Agent governance with A2A/Shopify/MCP trust audits, action screening, and decision UI.
Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.
La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.
Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.
https://cibcxqrqiqvzpardbdrw.supabase.co/functions/v1/ghosbc-safety-gate-mcp9 herramientas · 1294 msaudit_a2a_agent_cardUse before depending on an unfamiliar A2A agent. Reads only the public Agent Card and optional public registry metadata, checks declared bindings/protocol versions, skill descriptions, security declarations and registry task-verification evidence, then returns a trust/readiness score plus shareable…Use before depending on an unfamiliar A2A agent. Reads only the public Agent Card and optional public registry metadata, checks declared bindings/protocol versions, skill descriptions, security declarations and registry task-verification evidence, then returns a trust/readiness score plus shareable…
| Parámetro | Tipo | Descripción |
|---|---|---|
| card_url* | string | Public HTTPS A2A Agent Card URL, normally /.well-known/agent-card.json. |
audit_shopify_agentic_storefrontUse to inspect a public Shopify store's AI-shopping surface before an autonomous agent trusts it. Reads only public /.well-known/ucp, /agents.md and /api/ucp/mcp metadata, runs initialize/tools/list, screens exposed tool definitions, and returns a readiness/risk packet. It never creates or mutates…Use to inspect a public Shopify store's AI-shopping surface before an autonomous agent trusts it. Reads only public /.well-known/ucp, /agents.md and /api/ucp/mcp metadata, runs initialize/tools/list, screens exposed tool definitions, and returns a readiness/risk packet. It never creates or mutates…
| Parámetro | Tipo | Descripción |
|---|---|---|
| store* | string | Public Shopify store domain or HTTPS URL, for example store.myshopify.com. |
audit_mcp_dependencyUse for a public remote MCP server that an autonomous agent depends on. Remembers the tools/list baseline, returns only added/removed/modified tools, screens new or changed tool definitions, and produces one aggregate ALLOW/REVIEW/BLOCK decision. It does not inspect server source code or authentica…Use for a public remote MCP server that an autonomous agent depends on. Remembers the tools/list baseline, returns only added/removed/modified tools, screens new or changed tool definitions, and produces one aggregate ALLOW/REVIEW/BLOCK decision. It does not inspect server source code or authentica…
| Parámetro | Tipo | Descripción |
|---|---|---|
| endpoint_url* | string | Public HTTPS MCP endpoint. |
screen_agent_requestUse before an agent follows untrusted instructions or requests capabilities. Returns ALLOW, REVIEW, or BLOCK plus an audit digest. Best for prompt/policy routing; use screen_consequential_action for a concrete purchase, write, deployment, deletion or other bounded action.Use before an agent follows untrusted instructions or requests capabilities. Returns ALLOW, REVIEW, or BLOCK plus an audit digest. Best for prompt/policy routing; use screen_consequential_action for a concrete purchase, write, deployment, deletion or other bounded action.
| Parámetro | Tipo | Descripción |
|---|---|---|
| text* | string | — |
| capabilities | array | — |
| mode | string | — |
screen_mcp_tool_definitionUse before exposing a third-party MCP tool to an autonomous agent, or after a tool definition changed. Screens name, description, schema and annotations for injection-like language, credential/private-context surfaces, side-effect risk and weak contracts. Advisory metadata gate, not source-code ver…Use before exposing a third-party MCP tool to an autonomous agent, or after a tool definition changed. Screens name, description, schema and annotations for injection-like language, credential/private-context surfaces, side-effect risk and weak contracts. Advisory metadata gate, not source-code ver…
| Parámetro | Tipo | Descripción |
|---|---|---|
| name* | string | — |
| description | string | — |
| inputSchema | object | null | — |
| annotations | object | null | — |
screen_consequential_actionUse immediately before a consequential agent action such as purchase, payment, transfer, send, deploy, publish, execute, cart mutation, checkout mutation, or delete. Compares the proposed action with caller-declared allowed actions/targets, amount ceiling, currency and expiry. ALLOW only when expli…Use immediately before a consequential agent action such as purchase, payment, transfer, send, deploy, publish, execute, cart mutation, checkout mutation, or delete. Compares the proposed action with caller-declared allowed actions/targets, amount ceiling, currency and expiry. ALLOW only when expli…
| Parámetro | Tipo | Descripción |
|---|---|---|
| action* | string | — |
| target | string | — |
| amount | number | — |
| currency | string | — |
| constraints | object | — |
sanitize_agent_payloadUse before sending context to an external model, tool or agent when the payload may contain credentials or private material. Redacts common secret patterns and flags policy-extraction language. Not a complete DLP/compliance system.Use before sending context to an external model, tool or agent when the payload may contain credentials or private material. Redacts common secret patterns and flags policy-extraction language. Not a complete DLP/compliance system.
| Parámetro | Tipo | Descripción |
|---|---|---|
| payload* | — | — |
validate_agent_responseUse immediately before an agent delivers a response outside its trust boundary. Flags likely credential leakage or policy-extraction content and returns a sanitized response when review is needed. Not factuality verification.Use immediately before an agent delivers a response outside its trust boundary. Flags likely credential leakage or policy-extraction content and returns a sanitized response when review is needed. Not factuality verification.
| Parámetro | Tipo | Descripción |
|---|---|---|
| response* | — | — |
buy_policy_checksUse only when free usage is exhausted or production volume is needed. Returns Stripe checkout for 10,000 prepaid GHOSBC Safety Gate checks for $19; it does not charge or receive payment credentials.Use only when free usage is exhausted or production volume is needed. Returns Stripe checkout for 10,000 prepaid GHOSBC Safety Gate checks for $19; it does not charge or receive payment credentials.
No se publicó ningún esquema de entrada para esta herramienta.
9 de 9 herramientas publicaron una descripción.
Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.
Agent governance with A2A/Shopify/MCP trust audits, action screening, and decision UI.
Los nombres enlazados abren el índice de Forge con todas las entradas que se observó que exponen esa herramienta. Ver todas las herramientas indexadas.
Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.