bundlebox

MCPcon attestation
v0.8.0io.github.blackswanalphaMITActualizado hace 1 dnpmGitHub

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

Funciona en
ClaudeCursorCopilotGemini

Inferido de los transportes que declara este listado (stdio). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Build con attestation
Una attestation de procedencia verificada vincula este artefacto al repositorio listado. Nadie ha reclamado todavía el listado: esto demuestra dónde se construyó el código, no quién lo respalda.
150Descargas/sem.
2Estrellas en GitHub
hace 1 dÚltima actualización
Paquete
Autorio.github.blackswanalpha
LicenciaMIT
Versión0.8.0
Fuentenpm+mcp-registry
Estado de confianza
A
85/100Fiable
Listado en el índice de Forge+10/10
Identidad verificada · build con attestation+20/20
Firma de publicación Ed25519+0/5
Se incluye automáticamente cuando el publicador ejecuta `forge publish`
Verificación de dominio+0/5
Publicador: aloja /.well-known/forge.json en la página del paquete con { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
Coincidencia de maintainer en npm+0/5
Publicador: añade el login de GitHub verificado a los maintainers del paquete de npm (npm owner add <login>)
Análisis CVE · limpio+30/30
Análisis estático · limpio+20/20
Pégalo en Claude Code, Cursor o cualquier asistente de IA para corregir todas las carencias
EstadoIdentidad verificada
PublicadorSin verificar
FirmaSin firmar
Dominio
Procedencia✓ Verificado con Sigstore · 2907a91
Dependencias✓ 0 resueltas · ninguna vulnerable
Superficie de herramientas24 herramientas · ninguna privilegiada
Análisis de seguridad✓ Limpiov0.8.0 · hace 1 d¿Qué tan bien funciona este análisis?
EvaluacionesNinguna
Indexado22 sept 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

24 herramientas · ninguna privilegiada
Extraído estáticamente del paquete publicadov0.8.0 · 1d ago

Leído del código que npm publica realmente, en el momento del análisis. El paquete nunca se ejecutó. Las herramientas registradas dinámicamente en tiempo de ejecución, o escondidas en código empaquetado o minificado, pueden pasarse por alto — así que esto es un mínimo de la superficie de herramientas, no un censo completo.

intakewhat is wrong, found locally; ends holding lanes, the last point before anything spends

what is wrong, found locally; ends holding lanes, the last point before anything spends

No se publicó ningún esquema de entrada para esta herramienta.

orientwhat a session gets handed instead of searching

what a session gets handed instead of searching

No se publicó ningún esquema de entrada para esta herramienta.

measurewhat sessions cost, what the local path displaced, and what packing a task is worth

what sessions cost, what the local path displaced, and what packing a task is worth

No se publicó ningún esquema de entrada para esta herramienta.

opsis this box healthy

is this box healthy

No se publicó ningún esquema de entrada para esta herramienta.

buckmastertrain the process model on everything above, then turn it into automation

train the process model on everything above, then turn it into automation

No se publicó ningún esquema de entrada para esta herramienta.

situationwhat is happening right now: services, what is failing, and what the detectors see

what is happening right now: services, what is failing, and what the detectors see

No se publicó ningún esquema de entrada para esta herramienta.

genesisthe inlet: what the world declares that no scenario touches, packed to briefs

the inlet: what the world declares that no scenario touches, packed to briefs

No se publicó ningún esquema de entrada para esta herramienta.

scenariosrun the corpus against the running system and read what it means

run the corpus against the running system and read what it means

No se publicó ningún esquema de entrada para esta herramienta.

auditwhich areas have no current audit, and the briefs that would produce one

which areas have no current audit, and the briefs that would produce one

No se publicó ningún esquema de entrada para esta herramienta.

watchfold what was spent, and rebuild the one page that shows it

fold what was spent, and rebuild the one page that shows it

No se publicó ningún esquema de entrada para esta herramienta.

bootstrapbring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page

bring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page

No se publicó ningún esquema de entrada para esta herramienta.

factoryone tick of the whole free path: intake, orient, measure, buckmaster, watch

one tick of the whole free path: intake, orient, measure, buckmaster, watch

No se publicó ningún esquema de entrada para esta herramienta.

fullthe whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost

the whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost

No se publicó ningún esquema de entrada para esta herramienta.

practicefill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one

fill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one

No se publicó ningún esquema de entrada para esta herramienta.

bb_pinpointOne problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on file, the acceptance command, traps and guidelines. Call this BEFORE searching the tree.

One problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on file, the acceptance command, traps and guidelines. Call this BEFORE searching the tree.

No se publicó ningún esquema de entrada para esta herramienta.

bb_contextDoes this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cut.

Does this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cut.

No se publicó ningún esquema de entrada para esta herramienta.

bb_snapgenReference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `table` returns the INDEX with each table's token cost so you can choose. Read a table instead of grepping.

Reference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `table` returns the INDEX with each table's token cost so you can choose. Read a table instead of grepping.

No se publicó ningún esquema de entrada para esta herramienta.

bb_findingsOpen findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.

Open findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.

No se publicó ningún esquema de entrada para esta herramienta.

bb_scanRun the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.

Run the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.

No se publicó ningún esquema de entrada para esta herramienta.

bb_oversight_briefWhat is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editing. About 300 tokens.

What is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editing. About 300 tokens.

No se publicó ningún esquema de entrada para esta herramienta.

bb_explainOne finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).

One finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).

No se publicó ningún esquema de entrada para esta herramienta.

bb_tokens_estimateEstimated tokens per file and in total, with the calibrated estimator (not chars/4).

Estimated tokens per file and in total, with the calibrated estimator (not chars/4).

No se publicó ningún esquema de entrada para esta herramienta.

bb_situationWhere this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, and what the last echos run saw. Call this instead of git status + git diff + bb env + bb findings + bb echos.

Where this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, and what the last echos run saw. Call this instead of git status + git diff + bb env + bb findings + bb echos.

No se publicó ningún esquema de entrada para esta herramienta.

bb_sessionWhat the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

What the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

No se publicó ningún esquema de entrada para esta herramienta.

24 de 24 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

Palabras clave
mcp
Alternativas
Comparando superficies de herramientas…

Árbol de dependencias

Lo que un análisis de Forge resolvió a partir de los metadatos de npm el 2026-09-23: resolución observada, no una declaración del publicador.

0 paquetes resueltos · 0 directos · ninguno con avisos de seguridad La resolución se detiene en la profundidad 4 y en 60 paquetes.

Este paquete no declara dependencias en tiempo de ejecución.