@shardflux/mcp

MCPCommunitylive
v0.12.2dev.shardfluxApache-2.0Aktualisiert vor 2 Tnpm

Persistent cloud workspaces for AI agents: run commands, edit files, use git and a browser.

Endpunkt-Statuslive
geprüft vor 21 Std. · 219 ms · Authentifizierung erforderlich
100 % der letzten 1 Prüfung hat diesen Endpunkt erreicht
Läuft in
ClaudeCursorCopilotChatGPTGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio, streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Automatisch aus öffentlichen Quellen indexiert. Vom Entwickler auf Forge noch nicht verifiziert.Diesen Eintrag beanspruchen →
2kDownloads/Wo.
vor 2 TLetzte Aktualisierung
Braucht 1 Zugangsdatum, bevor es läuft
  • SHARDFLUX_API_KEYAPI-Schlüsselerforderlich

    Scoped Shardflux project API key (sfk_<key id>_<secret>). Its tool permissions decide which workspace tools are listed.

  • SHARDFLUX_WORKSPACE_KEYAPI-Schlüsseloptional

    Pin one workspace: workspace_key becomes optional on every tool and any other key is refused (workspace_pinned).

Vom Autor in der offiziellen MCP-Registry angegeben. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paket
Autordev.shardflux
LizenzApache-2.0
Version0.12.2
Quellenpm+mcp-registry
Trust-Status
B
60/100Gut
✓Im Forge-Index gelistet+10/10
—Publisher-Identität verifiziert+0/20
→ Publisher: führe `forge publish` im Repo des Pakets aus, um die Inhaberschaft zu beanspruchen
—Ed25519-Publish-Signatur+0/5
→ Wird automatisch ergänzt, wenn der Publisher `forge publish` ausführt
—Domain-Verifizierung+0/5
→ Publisher: hinterlege /.well-known/forge.json auf der Paket-Homepage mit { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Veröffentliche aus GitHub Actions mit --provenance, damit die Attestation dieses Paket an dieses Repo bindet
—npm-Maintainer-Übereinstimmung+0/5
→ Wird erreicht, sobald deine Identität oben verifiziert ist und dieser Login npm-Maintainer dieses Pakets ist
✓CVE-Scan · sauber+30/30
✓Statische Analyse · sauber+20/20
Füge das in Claude Code, Cursor oder einen beliebigen KI-Assistenten ein, um alle Lücken zu schließen
StatusVon der Community indexiert
PublisherNicht verifiziert
SignaturNicht signiert
Domain—
Herkunft—
Abhängigkeiten60 aufgelöst · 1 mit Advisories
Tool-Oberfläche35 Tools · keines privilegiert
Sicherheits-Scan⚠ Warnungen (1)v0.13.0 · heuteWie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert9. Okt. 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

35 Tools · keines privilegiert
Statisch aus dem veröffentlichten Paket extrahiertv0.13.0 · 21h ago

Aus dem Quellcode gelesen, den npm tatsächlich ausliefert, zum Zeitpunkt des Scans. Das Paket wurde nie ausgeführt. Tools, die zur Laufzeit dynamisch registriert werden oder in gebündeltem beziehungsweise minifiziertem Code stecken, können übersehen werden — das hier ist also eine Untergrenze der Tool-Oberfläche, keine vollständige Erhebung.

project_space_readerOpen a read-only workspace to fetch saved project branches and transcripts.

Open a read-only workspace to fetch saved project branches and transcripts.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

credential_fillFill the workspace browser from an approved vault item. Returns filled or a refusal, never the value.

Fill the workspace browser from an approved vault item. Returns filled or a refusal, never the value.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

credential_requests_listList pending login approvals, without credential values.

List pending login approvals, without credential values.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

credential_request_denyRefuse a pending login request.

Refuse a pending login request.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

credential_request_fulfilRelay a credential already sealed to the workspace one-time public key. Accepts ciphertext only.

Relay a credential already sealed to the workspace one-time public key. Accepts ciphertext only.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

volume_openCreate or reuse a project volume by name. Waits until available unless wait is false.

Create or reuse a project volume by name. Waits until available unless wait is false.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

volume_listList project volumes, optionally including organization shared volumes.

List project volumes, optionally including organization shared volumes.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

agents_listList coding agent sessions in this project.

List coding agent sessions in this project.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_openOpen a persistent workspace by key: creates it from the template on first use, reconnects (or resumes) it afterwards, never resets it. Waits until it is ready unless wait is false; on timeout the start continues server side (operation_wait); a queued start has a deadline 15 minutes after it was cre…

Open a persistent workspace by key: creates it from the template on first use, reconnects (or resumes) it afterwards, never resets it. Waits until it is ready unless wait is false; on timeout the start continues server side (operation_wait); a queued start has a deadline 15 minutes after it was cre…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_listList the workspaces of this API key’s project (key, state, template, active operation).

List the workspaces of this API key’s project (key, state, template, active operation).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_statusCurrent state of one workspace (ready, mode, observed/desired state, grants, pending reason; tree_revision for a file-first workspace) and its most recent operations.

Current state of one workspace (ready, mode, observed/desired state, grants, pending reason; tree_revision for a file-first workspace) and its most recent operations.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_idleRead idle policy and activity without waking or recording activity.

Read idle policy and activity without waking or recording activity.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_hintStage a parked workspace ahead of an imminent VM tool call. Invoke explicitly when tool input starts; returns without waiting for restore. A suspended workspace must be resumed first.

Stage a parked workspace ahead of an imminent VM tool call. Invoke explicitly when tool input starts; returns without waiting for restore. A suspended workspace must be resumed first.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_keepalivePrevent idle suspension for seconds; never shortens an existing keepalive.

Prevent idle suspension for seconds; never shortens an existing keepalive.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_set_retentionDelete a persistent workspace after this many idle days (1..3650). null removes its own policy and follows the project default.

Delete a persistent workspace after this many idle days (1..3650). null removes its own policy and follows the project default.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_set_idle_policySet adaptive, never or fixed:<seconds> (60..604800); default restores the inherited policy.

Set adaptive, never or fixed:<seconds> (60..604800); default restores the inherited policy.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_set_labelsReplace all labels; an empty object clears them. Labels are searchable metadata, not secrets.

Replace all labels; an empty object clears them. Labels are searchable metadata, not secrets.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_suspendSuspend a running workspace (full-state checkpoint; processes stop, files and state are kept, and the next tool call resumes it). Returns the suspend operation (with wait: once finished, and its timing).

Suspend a running workspace (full-state checkpoint; processes stop, files and state are kept, and the next tool call resumes it). Returns the suspend operation (with wait: once finished, and its timing).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_forkFork a running or suspended workspace into a new key (an independent copy of its committed state). Returns the fork operation and the new workspace (with wait: once finished, and its timing). Not for file-first workspaces.

Fork a running or suspended workspace into a new key (an independent copy of its committed state). Returns the fork operation and the new workspace (with wait: once finished, and its timing). Not for file-first workspaces.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_upgradeKeep files, installed package files and home while moving to the supported current layout/base. One cold start ends memory and running processes. at next_resume schedules it without stopping the VM; now upgrades immediately. The operation reports whether it is scheduled or applied.

Keep files, installed package files and home while moving to the supported current layout/base. One cold start ends memory and running processes. at next_resume schedules it without stopping the VM; now upgrades immediately. The operation reports whether it is scheduled or applied.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_resizeKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

operation_waitWait for a lifecycle operation (open, suspend, resume, fork, ...) to finish, up to timeout_ms. Returns the operation and the wait’s timing. With durable (a suspend or fork), also wait until its copy is in durable storage.

Wait for a lifecycle operation (open, suspend, resume, fork, ...) to finish, up to timeout_ms. Returns the operation and the wait’s timing. With durable (a suspend or fork), also wait until its copy is in durable storage.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_expose_portKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

workspace_list_portsThe exposed ports of the workspace: {ports: [{port, url, created_at, callback}]}, ordered by port. callback is set when the port has a callback URL for webhooks. Every port is private; workspace_port_link gives a link that opens one in a browser.

The exposed ports of the workspace: {ports: [{port, url, created_at, callback}]}, ordered by port. callback is set when the port has a callback URL for webhooks. Every port is private; workspace_port_link gives a link that opens one in a browser.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_close_portStop serving an exposed port: its URL stops answering and every link to it stops working at once. Idempotent (also when the port is not exposed). Returns {port, closed: true}.

Stop serving an exposed port: its URL stops answering and every link to it stops working at once. Idempotent (also when the port is not exposed). Returns {port, closed: true}.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_port_linkA link that opens an exposed port in a browser: give it to the person you work for, or open it yourself. Returns {url, expires_at}. Opening it starts a browser session for the port until expires_at and lands on path. Anyone with the link can open the port until then, so treat it like a password. Ex…

A link that opens an exposed port in a browser: give it to the person you work for, or open it yourself. Returns {url, expires_at}. Opening it starts a browser session for the port until expires_at and lands on path. Anyone with the link can open the port until then, so treat it like a password. Ex…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_set_computer_useSwitch computer use on or off for a workspace (inherit follows its template). While it is on, the computer tool drives the workspace desktop, which starts on the first computer call. Returns {enabled, workspace, template, available}; available false means its template version cannot run a desktop (…

Switch computer use on or off for a workspace (inherit follows its template). While it is on, the computer tool drives the workspace desktop, which starts on the first computer call. Returns {enabled, workspace, template, available}; available false means its template version cannot run a desktop (…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_computer_streamA link to watch the workspace desktop live in a browser (view only unless interactive): give it to the person you work for. Returns {url, expires_at, port, interactive}. Anyone with the link can open it until expires_at, so treat it like a password. stop: true ends every view instead.

A link to watch the workspace desktop live in a browser (view only unless interactive): give it to the person you work for. Returns {url, expires_at, port, interactive}. Anyone with the link can open it until expires_at, so treat it like a password. stop: true ends every view instead.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

workspace_computer_desktopThe workspace desktop itself. status: whether it runs, its screen size and its viewers (never starts it). start: start it at a screen size (640x480 to 2560x1600, default 1280x800; a no-op while it runs); without it the first computer call starts it at the default size. stop: stop it (its windows cl…

The workspace desktop itself. status: whether it runs, its screen size and its viewers (never starts it). start: start it at a screen size (640x480 to 2560x1600, default 1280x800; a no-op while it runs); without it the first computer call starts it at the default size. stop: stop it (its windows cl…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

template_getA template this project can open: its versions (state, source, installed tools, immutable paths) and each version’s settings (env, open-time inputs, start commands, services, defaults). With version, also that version’s recipe in request form (the recipe v2 document template_build takes; null for v…

A template this project can open: its versions (state, source, installed tools, immutable paths) and each version’s settings (env, open-time inputs, start commands, services, defaults). With version, also that version’s recipe in request form (the recipe v2 document template_build takes; null for v…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

template_languagesThe languages (python, node, go, rust, java) and versions a base offers a recipe v2’s build.languages, e.g. base "ubuntu-24.04@1". included: the base already has that version (nothing is installed); default: what {id} without a version picks. A version the base has another version of is not offered.

The languages (python, node, go, rust, java) and versions a base offers a recipe v2’s build.languages, e.g. base "ubuntu-24.04@1". included: the base already has that version (nothing is installed); default: what {id} without a version picks. A version the base has another version of is not offered.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

template_buildKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

usage_summaryKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

send_feedbackKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

shardfluxKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

29 von 35 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Persistent cloud workspaces for AI agents: run commands, edit files, use git and a browser.

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Abhängigkeitsbaum

Was ein Forge-Scan am 2026-10-09 aus den npm-Metadaten aufgelöst hat — beobachtete Auflösung, keine Angabe des Herausgebers.

60 Pakete aufgelöst · 4 direkt · 1 mit Sicherheitshinweisen Die Auflösung endet bei Tiefe 4 und 60 Paketen.

Der Durchlauf endete an der Grenze von 60 Paketen. Der Rest des Baums wurde nie aufgelöst.

36 weitere aufgelöste Pakete werden hier nicht gezeichnet (Anzeigegrenze: 24). Jede Abhängigkeit mit einem Sicherheitshinweis wird unabhängig von der Grenze gezeichnet. Vollständiges Inventar (CycloneDX-SBOM)

Deklariert, aber nicht aufgelöst

57 deklarierte Abhängigkeiten sind nie im Baum gelandet. Sie fehlen in Forges Auflösung, nicht im Paket.

+45 weitere nicht aufgeführt. Die Zählungen nach Grund oben erfassen sie alle.

Nicht verfolgt: peerDependencies. Dieser Baum erfasst nur Laufzeitabhängigkeiten; was jene mitbringen, wurde nie aufgelöst.