io.github.Tanbir404/zephex

MCPCommunitybeeinträchtigt
v1.0.0io.github.Tanbir404UnknownAktualisiert vor 4 Mon.

MCP gateway with 10 tools for code analysis, architecture, package audit & security.

Endpunkt-Statusbeeinträchtigt
geprüft vor 9 Tagen · zuletzt erreichbar vor 28 Tagen
60 % der letzten 5 Prüfungen haben diesen Endpunkt erreicht
Läuft in
ClaudeCursorCopilotChatGPTGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Automatisch aus öffentlichen Quellen indexiert. Vom Entwickler auf Forge noch nicht verifiziert.Diesen Eintrag beanspruchen →
vor 4 Mon.Letzte Aktualisierung
Paket
Autorio.github.Tanbir404
LizenzUnknown
Version1.0.0
Quellemcp-registry
Trust-Status
D
30/100Risiko
✓Im Forge-Index gelistet+10/10
—Publisher-Identität verifiziert+0/30
→ Publisher: für diesen Eintrag ist kein Repository hinterlegt, daher kann `forge publish` die Inhaberschaft nicht automatisch prüfen. Nutze oben „Diesen Eintrag beanspruchen“ — Forge prüft diese Fälle von Hand.
—Domain-Verifizierung+0/10
→ Für diesen Eintragstyp derzeit nicht verfügbar — die Domain-Prüfung läuft heute nur für npm-gestützte Pakete, diese Zeile lässt sich hier also noch nicht erreichen, unabhängig davon, was auf der Domain liegt.
—Prompt-Injection-Scan · Befunde+0/30
→ Publisher: entferne aus dem Quellcode Anweisungen, die sich an KI-Clients statt an menschliche Leser richten
✓Obfuskations-/Exfiltrations-Scan · sauber+20/20
StatusVon der Community indexiert
PublisherNicht verifiziert
SignaturNicht signiert
Domain—
Herkunft—
AbhängigkeitenNicht auditiert
Tool-Oberfläche10 Tools · keines privilegiert
Sicherheits-Scan⚠ Warnungen (1)vlive · vor 1 Mon.Wie gut funktioniert dieser Scan?
PROMPTtool:audit_headersExfiltration-shaped instruction
PROMPTtool:audit_headersLinks to undeclared domain: myapp.vercel.app
PROMPTtool:audit_headers#urlLinks to undeclared domain: myapp.vercel.app
PROMPTtool:explain_architectureLinks to undeclared domain: github.com
EvaluierungenKeine
Indexiert13. Juni 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

10 Tools · keines privilegiert · 1 wegen Injektion markiert
Live am Endpunkt des Anbieters beobachtet1mo ago

Aus einem echten MCP-Handshake initialize → tools/list gegen den deklarierten Endpunkt gelesen. Es wurde nie ein Tool aufgerufen — tools/list ist der lesende Introspektionsaufruf, den das Protokoll dafür vorsieht. Es spiegelt wider, was der Server in diesem Moment angeboten hat; ein gehosteter Endpunkt ist an keine Version gebunden und kann sich ohne Ankündigung ändern.

  • https://zephex.dev/mcp10 Tools · 582 ms
audit_headersInjektionsrisikoAudit a public HTTPS URL the user deployed — security grade A–F, SSL, headers, cookies, health (ALIVE/DEGRADED/BROKEN), exposed secrets, tech stack. Read plain_summary first; only drill into security_headers or secrets if grade is poor. quick ~1–3s; scan_depth=deep for secret scan (~8–12s). 6 credi…

Audit a public HTTPS URL the user deployed — security grade A–F, SSL, headers, cookies, health (ALIVE/DEGRADED/BROKEN), exposed secrets, tech stack. Read plain_summary first; only drill into security_headers or secrets if grade is poor. quick ~1–3s; scan_depth=deep for secret scan (~8–12s). 6 credi…

INJEKTIONExfiltration-shaped instructionwhen user pastes a live URL — post-deploy check, is it secure, what framework, exposed keys. Blocks localhost/private IP…
HINWEISLinks to undeclared domain: myapp.vercel.app
HINWEISIm Parameter url: Links to undeclared domain: myapp.vercel.app
ParameterTypBeschreibung
url*stringPublic https:// URL to audit — e.g. https://myapp.vercel.app or https://zephex.dev
pathstringOptional subpath (e.g. /checkout) — appended to url
scan_modestringquick=~1-3s (default); thorough=DNS+APIs+secrets ~5-12s
check_redirectsbooleanFollow and audit the full redirect chain (default: true)
check_sslbooleanCheck SSL certificate validity, expiry, and protocol (default: true)
check_headersbooleanGrade all security headers and return fix snippets when include_fix_snippets=true (default: true)
check_cookiesbooleanCheck cookie Secure/HttpOnly/SameSite flags (default: true)
check_healthbooleanSite health: verdict, trust score, load time, page title (default: true)
check_techbooleanTech stack: framework, hosting, CDN, third-party (default: true)
check_secretsbooleanSecret scan: HTML/JS keys, exposed .env/.git, GraphQL (default: true; depth via scan_depth)
scan_depthstringquick=light scan, 3 bundles (default); deep=full supply URL phase with JWT decode, source maps, verification (~8-12s)
check_apisbooleanProbe /api/health and common API paths — adds ~1-2s (default: false)
check_networkbooleanHTTP network timing table — slow requests, API probes (default: true)
security_depthstringbasic=fast (default); full adds DNS SPF/DMARC/DKIM + HSTS preload lookup
timeout_msnumberMax scan time in ms (default: 8000, max: 15000)
focusstringTrim output layers (default: all)
include_fix_snippetsbooleanInclude Nginx/Vercel/Next fix snippets — token-heavy (default: false)
probe_enginestringfetch=HTTP only (default); browser=headless Chrome on Zephex servers for console errors + browser network (falls back to fetch with warning if unavailable)
check_packageVerify a public registry package before the agent recommends, installs, or changes a dependency. ALWAYS call when the user says install, add a package, add a dependency, upgrade, bump, migrate, is this package safe, is this name real, check CVEs, vulnerability, deprecation, slopsquatting, supply-ch…

Verify a public registry package before the agent recommends, installs, or changes a dependency. ALWAYS call when the user says install, add a package, add a dependency, upgrade, bump, migrate, is this package safe, is this name real, check CVEs, vulnerability, deprecation, slopsquatting, supply-ch…

ParameterTypBeschreibung
package*stringPackage name on the public registry — e.g. next, stripe, prisma, express, @supabase/supabase-js.
taskstringOne goal per call: check=safe to add; security=CVEs for version; upgrade=version bump plan; migrate=major-version migration; debug=version-specific release clu…
versionstringInstalled or pinned version. Pass for task=check|security so advisories are evaluated against the user's actual version.
from_versionstringVersion being changed from. Pass for task=upgrade|migrate|debug so release notes and advisories are version-specific.
sourcestringOptional. local = read pinned version from disk (stdio only). Prefer passing version/from_version directly.
ecosystemstringRegistry (default npm, auto-detected). Omit for next/stripe/prisma.
channelstringINTERNAL: Zephex terminal CLI only. Agents must omit — returns richer fields than agent-safe JSON.
cli_depthstringINTERNAL: CLI terminal depth. Agents must omit.
check_testRun the project's real test suite and return structured health — the same engine as the terminal command zephex check test. Detects bun, vitest, jest, pytest, go test, and cargo. Parses JUnit plus lcov (not a regex over stdout). Returns summary, a plain card (what broke, why clusters, coverage, war…

Run the project's real test suite and return structured health — the same engine as the terminal command zephex check test. Detects bun, vitest, jest, pytest, go test, and cargo. Parses JUnit plus lcov (not a regex over stdout). Returns summary, a plain card (what broke, why clusters, coverage, war…

ParameterTypBeschreibung
taskstringrun = execute the suite (stores a session). detect = see runner, do not execute. failures|status|list|coverage|fix_prompt|why = read the last session (no re-ru…
pathstringProject folder. Local/stdio: omit to use the editor cwd (tests run on their machine), or pass the absolute folder. Hosted: public GitHub URL or inline_files —…
session_idstringFrom a prior task=run (ts_*). Reuse for failures/status/list/why/fix_prompt so you do not re-run. Omit on stdio to read the last run on this machine.
file_filterstringSubstring or glob fragment to filter test_files (e.g. auth, handlers)
areastringScope to module/area name derived from test paths (e.g. proxy, auth, handlers)
questionstringNatural-language follow-up for task:why (e.g. "what failed in proxy?")
commandstringOverride auto-detected test command
with_coveragebooleanCollect lcov coverage (default true)
failed_onlybooleanRe-run only tests that failed in the prior session
diff_basestringGit branch for patch coverage and failures_in_diff (e.g. main) — use after edits
include_flakybooleanInclude flaky test hints from local history
include_missingbooleanGit-diff scan for source files without matching tests (default true on detect and when diff_base set)
timeout_msnumberMax run time ms (default 1800000 stdio, capped 600000 hosted)
detail_levelstringToken budget: brief <500 tokens on PASS; agent default; full=all slices
coverage_topnumberMax files in coverage slice
limitnumberMax rows for task:history (1–20)
inline_filesobjectHosted fallback when github is unavailable: { "package.json": "...", "src/foo.test.ts": "..." }. Supports task detect and task run (temp dir on Railway). Inclu…
explain_architectureMap how files in the user's project connect — which files are hubs, what imports what, where auth/API/database live. Not file bodies. ALWAYS call when they ask how auth works, where login is checked, what's the database, how the API is wired, give me an overview of these files, or where do I patch…

Map how files in the user's project connect — which files are hubs, what imports what, where auth/API/database live. Not file bodies. ALWAYS call when they ask how auth works, where login is checked, what's the database, how the API is wired, give me an overview of these files, or where do I patch…

HINWEISLinks to undeclared domain: github.com
ParameterTypBeschreibung
pathstringThe user's project folder. Local/stdio: omit to use editor cwd, or pass the absolute folder. Hosted with no disk: omit and use inline_files, or a public GitHub…
project_pathstringAlias for 'path' (some clients pass this name). Accepts the same values.
inline_filesobjectFallback for remote transports. Shape: { "": "" }. Include 10-50 SOURCE files (entry points, routes, middleware, auth, DB setup) plus package.json. For local s…
focusstringWiring slice. Default: api. auth=validation chain, integrations=external SDK touchpoints, database=ORM, security=auth+errors, full=all analyzers.
concernstringAny subsystem label (folder name, feature codename, module). Uses find_code concept search + import graph — not a fixed keyword list. Returns roles, edges, sym…
seed_filesarray1–20 paths from find_code — graph expands to related modules. Use with or without concern.
modestringoverview=fast wiring map (no AST flow trace), deep=request_flows + sequenceDiagram, audit=anti_patterns + health_score. Default: overview
verbositystringOutput size. minimal=core only, standard=default, full=adds constraints + state_management. Alias: detail_level
detail_levelstringLegacy alias for verbosity
subpathstringMonorepo scope — analyze only this subdirectory (e.g. apps/api). Faster than whole repo.
forcebooleanBypass architecture result cache. Default false.
excludearrayOptional glob patterns to exclude from ripgrep (vendor, build, etc.).
find_codeSearch the user's project when you do not know which file holds something. Ranked hits; the definition of that name comes first, not a call site like const user = await name(). ALWAYS call instead of guessing a path. ALWAYS call when the user says where is, find, who uses, usages, or rename X every…

Search the user's project when you do not know which file holds something. Ranked hits; the definition of that name comes first, not a call site like const user = await name(). ALWAYS call instead of guessing a path. ALWAYS call when the user says where is, find, who uses, usages, or rename X every…

ParameterTypBeschreibung
query*stringRequired. Text to find: pasted editor line, symbol name (validateToken), or topic keyword (encrypt).
pathstringThe user's project folder. Local/stdio: omit to use editor cwd, or pass the absolute folder. Hosted: public GitHub URL or inline_files.
intentstringSearch mode. snippet=paste exact line. symbol=find definition. concept=topic hunt. everywhere=all hits before rename.
also_tryarrayExtra keywords merged in parallel. concept=topic synonyms. everywhere=rename variants (crystal, CRYSTAL, crystal-app).
includestringLimit file types. code=src. docs=md/readme. config=json/yaml. data=sql/prisma. all=default.
file_patternstringCustom glob; overrides include. Examples: src/**/*.ts, **/*.md.
whole_wordbooleanWith intent everywhere. true = whole word only (Crystal not Crystalline). Use before renames.
case_sensitivebooleantrue = match exact casing (Crystal vs crystal). Default false.
inline_filesobjectHosted MCP only: {"path/to/file.ts": "file contents"}. Use when path disk is unavailable.
response_formatstringconcise=line preview per hit. detailed=full function/class block when AST available.
get_project_contextAnswer what the user's project is — name, stack, how to run/test/build, auth, database, deploy, folder layout — from their files on disk, not from training data. ALWAYS call this before you invent npm/pip/cargo commands or read package.json yourself. ALWAYS call when the user says: what is this app…

Answer what the user's project is — name, stack, how to run/test/build, auth, database, deploy, folder layout — from their files on disk, not from training data. ALWAYS call this before you invent npm/pip/cargo commands or read package.json yourself. ALWAYS call when the user says: what is this app…

ParameterTypBeschreibung
pathstringThe user's project folder. Local/stdio: omit to use editor cwd, or pass the absolute folder (any OS). Hosted with no disk: omit and use inline_files.
inline_filesobjectPrimary way to supply code. Shape: { "": "", ... }. The VALUE is the actual file body — never a filename, path, or placeholder. Example: { "package.json": "{"n…
forcebooleanSet true to re-detect even if cached (use when project changed)
topicstringWhich slice to return (one per call). identity=project name/type + which topics apply; run=dev/test/build/lint commands; framework=language/runtime/package man…
detail_levelstringOutput tier: "brief" (default, ≤500 tokens), "standard" (full fields), "full" (all fields + file tree)
include_structurebooleanWhen true, includes file tree in response (also triggered by detail_level: full)
structure_depthnumberMax folder depth for file tree scan (default: 3, max: 6)
focus_onstringSubdirectory to focus the file tree scan on (e.g. 'src/tools')
keep_thinkingStructure multi-step debugging and planning across tool calls — not a one-shot think. Tracks hypotheses, observations, plans; detects loops via lastActions; riskLevel high/critical blocks dangerous edits (drop table, prod deploy). Loads projectBrief (stack, key_paths, project_memory recall) on loca…

Structure multi-step debugging and planning across tool calls — not a one-shot think. Tracks hypotheses, observations, plans; detects loops via lastActions; riskLevel high/critical blocks dangerous edits (drop table, prod deploy). Loads projectBrief (stack, key_paths, project_memory recall) on loca…

ParameterTypBeschreibung
thought*stringReasoning (20–2000 chars) — file names, symbols, error messages.
thoughtNumber*integer1-based thought index in this session.
totalThoughts*integerEstimated thoughts needed (revise upward if needed).
nextThoughtNeeded*booleanfalse ends session and writes checkpoint.
confidence*number0–1. Below 0.5 forces revision. Above 0.85 safe to proceed.
thoughtType*stringhypothesis|debug for investigation; plan|conclusion before acting.
goalAnchorstringOne sentence restating the task — required after thought 2.
revisesintegerThought number this revision replaces.
assumptionsarrayUp to 5 assumptions; set invalidated:true when contradicted.
toolOutputRelevancestringClassify last tool result — 3+ noise/error in last 5 triggers loop.
sessionIdstringResume prior session; restores checkpoint on thought 1.
actionReadybooleantrue when done planning and about to execute edits.
lastActionsarrayLast 2–5 tool calls as name(arg=val) — identical pair triggers boredLoopDetected.
areastringSubsystem (auth, billing, api) — scopes project_memory recall.
projectPathstringLocal project root (stdio defaults to cwd) for projectBrief.
project_memorySave project notes that must survive this chat — rules, conventions, decisions, gotchas, preferences. Writes notes. Does not read source files. ALWAYS call when they say remember, save this, don't forget, write this down, keep this, my rule, our convention, I always want, last time, what did we dec…

Save project notes that must survive this chat — rules, conventions, decisions, gotchas, preferences. Writes notes. Does not read source files. ALWAYS call when they say remember, save this, don't forget, write this down, keep this, my rule, our convention, I always want, last time, what did we dec…

ParameterTypBeschreibung
action*stringremember=save a note, recall=search notes and return full content, list=recent notes with preview, forget=delete by id
pathstringFolder these notes belong to. Same string on remember, recall, and list. Stdio: optional (editor cwd). Hosted: reuse that folder string (or normalized_path fro…
titlestringRequired for remember. Max 80 chars.
contentstringRequired for remember. Up to 12000 characters (~2000 words). Write the why and the trap — not a one-liner.
typestringRequired for remember. decision=chose an approach; gotcha=non-obvious bug; goal=what we are building toward; preference=user style; area_fact=fact about a subs…
areastringSubsystem label (auth, billing, deploy) — included in search index for scoped recall. Max 64 chars.
tagsarrayOptional lowercase tags. Max 10.
written_bystringWho authored this memory.
querystringRequired for recall. Short keywords from the title or topic (e.g. auth middleware stripe).
idstringRequired for forget. Memory uuid.
limitnumberrecall/list cap. Default 10, max 20.
scopestringproject=this folder only (default). personal=notes that apply everywhere. all=every project — only when they ask to search everything.
read_codeRead a known symbol or file from the user's project without dumping the whole tree. AST extract — signature plus body — cheaper than opening a 2,000-line file. ALWAYS call when find_code just returned a name or path, when the user named a function to inspect, or before you edit a large file. If the…

Read a known symbol or file from the user's project without dumping the whole tree. AST extract — signature plus body — cheaper than opening a 2,000-line file. ALWAYS call when find_code just returned a name or path, when the user named a function to inspect, or before you edit a large file. If the…

ParameterTypBeschreibung
modestringsymbol=AST extract by name (default). file=batch read files[] (all paths return). outline=file TOC. scan=keyword/pattern hits across files[] (use target or tar…
pathstringThe user's project folder. Local/stdio: omit to use editor cwd, or pass the absolute folder. Hosted with no disk: use inline_files. Pair files[] from find_code.
inline_filesobjectWhen path disk is unavailable: {"src/auth.ts": ""}. Hosted/private transport fallback.
targetstringmode:symbol|callers|blast_radius — symbol name (fuzzy). mode:scan — keyword or regex to find across files[].
symbol_idstringWith mode:symbol. Direct lookup ID from a prior hit (e.g. src/auth.ts::validateUser#function). Skips fuzzy search.
targetsarraymode:symbol — batch symbol names (max 8, set max_results:10). mode:scan — multiple keywords in one pass across files[].
filesarrayWith mode:file|outline. Relative paths — from find_code hits. File mode: every path returns in one call (truncated per file if large, never dropped).
offset_linenumberWith mode:file. Start line (1-indexed). Use after batch read when data.hint says truncated.
limit_linesnumberWith mode:file. Max lines per file. Default: budget-based; set for pagination slices.
compactbooleanWith mode:file|symbol. true = omit line numbers to save tokens.
kindstringWith mode:symbol. Filter to one symbol kind — disambiguate class vs method with same name.
context_pathstringWith mode:symbol. File path hint for ranking (e.g. src/auth.ts when repo has many auth symbols).
detail_levelstringWith mode:symbol. signature=~100 tokens. body=full implementation (default). context=body+imports.
max_tokensnumberResponse size cap (default 2000, max 8000). File batch auto-shares across paths. Lower only if context is tight.
max_resultsnumbermode:symbol — max symbols (default 3, max 10). mode:scan|smell — max hits returned (default 30, max 100).
confidence_thresholdnumberWith mode:symbol. Min match confidence 0–1 (default 0.5). Raise 0.8 for exact; lower 0.3 to explore.
session_idstringDedup across turns — symbols already returned get a stub with symbol_id instead of full body.
Zephex_dev_infoExpert developer playbooks — not your repo. Stripe webhooks & checkout, Supabase RLS, Next.js auth (clerk, next-auth), payment flows, CSP/HSTS, deploy patterns. operation=search finds entries by question; operation=get returns full guidance by slug from search. Read summary and checklist first. 2 c…

Expert developer playbooks — not your repo. Stripe webhooks & checkout, Supabase RLS, Next.js auth (clerk, next-auth), payment flows, CSP/HSTS, deploy patterns. operation=search finds entries by question; operation=get returns full guidance by slug from search. Read summary and checklist first. 2 c…

ParameterTypBeschreibung
operationstringsearch=find by query (first step); get=full entry by slug from search.
querystringRequired for search — e.g. 'Supabase RLS for multi-tenant' or 'Next.js middleware auth'.
slugstringRequired for get — exact slug from a search hit.
categorystringOptional search filter — payments, auth, security, databases, etc.

10 von 10 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

MCP gateway with 10 tools for code analysis, architecture, package audit & security.

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Keine Abdeckung der Abhängigkeiten

Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.