toolfactory

MCPattestiert
v0.3.1io.github.GoatInAHatMITAktualisiert vor 2 TnpmGitHub

Build an agent tool once; ship it as Agent Skills, MCP servers, Agent Plugins / Claude / Codex / Cursor bundles, OpenClaw and Hermes plugins, CLIs, and packages, with the tests and releases to match.

Läuft in
ClaudeCursorCopilotGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Attestierter Build
Eine verifizierte Herkunfts-Attestation bindet dieses Artefakt an das gelistete Repository. Den Eintrag hat noch niemand beansprucht — das belegt, wo der Code gebaut wurde, nicht, wer dahintersteht.
271Downloads/Wo.
vor 2 TLetzte Aktualisierung
Paket
Autorio.github.GoatInAHat
LizenzMIT
Version0.3.1
Quellenpm+mcp-registry
Trust-Status
A
85/100Vertrauenswürdig
Im Forge-Index gelistet+10/10
Identität verifiziert · attestierter Build+20/20
Ed25519-Publish-Signatur+0/5
Wird automatisch ergänzt, wenn der Publisher `forge publish` ausführt
Domain-Verifizierung+0/5
Publisher: hinterlege /.well-known/forge.json auf der Paket-Homepage mit { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
npm-Maintainer-Übereinstimmung+0/5
Publisher: trage den verifizierten GitHub-Login als Maintainer des npm-Pakets ein (npm owner add <login>)
CVE-Scan · sauber+30/30
Statische Analyse · sauber+20/20
Füge das in Claude Code, Cursor oder einen beliebigen KI-Assistenten ein, um alle Lücken zu schließen
StatusIdentität verifiziert
PublisherNicht verifiziert
SignaturNicht signiert
Domain
Herkunft✓ Sigstore-verifiziert · c1d4f9a
Abhängigkeiten✓ 24 aufgelöst · keine verwundbar
Tool-Oberfläche28 Tools · keines privilegiert
Sicherheits-Scan✓ Sauberv0.3.1 · vor 1 TWie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert8. Sept. 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

28 Tools · keines privilegiert
Statisch aus dem veröffentlichten Paket extrahiertv0.3.1 · 1d ago

Aus dem Quellcode gelesen, den npm tatsächlich ausliefert, zum Zeitpunkt des Scans. Das Paket wurde nie ausgeführt. Tools, die zur Laufzeit dynamisch registriert werden oder in gebündeltem beziehungsweise minifiziertem Code stecken, können übersehen werden — das hier ist also eine Untergrenze der Tool-Oberfläche, keine vollständige Erhebung.

echokey

key

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

scrapeKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

summarizeKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

loginKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

screenshotCapture the current page.

Capture the current page.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

notifyPost a message into the live conversation.

Post a message into the live conversation.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

browseService region.

Service region.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

regionService region.

Service region.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

shootSay hello

Say hello

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

webOpen the generated operations page.

Open the generated operations page.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

adoptStop regenerating one file; it becomes the author's (recorded as manual in the lock).

Stop regenerating one file; it becomes the author's (recorded as manual in the lock).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

bootstrap-repoPrepare the GitHub repository from the local .env: the `live-tests` environment with its required reviewers and the sensitive config keys inside it, the release registries' tokens at repository scope, GitHub Pages with source = Actions, and npm's trusted publisher. Values go to `gh` on stdin and ar…

Prepare the GitHub repository from the local .env: the `live-tests` environment with its required reviewers and the sensitive config keys inside it, the release registries' tokens at repository scope, GitHub Pages with source = Actions, and npm's trusted publisher. Values go to `gh` on stdin and ar…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

buildGenerate every selected surface in-tree from the identity file and the operation snapshot, and refresh the lock.

Generate every selected surface in-tree from the identity file and the operation snapshot, and refresh the lock.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

checkFail if the operation snapshot or any generated file drifted from the code (the CI drift gate).

Fail if the operation snapshot or any generated file drifted from the code (the CI drift gate).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

coverageThe operation × surface verdict matrix: native, bridged, degraded, or excluded, with reasons.

The operation × surface verdict matrix: native, bridged, degraded, or excluded, with reasons.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

doctorReport which upstream CLIs this machine can delegate to (git, gh, npm, uv, claude, openclaw, clawhub, hermes, uvx, agentskills, MCP Inspector, docker).

Report which upstream CLIs this machine can delegate to (git, gh, npm, uv, claude, openclaw, clawhub, hermes, uvx, agentskills, MCP Inspector, docker).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

ejectAdopt every file a surface owns, so the author takes it over entirely.

Adopt every file a surface owns, so the author takes it over entirely.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

gateRun the gate here, in order: build, the drift check, every selected surface's upstream validator, the author's checks and tests, and the credential-free host end-to-end. The same step list the generated ci.yml renders, so a project with no CI has the identical gate.

Run the gate here, in order: build, the drift check, every selected surface's upstream validator, the author's checks and tests, and the credential-free host end-to-end. The same step list the generated ci.yml renders, so a project with no CI has the identical gate.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

initCreate a new tool: dev.toolfactory/tool.json, the authored identity file, the kernel scaffold for the chosen language, and the first build of every selected surface.

Create a new tool: dev.toolfactory/tool.json, the authored identity file, the kernel scaffold for the chosen language, and the first build of every selected surface.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

introspectSpawn the kernel MCP server, list its tools, and snapshot them to dev.toolfactory/ops.json.

Spawn the kernel MCP server, list its tools, and snapshot them to dev.toolfactory/ops.json.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

packageBuild every release asset into dist/release/ — npm tarball, Python distributions, OpenClaw plugin tarball, plugin bundle zip, web build, coverage — by the same steps the release workflow's package job runs. Publishing stays a CI concern.

Build every release asset into dist/release/ — npm tarball, Python distributions, OpenClaw plugin tarball, plugin bundle zip, web build, coverage — by the same steps the release workflow's package job runs. Publishing stays a CI concern.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

review-promptEvaluate a prompt draft against the codex-prompt-standard rubric: anatomy sections, convention checks, and concrete directives. Draft, run this, fix what it flags, and re-run until it passes.

Evaluate a prompt draft against the codex-prompt-standard rubric: anatomy sections, convention checks, and concrete directives. Draft, run this, fix what it flags, and re-run until it passes.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

secrets-usageEvery credential this project's surfaces need — the tool's own sensitive config keys and the release registries' tokens — with where each one is set, whether it is present locally and on GitHub, and (check) whether the registry accepts it. Never a value.

Every credential this project's surfaces need — the tool's own sensitive config keys and the release registries' tokens — with where each one is set, whether it is present locally and on GitHub, and (check) whether the registry accepts it. Never a value.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

unadoptReturn an adopted file to toolfactory and regenerate it.

Return an adopted file to toolfactory and regenerate it.

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

unpublishRetract what a deselected surface used to publish. Git is the ledger: the previous tag's dev.toolfactory/tool.json says what was selected then, and every registry row that lost its surface is checked for the version that tag published and then retracted with the registry's own CLI — or reported wit…

Retract what a deselected surface used to publish. Git is the ledger: the previous tag's dev.toolfactory/tool.json says what was selected then, and every registry row that lost its surface is checked for the version that tag published and then retracted with the registry's own CLI — or reported wit…

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

validateRun each selected surface's own upstream validator (agentskills, claude plugin validate, MCP Inspector, openclaw, hermes, npm pack, uv build).

Run each selected surface's own upstream validator (agentskills, claude plugin validate, MCP Inspector, openclaw, hermes, npm pack, uv build).

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

helloSay hello

Say hello

Für dieses Tool wurde kein Eingabeschema veröffentlicht.

nativeKeine Beschreibung veröffentlicht

Dieses Tool hat keine Beschreibung veröffentlicht. Forge erfindet keine.

24 von 28 Tools haben eine Beschreibung veröffentlicht.

Tool-Namen und -Beschreibungen stammen vom Publisher und werden wortgetreu als inerter Text angezeigt. Es sind die Zeichenketten, die ein MCP-Client an ein Modell übergibt, deshalb prüft Forge sie auf Prompt-Injection-Muster — jeder Befund erscheint oben beim Sicherheits-Scan. „Privilegiert“ ist ein Schlagwort-Treffer im Tool-Namen, keine Prüfung dessen, was das Tool tut: ein harmlos klingender Name kann trotzdem alles tun.

Über

Build an agent tool once; ship it as Agent Skills, MCP servers, Agent Plugins / Claude / Codex / Cursor bundles, OpenClaw and Hermes plugins, CLIs, and packages, with the tests and releases to match.

Schlagwörter
agentmcpskillsagent-pluginsopenclawhermesclaude-codecodexcursor
Alternativen
Tool-Oberflächen werden verglichen…

Abhängigkeitsbaum

Was ein Forge-Scan am 2026-09-17 aus den npm-Metadaten aufgelöst hat — beobachtete Auflösung, keine Angabe des Herausgebers.

24 Pakete aufgelöst · 8 direkt · keines mit Sicherheitshinweisen Die Auflösung endet bei Tiefe 4 und 60 Paketen.

Nicht verfolgt: peerDependencies. Dieser Baum erfasst nur Laufzeitabhängigkeiten; was jene mitbringen, wurde nie aufgelöst.