@paxaver/mcp

MCPCommunitylive
v2.4.1Vahid GhafarpourApache-2.0Aktualisiert vor 3 TnpmGitHub

Paxaver MCP server — AI-facing adapter over the Paxaver school community operating system. Streamable HTTP, OAuth 2.1, capability-first authorization.

Endpunkt-Statuslive
geprüft vor 2 Tagen · 17 ms
100 % der letzten 1 Prüfung hat diesen Endpunkt erreicht
Läuft in
ClaudeCursorCopilotChatGPTGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio, streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Automatisch aus öffentlichen Quellen indexiert. Vom Entwickler auf Forge noch nicht verifiziert.Diesen Eintrag beanspruchen →
208Downloads/Wo.
vor 3 TLetzte Aktualisierung
Paket
AutorVahid Ghafarpour
LizenzApache-2.0
Version2.4.1
Quellenpm+mcp-registry
Trust-Status
B
60/100Gut
Im Forge-Index gelistet+10/10
Publisher-Identität verifiziert+0/20
Publisher: führe `forge publish` im Repo des Pakets aus, um die Inhaberschaft zu beanspruchen
Ed25519-Publish-Signatur+0/5
Wird automatisch ergänzt, wenn der Publisher `forge publish` ausführt
Domain-Verifizierung+0/5
Publisher: hinterlege /.well-known/forge.json auf der Paket-Homepage mit { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+0/5
Veröffentliche aus GitHub Actions mit --provenance, damit die Attestation dieses Paket an dieses Repo bindet
npm-Maintainer-Übereinstimmung+0/5
Wird erreicht, sobald deine Identität oben verifiziert ist und dieser Login npm-Maintainer dieses Pakets ist
CVE-Scan · sauber+30/30
Statische Analyse · sauber+20/20
Füge das in Claude Code, Cursor oder einen beliebigen KI-Assistenten ein, um alle Lücken zu schließen
StatusVon der Community indexiert
PublisherNicht verifiziert
SignaturNicht signiert
Domain
Herkunft
Abhängigkeiten✓ 1 aufgelöst · keine verwundbar
Tool-Oberfläche30 Tools · 1 privilegiert
Sicherheits-Scan✓ Sauberv2.4.1 · heuteWie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert14. Sept. 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

30 Tools · 1 privilegiert
Statisch aus dem veröffentlichten Paket extrahiertv2.4.1 · 8h ago

Aus dem Quellcode gelesen, den npm tatsächlich ausliefert, zum Zeitpunkt des Scans. Das Paket wurde nie ausgeführt. Tools, die zur Laufzeit dynamisch registriert werden oder in gebündeltem beziehungsweise minifiziertem Code stecken, können übersehen werden — das hier ist also eine Untergrenze der Tool-Oberfläche, keine vollständige Erhebung.

get_user_infoReturns the authenticated Paxaver user context: their first name, active school, students they are a guardian for, and available roles. ALWAYS call this first before any other tool to establish context. This is a read-only operation.

Returns the authenticated Paxaver user context: their first name, active school, students they are a guardian for, and available roles. ALWAYS call this first before any other tool to establish context. This is a read-only operation.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_wallet_balanceReturns the current wallet balance for the authenticated user at their active school. Read-only. Use this to check funds before ordering lunch.

Returns the current wallet balance for the authenticated user at their active school. Read-only. Use this to check funds before ordering lunch.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_wallet_statusReturns the wallet balance plus recent transactions and pending deposits. Read-only. Use this for a wallet overview.

Returns the wallet balance plus recent transactions and pending deposits. Read-only. Use this for a wallet overview.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

order_lunchPlaces a lunch order for a student the authenticated user is a guardian of. Requires menu_item_id (from get_daily_menu) and menu_date (YYYY-MM-DD). Optionally specify student_id (defaults to the user's first student if only one). Payment is deducted from the wallet. This is a FINANCIAL + WRITE oper…

Places a lunch order for a student the authenticated user is a guardian of. Requires menu_item_id (from get_daily_menu) and menu_date (YYYY-MM-DD). Optionally specify student_id (defaults to the user's first student if only one). Payment is deducted from the wallet. This is a FINANCIAL + WRITE oper…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_ordersReturns recent lunch orders for the authenticated user's students. Read-only. Optionally filter by student_id.

Returns recent lunch orders for the authenticated user's students. Read-only. Optionally filter by student_id.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_daily_menuReturns the daily lunch menu for the user's active school. Accepts either "date" (YYYY-MM-DD) or "month" (YYYY-MM). If neither is given, returns today's menu. Read-only. Use this to find menu_item_id values for order_lunch.

Returns the daily lunch menu for the user's active school. Accepts either "date" (YYYY-MM-DD) or "month" (YYYY-MM). If neither is given, returns today's menu. Read-only. Use this to find menu_item_id values for order_lunch.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_daily_ordersADMIN: Returns all orders for the active school on a given date. Requires pac_cordinator or lunch_cordinator role. Read-only.

ADMIN: Returns all orders for the active school on a given date. Requires pac_cordinator or lunch_cordinator role. Read-only.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_monthly_ordersReturns a monthly summary of orders. Optionally filter by month (YYYY-MM) and student. Read-only.

Returns a monthly summary of orders. Optionally filter by month (YYYY-MM) and student. Read-only.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

create_draft_orderCreates a draft lunch order for a student. Requires student_id, school_slug, menu_date, and items array. Each item needs menu_item_id, menu_item_name, price_cents, and quantity. The draft is not finalized - call finalize_order to commit the order and deduct payment. This is a FINANCIAL + WRITE oper…

Creates a draft lunch order for a student. Requires student_id, school_slug, menu_date, and items array. Each item needs menu_item_id, menu_item_name, price_cents, and quantity. The draft is not finalized - call finalize_order to commit the order and deduct payment. This is a FINANCIAL + WRITE oper…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

finalize_orderFinalizes a draft order, deducting payment from the wallet. Optionally include tip_cents (donated to the school's PAC). This is a FINANCIAL + WRITE operation - always confirm with the user before calling. Idempotent.

Finalizes a draft order, deducting payment from the wallet. Optionally include tip_cents (donated to the school's PAC). This is a FINANCIAL + WRITE operation - always confirm with the user before calling. Idempotent.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

cancel_orderCancels a finalized order if labels have not been sent yet. Refunds the wallet. This is a DESTRUCTIVE operation - always confirm with the user before cancelling. If labels have already been sent, the cancellation will be rejected. Idempotent.

Cancels a finalized order if labels have not been sent yet. Refunds the wallet. This is a DESTRUCTIVE operation - always confirm with the user before cancelling. If labels have already been sent, the cancellation will be rejected. Idempotent.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

get_upcoming_eventsReturns upcoming events for the user's active school. Optionally filter by date range (start_date / end_date, YYYY-MM-DD). Read-only.

Returns upcoming events for the user's active school. Optionally filter by date range (start_date / end_date, YYYY-MM-DD). Read-only.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

create_eventADMIN: Creates a school event. Requires pac_cordinator or event_cordinator role. This is a WRITE operation - confirm details with the user before creating. Do not create events without explicit user request.

ADMIN: Creates a school event. Requires pac_cordinator or event_cordinator role. This is a WRITE operation - confirm details with the user before creating. Do not create events without explicit user request.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

update_eventADMIN: Updates an existing school event. Requires pac_cordinator or event_cordinator role. WRITE operation - confirm changes with the user.

ADMIN: Updates an existing school event. Requires pac_cordinator or event_cordinator role. WRITE operation - confirm changes with the user.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

cancel_eventADMIN: Cancels a school event. Requires pac_cordinator or event_cordinator role. This is a DESTRUCTIVE operation - always confirm with the user before cancelling. Cancelled events cannot be reactivated.

ADMIN: Cancels a school event. Requires pac_cordinator or event_cordinator role. This is a DESTRUCTIVE operation - always confirm with the user before cancelling. Cancelled events cannot be reactivated.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

register_eventRegisters the authenticated user for a school event. Requires event_id. Optionally specify quantity (default 1). This is a WRITE operation - confirm with the user before registering. Idempotent.

Registers the authenticated user for a school event. Requires event_id. Optionally specify quantity (default 1). This is a WRITE operation - confirm with the user before registering. Idempotent.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

sign_up_to_volunteerSigns up the authenticated user as a volunteer for a specific shift. Requires shift_id (from get_upcoming_events or event detail). This is a WRITE operation - confirm with the user before signing up. Idempotent.

Signs up the authenticated user as a volunteer for a specific shift. Requires shift_id (from get_upcoming_events or event detail). This is a WRITE operation - confirm with the user before signing up. Idempotent.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_school_restaurantsADMIN: Lists restaurants for the active school. Requires pac_cordinator, pac_member, or lunch_cordinator role. Read-only.

ADMIN: Lists restaurants for the active school. Requires pac_cordinator, pac_member, or lunch_cordinator role. Read-only.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

create_restaurantADMIN: Creates a restaurant for the active school. Requires pac_cordinator role. WRITE operation - confirm with the user.

ADMIN: Creates a restaurant for the active school. Requires pac_cordinator role. WRITE operation - confirm with the user.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

list_menu_itemsADMIN: Lists menu items for a restaurant. Requires pac_cordinator or lunch_cordinator role. Read-only.

ADMIN: Lists menu items for a restaurant. Requires pac_cordinator or lunch_cordinator role. Read-only.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

create_menu_itemADMIN: Creates a menu item for a restaurant. Requires pac_cordinator or lunch_cordinator role. WRITE operation.

ADMIN: Creates a menu item for a restaurant. Requires pac_cordinator or lunch_cordinator role. WRITE operation.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

update_menu_itemADMIN: Updates a menu item. Requires pac_cordinator or lunch_cordinator role. WRITE operation.

ADMIN: Updates a menu item. Requires pac_cordinator or lunch_cordinator role. WRITE operation.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

set_menu_item_priceADMIN: Sets the price of a menu item. Requires pac_cordinator or lunch_cordinator role. FINANCIAL + WRITE operation - confirm the new price with the user.

ADMIN: Sets the price of a menu item. Requires pac_cordinator or lunch_cordinator role. FINANCIAL + WRITE operation - confirm the new price with the user.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

delete_menu_itemprivilegiertADMIN: Soft-deletes a menu item. Requires pac_cordinator or lunch_cordinator role. DESTRUCTIVE operation - confirm with the user.

ADMIN: Soft-deletes a menu item. Requires pac_cordinator or lunch_cordinator role. DESTRUCTIVE operation - confirm with the user.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

set_daily_menuADMIN: Sets the daily menu (assigns a menu item to a date with available quantity). Requires pac_cordinator or lunch_cordinator role. WRITE operation.

ADMIN: Sets the daily menu (assigns a menu item to a date with available quantity). Requires pac_cordinator or lunch_cordinator role. WRITE operation.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

daily_lunch_menuShow today lunch menu for the school.

Show today lunch menu for the school.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

wallet_balanceCheck the current wallet balance.

Check the current wallet balance.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

upcoming_eventsList upcoming events at the school.

List upcoming events at the school.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

order_lunch_helperGuide the user through ordering lunch for a student.

Guide the user through ordering lunch for a student.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

student_nameThe student name to order lunch for.

The student name to order lunch for.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

30 von 30 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Paxaver MCP server — AI-facing adapter over the Paxaver school community operating system. Streamable HTTP, OAuth 2.1, capability-first authorization.

Schlagwörter
mcpmodel-context-protocolpaxaverschoolluncheducationcloudflare-workersaiassistantoauth
Alternativen
Tool-Oberflächen werden verglichen…

Abhängigkeitsbaum

Was ein Forge-Scan am 2026-09-16 aus den npm-Metadaten aufgelöst hat — beobachtete Auflösung, keine Angabe des Herausgebers.

1 Pakete aufgelöst · 1 direkt · keines mit Sicherheitshinweisen Die Auflösung endet bei Tiefe 4 und 60 Paketen.

Themen

Verwandtes in cloud platforms