Secure Linux desktop automation - input, screen/OCR/vision, AT-SPI2 UI tree, window, clipboard
ULTRANIX_MCP_API_KEYAPI-SchlüsseloptionalAPI key(s) (uxcp_*) for HTTP transport auth - required for --transport http (fail-closed), unused on stdio
ULTRANIX_MCP_HISTORY_SECRETAPI-SchlüsseloptionalAES-256-GCM secret for encrypted action history (per-install generated if unset)
ULTRANIX_MCP_SENTRY_DSNAPI-SchlüsseloptionalOptional Sentry DSN for error reporting (unset = disabled)
ULTRANIX_MCP_AUDIT_SECRETAPI-SchlüsseloptionalOptional HMAC-SHA256 signing secret for audit.jsonl lines (tamper evidence for SIEM ingestion)
Vom Autor in der offiziellen MCP-Registry angegeben. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Forge hat zu diesem Eintrag keinen Scan verzeichnet und hat daher keine Beobachtung seiner Tool-Oberfläche. Das ist das Fehlen eines Belegs, nicht der Beleg, dass er keine Tools offenlegt.
Secure Linux desktop automation - input, screen/OCR/vision, AT-SPI2 UI tree, window, clipboard
Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.