118 
119---
120 
121## Use with your coding agent
122 
123OrangePro runs as an MCP server. Add to your client's config:
124 
125```json
126{
127 "mcpServers": {
128 "orangepro-local": {
129 "command": "npx",
130 "args": ["-y", "@orangepro/mcp-server@latest", "mcp"]
131 }
132 }
133}
134```
135 
136| Client | Where to put it |
137| --- | --- |
138| Claude Code | `.mcp.json` or `~/.claude.json` |
139| Cursor | `~/.cursor/mcp.json` or Settings → MCP |
140| VS Code / Copilot | MCP settings |
141| Codex / OpenCode | Run `npx -y @orangepro/mcp-server@latest agent --client codex` |
142 
143**The workflow:** Tell your agent:
144 
145> "Use `orangepro_start`, then `orangepro_generate_tests` with base_ref=main. Write each test to its suggested_path, run it, and report pass/fail."
146 
147The agent writes the test, runs it, calls `orangepro_prove`, and the behavior turns Dynamically Proven. One prompt, full loop.
148 
149---
150 
151## Works with
152 
153<p>
154 <strong>Claude Code</strong> · <strong>Cursor</strong> · <strong>GitHub Copilot</strong> · <strong>Codex</strong> · <strong>Windsurf</strong> · <strong>OpenCode</strong> · <strong>VS Code</strong>
155</p>
156 
157Any MCP-compatible agent can drive OrangePro. No vendor lock-in.
158 
159---
160 
161## How it works
162 
163```
164┌─────────────┐ ┌──────────────┐ ┌─────────────┐
165│ Your Code │ ──► │ Knowledge │ ──► │ Evidence │
166│ (any lang) │ │ Graph │ │ Tiers │
167└─────────────┘ └──────────────┘ └─────────────┘
168 │
169 ┌──────┴──────┐
170 ▼ ▼
171 ┌───────────┐ ┌──────────┐
172 │ Gap Report│ │ Generate │
173 │ + Risks │ │ Tests │
174 └───────────┘ └──────────┘
175```
176 
177| Phase | What happens | Needs a model key? |
178|-------|-------------|-------------------|
179| **Analyze** | AST walk → behaviors, flows, evidence tiers | No |
180| **Score** | Graph readiness score (0–100) | No |
181| **Generate** | Grounded tests for top gaps | Yes (BYOK) |
182| **Prove** | Mutation-kill oracle confirms test breaks if behavior changes | No |
183 
184Same code = same score. Deterministic. Always.
185 
186---
187 
188## Language support
189 
190| Language | Static mapping | Generated tests | Dynamic proof |
191|----------|:-:|:-:|:-:|
192| TypeScript / JavaScript | ✓ | ✓ Jest / Vitest / Mocha | ✓ |
193| Python | ✓ | ✓ pytest | ✓ |
194| Go | ✓ | ✓ `*_test.go` | ✓ |
195| Java | ✓ | ✓ JUnit 4/5 | ✓ |
196| Kotlin, Rust, PHP, C#, Ruby, Swift, C, C++ | ✓ | planned | planned |
197 
198Static mapping works across many languages via tree-sitter. Dynamic proof is deliberately narrower — each language needs a runner, mutation locator, and sandbox profile.
199 
200---
201 
202## Highest-value local run
203 
204Use the repository's own setup and test commands first, and keep unit and integration
205coverage in separate artifacts. Then run `opro start`; it performs analysis, ingests
206the artifacts, attempts targeted proof, generates report-visible drafts, and writes the
207final report. A separate `opro analyze` is unnecessary when `opro start` follows it.
208 
209```bash
210# 1. Install/build exactly as the repository documents.
211# 2. Run the repository's unit and integration coverage commands separately.
212# 3. Record artifact provenance (example paths and commands):
213mkdir -p .orangepro
214# create .orangepro/coverage-suites.json using the schema below
215 
216opro coverage . # optional preflight: discover/generate artifacts
217opro start . --proof-limit 5 --generate-limit 20
218```
219 
220```json
221{
222 "artifacts": {
223 ".orangepro/coverage/unit.coverprofile": {
224 "suite": "unit",
225 "command": "make unit-test-coverage"
226 },
227 ".orangepro/coverage/integration.coverprofile": {
228 "suite": "integration",
229 "command": "make integration-test-coverage"
230 }
231 }
232}
233```
234 
235Without this manifest, OrangePro conservatively infers clear `unit`/`integration` names
236and labels everything else `unclassified`; it never guesses that an aggregate profile is
237unit-only. The report shows unit, integration, their overlap, unclassified coverage, and
238the combined union separately. `--proof-limit` controls dynamic proof attempts (which
239may draft a test for proof); `--generate-limit` independently controls the additional
240report-visible risk-gap drafting lane. A generation run
241also records its terminal status and exact reason, so a compiler/import failure is not
242misreported as a generic dependency problem.
243 
244---
245 
246## Privacy
247 
248- **No stored source.** Reads code in-process. Never uploads to an OrangePro server.
249- **No existing-source mutation.** Never edits your source or test files.
250- **Your keys stay yours.** Read from env at call time, never persisted.
251- **BYOK is direct.** Code context goes to the model provider you configure. OrangePro is not in that path.
252 
253---
254 
255<details>
256<summary><strong>CLI reference</strong></summary>
257 
258```bash
259opro # analyze + report + agent next actions
260opro start --base main # same, scoped to a branch diff
261opro analyze # build the evidence graph
262opro score # graph readiness (0–100)
263opro gaps --limit 10 # top 10 untested behaviors
264opro generate --base main # tests for PR diff
265opro generate --single # top gap, whole repo
266opro prove # mutation-kill oracle
267opro rtm # traceability matrix
268opro export # metadata-only evidence pack
269opro mcp # run as MCP server (stdio)
270opro doctor # what evidence to add next
271opro coverage # discover/generate artifacts; analyze or start ingests them
272```
273 
274Add `--json` to any read command for machine output. Run `opro help` for the full reference.
275 
276</details>
277 
278<details>
279<summary><strong>MCP tools (18 total)</strong></summary>
280 
281| Tool | What it does |
282|------|--------------|
283| `orangepro_start` | One-command setup: analyze + report + next actions |
284| `orangepro_analyze_sources` | Build/refresh the evidence graph |
285| `orangepro_generate_tests` | Generate grounded tests for gaps |
286| `orangepro_prove` | Run mutation-kill oracle on a behavior |
287| `orangepro_prove_loop` | Setup + dynamic proof + report refresh for one behavior |
288| `orangepro_find_test_gaps` | List behaviors with weak/missing tests, ranked by risk |
289| `orangepro_graph_score` | Graph readiness score (0–100) |
290| `orangepro_status` | Workspace state without generating anything |
291| `orangepro_doctor` | Recommend next evidence to improve quality |
292| `orangepro_rtm` | Requirements traceability matrix |
293| `orangepro_stats` | Aggregate statistics |
294| `orangepro_changed_impact` | What a diff touches (requires git + base ref) |
295| `orangepro_record_run` | Record a test run result |
296| `orangepro_explain_test` | Explain why a test was generated |
297| `orangepro_export_evidence_pack` | Export metadata-only evidence pack |
298| `orangepro_update_graph` | Incremental graph update |
299| `orangepro_ai_links` | Weak behavior→symbol suggestions (optional AI) |
300| `orangepro_ai_flows` | Candidate flow discovery (optional AI) |
301 
302</details>
303 
304<details>
305<summary><strong>PR workflow</strong></summary>
306 
307```bash
308opro generate --base main # tests for what this branch changed
309opro generate --pr 1234 # checks out PR #1234
310opro generate --changed # current branch diff vs main
311```
312 
313Each generated test includes:
314- **Grounding** — the real files, symbols, and existing tests it cites
315- **Run hints** — where to write it, how to run it
316- **Scenario bucket** — what failure mode it targets
317 
318If dependencies aren't installed, tests are kept as **Manual tests** (Given/When/Then steps with the blocker named). Install dependencies and re-run to convert them to runnable tests.
319 
320</details>
321 
322<details>
323<summary><strong>Test categories</strong></summary>
324 
325Generation is evidence-gated. A category is produced only when the graph has supporting evidence.
326 
327| Category | What it targets |
328|----------|-----------------|
329| Happy path | Primary expected behavior |
330| Validation error | Bad/invalid input handling |
331| Edge case | Boundaries, empty/null, concurrency, retries |
332| Integration flow | Multi-step behavior across services |
333| Security / privacy | Auth, injection, data leakage |
334| Regression | Pinning a previously-broken behavior |
335 
336</details>
337 
338<details>
339<summary><strong>Model setup (BYOK)</strong></summary>
340 
341Analysis, scoring, and proof need no model key. Generation does.
342 
343| Provider | Environment variable |
344|----------|---------------------|
345| OpenAI-compatible | `OPENAI_API_KEY` (optional: `OPENAI_BASE_URL`, `OPENAI_MODEL`) |
346| Anthropic | `ANTHROPIC_API_KEY` (optional: `ANTHROPIC_MODEL`) |
347| Ollama (local, no key) | `OLLAMA_BASE_URL` (optional: `OLLAMA_MODEL`) |
348 
349Auto-detect order: OpenAI → Ollama → Anthropic. Override with `--provider` and `--model`.
350The defaults are `gpt-5.3-codex` for OpenAI and `claude-sonnet-5` for Anthropic.
351 
352Run `opro setup` to configure interactively. Keys stay in your environment — never written to graph, config, or artifacts.
353 
354</details>
355 
356<details>
357<summary><strong>AI candidate lanes</strong></summary>
358 
359With a provider key, OrangePro stages weak AI behavior→symbol links and AI-suggested candidate flows. These are review/generation worklists, not evidence:
360 
361- AI links appear as `AI-linked` suggestions.
362- AI flows are stored separately from deterministic flows.
363- Neither lane changes evidence tiers or denominator counts.
364 
365Use them when you want the agent to find likely service-boundary flows faster; ignore them for a deterministic-only report.
366 
367</details>
368 
369---
370 
371## What's on the hosted platform
372 
373This repo is the free local tool. The [OrangePro platform](https://orangepro.ai) adds:
374 
375- Persistent knowledge graph across PRs and repos
376- PR/CI policy gates over evidence tiers and risk deltas
377- Jira / Confluence / TestRail / OpenAPI enrichment
378- Cross-repo intelligence and recurring-flow memory
379- Production incident correlation and regression targeting
380- Team dashboards and test lifecycle management
381 
382---
383 
384## Contributing
385 
386```bash
387git clone https://github.com/OrangeproAI/orangepro-mcp.git
388cd orangepro-mcp && npm ci && npm run build
389npm test
390```
391 
392PRs welcome. Please open an issue first for large changes.
393 
394---
395 
396<p align="center">
397 MIT License · <a href="https://orangepro.ai">orangepro.ai</a>
398</p>
399 

Discussion

Alternatives