bundlebox

MCPattestiert
v0.8.0io.github.blackswanalphaMITAktualisiert vor 1 TnpmGitHub

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

Läuft in
ClaudeCursorCopilotGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Attestierter Build
Eine verifizierte Herkunfts-Attestation bindet dieses Artefakt an das gelistete Repository. Den Eintrag hat noch niemand beansprucht — das belegt, wo der Code gebaut wurde, nicht, wer dahintersteht.
150Downloads/Wo.
2GitHub-Sterne
vor 1 TLetzte Aktualisierung
Paket
Autorio.github.blackswanalpha
LizenzMIT
Version0.8.0
Quellenpm+mcp-registry
Trust-Status
A
85/100Vertrauenswürdig
Im Forge-Index gelistet+10/10
Identität verifiziert · attestierter Build+20/20
Ed25519-Publish-Signatur+0/5
Wird automatisch ergänzt, wenn der Publisher `forge publish` ausführt
Domain-Verifizierung+0/5
Publisher: hinterlege /.well-known/forge.json auf der Paket-Homepage mit { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
npm-Maintainer-Übereinstimmung+0/5
Publisher: trage den verifizierten GitHub-Login als Maintainer des npm-Pakets ein (npm owner add <login>)
CVE-Scan · sauber+30/30
Statische Analyse · sauber+20/20
Füge das in Claude Code, Cursor oder einen beliebigen KI-Assistenten ein, um alle Lücken zu schließen
StatusIdentität verifiziert
PublisherNicht verifiziert
SignaturNicht signiert
Domain
Herkunft✓ Sigstore-verifiziert · 2907a91
Abhängigkeiten✓ 0 aufgelöst · keine verwundbar
Tool-Oberfläche24 Tools · keines privilegiert
Sicherheits-Scan✓ Sauberv0.8.0 · vor 1 TWie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert22. Sept. 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

24 Tools · keines privilegiert
Statisch aus dem veröffentlichten Paket extrahiertv0.8.0 · 1d ago

Aus dem Quellcode gelesen, den npm tatsächlich ausliefert, zum Zeitpunkt des Scans. Das Paket wurde nie ausgeführt. Tools, die zur Laufzeit dynamisch registriert werden oder in gebündeltem beziehungsweise minifiziertem Code stecken, können übersehen werden — das hier ist also eine Untergrenze der Tool-Oberfläche, keine vollständige Erhebung.

intakewhat is wrong, found locally; ends holding lanes, the last point before anything spends

what is wrong, found locally; ends holding lanes, the last point before anything spends

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

orientwhat a session gets handed instead of searching

what a session gets handed instead of searching

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

measurewhat sessions cost, what the local path displaced, and what packing a task is worth

what sessions cost, what the local path displaced, and what packing a task is worth

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

opsis this box healthy

is this box healthy

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

buckmastertrain the process model on everything above, then turn it into automation

train the process model on everything above, then turn it into automation

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

situationwhat is happening right now: services, what is failing, and what the detectors see

what is happening right now: services, what is failing, and what the detectors see

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

genesisthe inlet: what the world declares that no scenario touches, packed to briefs

the inlet: what the world declares that no scenario touches, packed to briefs

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

scenariosrun the corpus against the running system and read what it means

run the corpus against the running system and read what it means

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

auditwhich areas have no current audit, and the briefs that would produce one

which areas have no current audit, and the briefs that would produce one

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

watchfold what was spent, and rebuild the one page that shows it

fold what was spent, and rebuild the one page that shows it

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bootstrapbring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page

bring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

factoryone tick of the whole free path: intake, orient, measure, buckmaster, watch

one tick of the whole free path: intake, orient, measure, buckmaster, watch

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

fullthe whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost

the whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

practicefill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one

fill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_pinpointOne problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on file, the acceptance command, traps and guidelines. Call this BEFORE searching the tree.

One problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on file, the acceptance command, traps and guidelines. Call this BEFORE searching the tree.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_contextDoes this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cut.

Does this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cut.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_snapgenReference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `table` returns the INDEX with each table's token cost so you can choose. Read a table instead of grepping.

Reference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `table` returns the INDEX with each table's token cost so you can choose. Read a table instead of grepping.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_findingsOpen findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.

Open findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_scanRun the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.

Run the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_oversight_briefWhat is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editing. About 300 tokens.

What is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editing. About 300 tokens.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_explainOne finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).

One finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_tokens_estimateEstimated tokens per file and in total, with the calibrated estimator (not chars/4).

Estimated tokens per file and in total, with the calibrated estimator (not chars/4).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_situationWhere this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, and what the last echos run saw. Call this instead of git status + git diff + bb env + bb findings + bb echos.

Where this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, and what the last echos run saw. Call this instead of git status + git diff + bb env + bb findings + bb echos.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bb_sessionWhat the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

What the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

24 von 24 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Abhängigkeitsbaum

Was ein Forge-Scan am 2026-09-23 aus den npm-Metadaten aufgelöst hat — beobachtete Auflösung, keine Angabe des Herausgebers.

0 Pakete aufgelöst · 0 direkt · keines mit Sicherheitshinweisen Die Auflösung endet bei Tiefe 4 und 60 Paketen.

Dieses Paket deklariert keine Laufzeitabhängigkeiten.