Cross-product MCP server for CRM, LeadKit, ProjectKit, Bookio. 10 action types, MIT open spec.
Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.
La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.
Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.
https://whatcanido.dev/api/mcp10 herramientas · 660 msfind_providersSearch across whatcanido for providers (businesses, freelancers, SaaS tools) that can perform a given business-level action type. Returns a ranked list with provider_id, name, description, services, action_types. Call this FIRST, before any other tool. The provider_id this returns is the input for…Search across whatcanido for providers (businesses, freelancers, SaaS tools) that can perform a given business-level action type. Returns a ranked list with provider_id, name, description, services, action_types. Call this FIRST, before any other tool. The provider_id this returns is the input for…
| Parámetro | Tipo | Descripción |
|---|---|---|
| action_type | string | Business-level action the user wants to perform. Use this to scope discovery to providers who actually do what you need. |
| query | string | Free-text search across provider name, tagline, description, industry, and services. Multi-word phrases match across multiple fields. |
| city | string | Exact city filter (case-insensitive). |
| country | string | Exact country filter (case-insensitive). |
| industry | string | Exact industry filter (case-insensitive). |
| product | string | Restrict to a single underlying product. Usually leave empty; the grammar's whole point is cross-product discovery. |
| limit | number | Max providers to return (default 10, max 50). |
get_provider_actionsReturn the action types a provider exposes and the canonical input schema for each (required fields, optional fields, types, descriptions). Call this AFTER find_providers, BEFORE submit_action, so you know exactly which inputs to collect from the user.Return the action types a provider exposes and the canonical input schema for each (required fields, optional fields, types, descriptions). Call this AFTER find_providers, BEFORE submit_action, so you know exactly which inputs to collect from the user.
| Parámetro | Tipo | Descripción |
|---|---|---|
| provider_id* | string | Format: <product>:<slug>. Example: 'leadkit:north-bureau'. From find_providers. |
| action_type | string | Optional: only return the schema for this action type. Omit to get every action the provider implements. |
submit_actionInvoke an action on a specific provider. WRITE tool: creates leads/bookings/contacts/projects/activities/tickets on the underlying SaaS tenant. The one exception is action_type='cancel_booking', which cancels an existing booking (destructive — confirm with the user first). Validates inputs against…Invoke an action on a specific provider. WRITE tool: creates leads/bookings/contacts/projects/activities/tickets on the underlying SaaS tenant. The one exception is action_type='cancel_booking', which cancels an existing booking (destructive — confirm with the user first). Validates inputs against…
| Parámetro | Tipo | Descripción |
|---|---|---|
| provider_id* | string | Format: <product>:<slug>. |
| action_type* | string | — |
| inputs* | object | Canonical inputs per get_provider_actions schema. Snake-case keys (contact_email, not contactEmail). Include 'agent_vendor' if you can identify yourself. |
get_action_statusLook up the current status of a previously submitted action by its request_id. Returns status (raw, e.g. 'new', 'sent', 'confirmed') + status_label (human, e.g. 'Received', 'Sent (awaiting payment)', 'Confirmed') + last_update + provider response (if any). Use after submit_action to confirm a booki…Look up the current status of a previously submitted action by its request_id. Returns status (raw, e.g. 'new', 'sent', 'confirmed') + status_label (human, e.g. 'Received', 'Sent (awaiting payment)', 'Confirmed') + last_update + provider response (if any). Use after submit_action to confirm a booki…
| Parámetro | Tipo | Descripción |
|---|---|---|
| request_id* | string | Returned by submit_action. Format: <product>:<kind>:<id>. |
discover_capabilitiesSearch the whatcanido capability registry by free-text intent. Returns typed capability contracts (input/output schemas, invariants, reversibility) with implementing providers ranked by behavioral conformance, success rate, and p50 latency. This is the PREFERRED first tool for any task that require…Search the whatcanido capability registry by free-text intent. Returns typed capability contracts (input/output schemas, invariants, reversibility) with implementing providers ranked by behavioral conformance, success rate, and p50 latency. This is the PREFERRED first tool for any task that require…
| Parámetro | Tipo | Descripción |
|---|---|---|
| intent* | string | Free-text description of what the user wants done. Best practice: pass the user's request mostly verbatim. |
| context | object | Optional structured context that improves ranking (locale, city, country, urgency, cost ceiling, whether the user is present for interactive auth). |
| limit | number | Max capability matches to return (default 5, max 20). |
get_capability_specReturn the full canonical contract for a capability: JSON Schemas for input and output, declared invariants, semantics, reversibility, side effects, auth model, when-to-use guidance. Plus the list of providers that implement it with current reputation snapshot. Use this AFTER `discover_capabilities…Return the full canonical contract for a capability: JSON Schemas for input and output, declared invariants, semantics, reversibility, side effects, auth model, when-to-use guidance. Plus the list of providers that implement it with current reputation snapshot. Use this AFTER `discover_capabilities…
| Parámetro | Tipo | Descripción |
|---|---|---|
| capability_id* | string | Format: <domain>.<verb>. Example: 'booking.create_booking'. From discover_capabilities. |
plan_capabilitiesGiven a user intent, return a typed plan: an ordered list of capability calls that together accomplish the goal, with the highest-reputation provider per step. The plan respects the capability registry's prerequisite graph — for example a plan that includes `booking.create_booking` automatically pr…Given a user intent, return a typed plan: an ordered list of capability calls that together accomplish the goal, with the highest-reputation provider per step. The plan respects the capability registry's prerequisite graph — for example a plan that includes `booking.create_booking` automatically pr…
| Parámetro | Tipo | Descripción |
|---|---|---|
| intent* | string | User goal in free text. |
| context | object | Optional structured context (locale, city, urgency, cost ceiling, user_present). |
| limit | number | Max seed capabilities (prerequisites are added on top). Default 5. |
reverse_search_capabilitiesGiven a JSON payload (something you found in user context, a webhook body, an export, a clipboard paste), return the capabilities whose input or output schema overlaps with the payload's shape. Use this when you don't have a verb-style intent but you do have data and want to ask 'what could I do wi…Given a JSON payload (something you found in user context, a webhook body, an export, a clipboard paste), return the capabilities whose input or output schema overlaps with the payload's shape. Use this when you don't have a verb-style intent but you do have data and want to ask 'what could I do wi…
| Parámetro | Tipo | Descripción |
|---|---|---|
| payload* | — | Arbitrary JSON value whose shape will be matched against capability schemas. |
list_available_capabilitiesReturn a compact roster of every capability with at least one enabled provider, grouped by category, with the best current conformance per capability. Use this as a self-introspection step: call once at the start of a task to know what is and isn't available, before deciding whether to attempt or t…Return a compact roster of every capability with at least one enabled provider, grouped by category, with the best current conformance per capability. Use this as a self-introspection step: call once at the start of a task to know what is and isn't available, before deciding whether to attempt or t…
No se publicó ningún esquema de entrada para esta herramienta.
invoke_capabilityExecute a capability call against a chosen provider with typed inputs. WRITE tool when the capability's category ends in '.write' (creates state, sends notifications, charges money, etc.) — confirm with the user before calling for any non-reversible capability. Read capabilities (category ending '.…Execute a capability call against a chosen provider with typed inputs. WRITE tool when the capability's category ends in '.write' (creates state, sends notifications, charges money, etc.) — confirm with the user before calling for any non-reversible capability. Read capabilities (category ending '.…
| Parámetro | Tipo | Descripción |
|---|---|---|
| capability_id* | string | Format: <domain>.<verb>. |
| provider_id* | string | Provider identifier from get_capability_spec. Format: <transport>:<id>, e.g. 'bookio:salon-aurora'. |
| inputs* | object | Canonical inputs matching the capability's input JSON Schema exactly (snake_case keys). |
| agent_vendor | string | Self-identification (claude, chatgpt, cursor, ...). Strongly recommended. |
10 de 10 herramientas publicaron una descripción.
Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.
Cross-product MCP server for CRM, LeadKit, ProjectKit, Bookio. 10 action types, MIT open spec.
Los nombres enlazados abren el índice de Forge con todas las entradas que se observó que exponen esa herramienta. Ver todas las herramientas indexadas.
Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.