Stop your agent before it runs rm -rf /etc or emails your .env. Deterministic preflight checks.
Abgeleitet aus den Transporten, die dieser Eintrag deklariert (streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Aus einem echten MCP-Handshake initialize → tools/list gegen den deklarierten Endpunkt gelesen. Es wurde nie ein Tool aufgerufen — tools/list ist der lesende Introspektionsaufruf, den das Protokoll dafür vorsieht. Es spiegelt wider, was der Server in diesem Moment angeboten hat; ein gehosteter Endpunkt ist an keine Version gebunden und kann sich ohne Ankündigung ändern.
https://agent-utility-mcp.insivotron.workers.dev/mcp4 Tools · 228 msanalyze_url_riskAnalyze a URL for structural and security risk signals and return a deterministic, policy-aware decision (allow, notice, confirm or block) under the applicable policy — permissive, balanced or strict, balanced by default.Analyze a URL for structural and security risk signals and return a deterministic, policy-aware decision (allow, notice, confirm or block) under the applicable policy — permissive, balanced or strict, balanced by default.
| Parameter | Typ | Beschreibung |
|---|---|---|
| url* | string | The absolute URL to analyze. |
| policy | string | Optional policy used to compute the decision: permissive, balanced or strict (default: balanced). |
| context | object | Optional declarative context. |
inspect_commandprivilegiertAnalyze a shell command before execution and return a deterministic, policy-aware decision (allow, notice, confirm or block) without running it, under the applicable policy — permissive, balanced or strict, balanced by default. Paths outside a known workspace_root are treated as higher risk than pa…Analyze a shell command before execution and return a deterministic, policy-aware decision (allow, notice, confirm or block) without running it, under the applicable policy — permissive, balanced or strict, balanced by default. Paths outside a known workspace_root are treated as higher risk than pa…
| Parameter | Typ | Beschreibung |
|---|---|---|
| command* | string | The complete command text to inspect without executing it. |
| shell | string | The command shell, when known. |
| cwd | string | Optional working-directory context. It is never accessed. |
| policy | string | Optional policy used to compute the decision: permissive, balanced or strict (default: balanced). |
| context | object | Optional declarative context. |
inspect_fileInspect a Base64-encoded file locally for deterministic structural and security risk signals without executing it, and return a policy-aware decision (allow, notice, confirm or block) under the applicable policy — permissive, balanced or strict, balanced by default.Inspect a Base64-encoded file locally for deterministic structural and security risk signals without executing it, and return a policy-aware decision (allow, notice, confirm or block) under the applicable policy — permissive, balanced or strict, balanced by default.
| Parameter | Typ | Beschreibung |
|---|---|---|
| filename* | string | The original filename, including its extension. |
| content_base64* | string | The complete file content encoded as canonical Base64 (maximum decoded size: 1 MiB). |
| policy | string | Optional policy used to compute the decision: permissive, balanced or strict (default: balanced). |
| context | object | Optional declarative context. |
analyze_tool_callAnalyze a proposed AI-agent tool call before execution and return a deterministic, policy-aware decision (allow, notice, confirm or block) covering destructive actions, sensitive-data exposure, external transmission, privilege changes and irreversible operations, under the applicable policy — permi…Analyze a proposed AI-agent tool call before execution and return a deterministic, policy-aware decision (allow, notice, confirm or block) covering destructive actions, sensitive-data exposure, external transmission, privilege changes and irreversible operations, under the applicable policy — permi…
| Parameter | Typ | Beschreibung |
|---|---|---|
| tool_name* | string | The exact name of the proposed tool. |
| arguments* | — | The proposed tool arguments. They are analyzed as data and never executed. |
| policy | string | Optional policy used to compute the decision: permissive, balanced or strict (default: balanced). |
| context | object | Optional declarative context about the proposed operation. |
4 von 4 Tools haben eine Beschreibung veröffentlicht.
Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.
Stop your agent before it runs rm -rf /etc or emails your .env. Deterministic preflight checks.
Verlinkte Namen öffnen den Forge-Index aller Einträge, bei denen dieses Tool beobachtet wurde. Alle indexierten Tools durchsuchen.
Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.