@octocrawl/mcp

MCPattestiertlive
v0.4.1io.github.77777R7AGPL-3.0-onlyAktualisiert vor 1 TnpmGitHub

Web scraper for agents: blocked, empty and wrong pages reported as such, with an Evidence Record.

Endpunkt-Statuslive
geprüft vor 1 Tag · 1594 ms
100 % der letzten 1 Prüfung hat diesen Endpunkt erreicht
Läuft in
ClaudeCursorCopilotChatGPTGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio, streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Attestierter Build
Eine verifizierte Herkunfts-Attestation bindet dieses Artefakt an das gelistete Repository. Den Eintrag hat noch niemand beansprucht — das belegt, wo der Code gebaut wurde, nicht, wer dahintersteht.
338Downloads/Wo.
vor 1 TLetzte Aktualisierung
Liest diese Zugangsdaten
  • W2L_API_TOKENAPI-Schlüsseloptional

    A bearer token for a hosted or self-hosted API; none for a local one

Vom Autor in der offiziellen MCP-Registry angegeben. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paket
Autorio.github.77777R7
LizenzAGPL-3.0-only
Version0.4.1
Quellenpm+mcp-registry
Trust-Status
B
65/100Gut
✓Im Forge-Index gelistet+10/10
✓Identität verifiziert · attestierter Build+20/20
—Ed25519-Publish-Signatur+0/5
→ Wird automatisch ergänzt, wenn der Publisher `forge publish` ausführt
—Domain-Verifizierung+0/5
→ Publisher: hinterlege /.well-known/forge.json auf der Paket-Homepage mit { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm-Maintainer-Übereinstimmung+0/5
→ Publisher: trage den verifizierten GitHub-Login als Maintainer des npm-Pakets ein (npm owner add <login>)
✓CVE-Scan · sauber+30/30
—Statische Analyse · sauber+0/20
→ Verdächtige Installationsskripte oder obfuskierter Code erkannt
Füge das in Claude Code, Cursor oder einen beliebigen KI-Assistenten ein, um alle Lücken zu schließen
StatusIdentität verifiziert
PublisherNicht verifiziert
SignaturNicht signiert
Domain—
Herkunft✓ Sigstore-verifiziert · da3842f
Abhängigkeiten✓ 60 aufgelöst+ · keine verwundbar
Tool-Oberfläche32 Tools · 1 privilegiert
Sicherheits-Scan⚠ Warnungen (1)v0.4.1 · vor 1 TWie gut funktioniert dieser Scan?
PROMPTtool:create_delivery_destinationExfiltration-shaped instruction
EvaluierungenKeine
Indexiert9. Okt. 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

32 Tools · 1 privilegiert · 1 wegen Injektion markiert
Statisch aus dem veröffentlichten Paket extrahiertv0.4.1 · 1d ago

Aus dem Quellcode gelesen, den npm tatsächlich ausliefert, zum Zeitpunkt des Scans. Das Paket wurde nie ausgeführt. Tools, die zur Laufzeit dynamisch registriert werden oder in gebündeltem beziehungsweise minifiziertem Code stecken, können übersehen werden — das hier ist also eine Untergrenze der Tool-Oberfläche, keine vollständige Erhebung.

preview_monitorCapture a nonpersistent sample and assess identity, fields, evidence, and missing reasons. Start with preset firecrawl-introduction.

Capture a nonpersistent sample and assess identity, fields, evidence, and missing reasons. Start with preset firecrawl-introduction.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

create_monitorCreate a public-document Monitor. Defaults to paused so a delivery destination can be configured first. Use preset firecrawl-introduction for first use.

Create a public-document Monitor. Defaults to paused so a delivery destination can be configured first. Use preset firecrawl-introduction for first use.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_monitorsList current Monitor state and freshness.

List current Monitor state and freshness.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_monitorCheck a Monitor baseline, latest run, latest event, and next schedule.

Check a Monitor baseline, latest run, latest event, and next schedule.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

run_monitorQueue a durable manual run. Returns runId immediately; disconnection does not cancel execution.

Queue a durable manual run. Returns runId immediately; disconnection does not cancel execution.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_monitor_runInspect a run and field assessment with evidence and failure reasons.

Inspect a run and field assessment with evidence and failure reasons.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

pause_monitorPause scheduling and cancel active Monitor execution.

Pause scheduling and cancel active Monitor execution.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

resume_monitorResume Monitor scheduling; first run becomes due immediately.

Resume Monitor scheduling; first run becomes due immediately.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

cancel_monitor_runExplicitly cancel a queued or running Monitor run.

Explicitly cancel a queued or running Monitor run.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

create_delivery_destinationInjektionsrisikoRegister an HTTPS webhook for a Monitor. The secretEnv names an operator environment variable; never send the secret value.

Register an HTTPS webhook for a Monitor. The secretEnv names an operator environment variable; never send the secret value.

INJEKTIONExfiltration-shaped instructionr environment variable; never send the secret value.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_delivery_destinationsList webhook destinations, optionally for one Monitor (monitorId) or one crawl or batch (jobId, the taskId); custom header names are listed, never their values.

List webhook destinations, optionally for one Monitor (monitorId) or one crawl or batch (jobId, the taskId); custom header names are listed, never their values.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_deliveriesPage through delivery state and failures, for a Monitor (monitorId) or a crawl or batch (jobId, the taskId). Defaults to 20 compact results.

Page through delivery state and failures, for a Monitor (monitorId) or a crawl or batch (jobId, the taskId). Defaults to 20 compact results.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_deliveryInspect one delivery and its retry attempts.

Inspect one delivery and its retry attempts.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

retry_dead_letterExplicitly retry a dead-letter delivery with the same eventId.

Explicitly retry a dead-letter delivery with the same eventId.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

scrape_productGet evidence-backed JSON for one anonymous Amazon.sg /dp/{ASIN} product. No schema or model setup needed.

Get evidence-backed JSON for one anonymous Amazon.sg /dp/{ASIN} product. No schema or model setup needed.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

batch_productsQueue 1-1000 distinct Amazon.sg product URLs with the reviewed JSON schema. Returns taskId; page results with get_batch_items.

Queue 1-1000 distinct Amazon.sg product URLs with the reviewed JSON schema. Returns taskId; page results with get_batch_items.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

scrapeFetch one URL through the Octocrawl coverage ladder. Compact by default; set debug=true for the full audit. The result's warnings name what its content cannot vouch for: robots_overridden (robots.txt disallows the URL; a local server fetched it because you named it), or client_rendered_suspected wh…

Fetch one URL through the Octocrawl coverage ladder. Compact by default; set debug=true for the full audit. The result's warnings name what its content cannot vouch for: robots_overridden (robots.txt disallows the URL; a local server fetched it because you named it), or client_rendered_suspected wh…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_scrapeRead the record of one scrape call by the scrapeId its response carried (metadata.scrapeId): the request (header values replaced by their names), who made it (origin, integration), the verdict, the lanes tried, the metadata, the snapshot, the usage, the warnings and the hints. No page body. Records…

Read the record of one scrape call by the scrapeId its response carried (metadata.scrapeId): the request (header values replaced by their names), who made it (origin, integration), the verdict, the lanes tried, the metadata, the snapshot, the usage, the warnings and the hints. No page body. Records…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

mapKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

crawlStart a multi-page crawl. Returns { taskId } (HTTP 202 equivalent). By default it follows links in the start URL's path subtree on its host and www twin, folds similar URLs into one page, and reports every collapsed or refused link in get_crawl's discovery counters and each page's links_offered tra…

Start a multi-page crawl. Returns { taskId } (HTTP 202 equivalent). By default it follows links in the start URL's path subtree on its host and www twin, folds similar URLs into one page, and reports every collapsed or refused link in get_crawl's discovery counters and each page's links_offered tra…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_crawlRead a crawl by task id. Returns a CrawlReport.

Read a crawl by task id. Returns a CrawlReport.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_crawl_pagesRead a paginated list of crawl page results by task id (the latest attempt's unless attemptId is given). Pages omit the routing audit and trace unless debug is true, and leave out pages whose content repeated an earlier page's (status duplicate) unless includeDuplicates is true. With maxResults the…

Read a paginated list of crawl page results by task id (the latest attempt's unless attemptId is given). Pages omit the routing audit and trace unless debug is true, and leave out pages whose content repeated an earlier page's (status duplicate) unless includeDuplicates is true. With maxResults the…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_crawl_errorsRead a paginated list of crawl errors by task id.

Read a paginated list of crawl errors by task id.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

cancel_crawlCancel a crawl task. Completed pages remain queryable.

Cancel a crawl task. Completed pages remain queryable.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

resume_crawlRestart a paused or failed crawl with the options it was started with. Returns { taskId }; poll get_crawl.

Restart a paused or failed crawl with the options it was started with. Returns { taskId }; poll get_crawl.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_active_crawlsList the crawls the API process is running (those it started and those it resumed at startup; never a batch): each with its id, start URL, status, pages so far and the options it was started with. Empty when nothing runs.

List the crawls the API process is running (those it started and those it resumed at startup; never a batch): each with its id, start URL, status, pages so far and the options it was started with. Empty when nothing runs.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

batch_scrapePersist and run 1-1000 explicit URLs. Returns a taskId (with ignoreInvalidURLs also invalidURLs, the entries skipped); use get_batch_items for paginated results and get_batch_errors for the URLs that failed or that robots.txt refused. With appendToId the urls are added to that existing batch instea…

Persist and run 1-1000 explicit URLs. Returns a taskId (with ignoreInvalidURLs also invalidURLs, the entries skipped); use get_batch_items for paginated results and get_batch_errors for the URLs that failed or that robots.txt refused. With appendToId the urls are added to that existing batch instea…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_batch_errorsThe items of a batch that did not succeed, across every attempt (a resumed batch keeps its earlier failures): errors [{ id, timestamp, url, status, code, error, httpStatus }] in pages of up to 1000 (cursor, limit), and robotsBlocked, every URL robots.txt refused (policy_denied by a robots_disallowe…

The items of a batch that did not succeed, across every attempt (a resumed batch keeps its earlier failures): errors [{ id, timestamp, url, status, code, error, httpStatus }] in pages of up to 1000 (cursor, limit), and robotsBlocked, every URL robots.txt refused (policy_denied by a robots_disallowe…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

hand_off_batchKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

import_loginKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

list_loginsThe person's saved logins (import_login, octocrawl login import): { logins: [{ domain, savedAt, cookieCount, localStorage, sessionSha256 }] }, never a cookie or a stored value.

The person's saved logins (import_login, octocrawl login import): { logins: [{ domain, savedAt, cookieCount, localStorage, sessionSha256 }] }, never a cookie or a stored value.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

remove_loginprivilegiertForget the person's saved login to a site (a domain or a page URL on it).

Forget the person's saved login to a site (a domain or a page URL on it).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

29 von 32 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Web scraper for agents: blocked, empty and wrong pages reported as such, with an Evidence Record.

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Abhängigkeitsbaum

Was ein Forge-Scan am 2026-10-10 aus den npm-Metadaten aufgelöst hat — beobachtete Auflösung, keine Angabe des Herausgebers.

60 Pakete aufgelöst · 1 direkt · keines mit Sicherheitshinweisen Die Auflösung endet bei Tiefe 4 und 60 Paketen.

Der Durchlauf endete an der Tiefengrenze 4. Alles unterhalb dieser Ebene wurde nie aufgelöst.

Der Durchlauf endete an der Grenze von 60 Paketen. Der Rest des Baums wurde nie aufgelöst.

36 weitere aufgelöste Pakete werden hier nicht gezeichnet (Anzeigegrenze: 24). Jede Abhängigkeit mit einem Sicherheitshinweis wird unabhängig von der Grenze gezeichnet. Vollständiges Inventar (CycloneDX-SBOM)

Deklariert, aber nicht aufgelöst

54 deklarierte Abhängigkeiten sind nie im Baum gelandet. Sie fehlen in Forges Auflösung, nicht im Paket.

+42 weitere nicht aufgeführt. Die Zählungen nach Grund oben erfassen sie alle.

Nicht verfolgt: peerDependencies. Dieser Baum erfasst nur Laufzeitabhängigkeiten; was jene mitbringen, wurde nie aufgelöst.