io.github.springrolldev/springroll

MCPcomunidaden línea
v0.1.0io.github.springrolldevUnknownActualizado hace 1 m

Register, deploy, review, and govern internal applications built with coding agents.

Estado del endpointen línea
comprobado hace 6 días · 363 ms
100 % de las últimas 5 comprobaciones llegaron a este endpoint
Funciona en
ClaudeCursorCopilotChatGPTGemini

Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Indexado automáticamente desde fuentes públicas. Aún sin verificar por su desarrollador en Forge.Reclamar este listado →
hace 1 mÚltima actualización
Paquete
Autorio.github.springrolldev
LicenciaUnknown
Versión0.1.0
Fuentemcp-registry
Estado de confianza
B
60/100Bueno
✓Listado en el índice de Forge+10/10
—Identidad del publicador verificada+0/30
→ Publicador: este listado no tiene ningún repositorio registrado, así que `forge publish` no puede verificar la propiedad de forma automática. Usa «Reclamar este listado» arriba — en Forge lo revisamos a mano.
—Verificación de dominio+0/10
→ Ahora mismo no está disponible para este tipo de listado: hoy la comprobación de dominio solo se ejecuta para paquetes publicados en npm, así que esta fila todavía no se puede conseguir aquí, sea lo que sea lo que haya alojado en el dominio.
✓Análisis de inyección de prompts · limpio+30/30
✓Análisis de ofuscación / exfiltración · limpio+20/20
EstadoIndexado por la comunidad
PublicadorSin verificar
FirmaSin firmar
Dominio—
Procedencia—
DependenciasSin auditar
Superficie de herramientas15 herramientas · ninguna privilegiada
Análisis de seguridad✓ Limpiovlive · hace 6 d¿Qué tan bien funciona este análisis?
EvaluacionesNinguna
Indexado14 ago 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

15 herramientas · ninguna privilegiada
Observado en vivo desde el endpoint del proveedor6d ago

Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.

  • https://springroll.dev/api/mcp15 herramientas · 363 ms
springroll.contextReturns the organization, identity, and permissions this agent token acts as, together with the deployment runtimes configured for it. Call this first: it tells you which tenant you are in, what you are allowed to do, and whether a deployment can actually land. It never returns credentials.

Returns the organization, identity, and permissions this agent token acts as, together with the deployment runtimes configured for it. Call this first: it tells you which tenant you are in, what you are allowed to do, and whether a deployment can actually land. It never returns credentials.

ParámetroTipoDescripción
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.deployRegisters the project if it is new, attaches whatever source you give it, and deploys it using the application's Deployment workflow. Direct applications go to Production; Staged applications go to Development. Returns the live URL, or a deployment id to poll if the build is still running. **You d…

Registers the project if it is new, attaches whatever source you give it, and deploys it using the application's Deployment workflow. Direct applications go to Production; Staged applications go to Development. Returns the live URL, or a deployment id to poll if the build is still running. **You d…

ParámetroTipoDescripción
applicationstringAn existing app's slug or id. Omit on the first ship; `name` implies it.
namestring—
slugstring—
manifeststringA SpringRoll manifest. Supersedes the metadata fields below; the source fields still apply.
descriptionstring—
departmentstring—
supportContactstringTeam channel or email for users of this app. Required before production.
dataClassificationstring—
tagsarray—
repositoryUrlstring—
refstringBranch, tag, or full commit SHA. Defaults to the app's default revision.
archivestringBase64 of a gzipped tar of the project source. Preferred over `files`.
filesobjectPath-to-contents map. Use `archive` for anything beyond a few files.
filesEncodingstring—
preferSourcestringTie-breaker when both a repository and files are given. Defaults to git.
frameworkstring—
installCommandstring—
buildCommandstring—
outputDirectorystring—
rootDirectorystring—
placementobjectOptional, provider-neutral hints about what this application needs. SpringRoll chooses the provider and plan; these only inform that choice. Leave out anything…
waitSecondsintegerHow long to wait for the build before returning. Defaults to 20. A real build usually outlasts this; poll springroll.deploy.status after.
idempotencyKey*stringRequired. A stable, caller-generated key. Retrying with the same key returns the original result instead of creating a duplicate.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.deploy.statusReturns a deployment's current status, refreshing it from the runtime provider when the build is still in progress. Statuses: QUEUED, VALIDATING, BUILDING, DEPLOYING, READY, FAILED, CANCELLED, SUPERSEDED, ROLLED_BACK. Poll this after deploying rather than assuming success. Pass `includeLogs` to ge…

Returns a deployment's current status, refreshing it from the runtime provider when the build is still in progress. Statuses: QUEUED, VALIDATING, BUILDING, DEPLOYING, READY, FAILED, CANCELLED, SUPERSEDED, ROLLED_BACK. Poll this after deploying rather than assuming success. Pass `includeLogs` to ge…

ParámetroTipoDescripción
deploymentId*string—
includeLogsbooleanInclude build and deploy log lines. Defaults to false.
logLimitintegerHow many log lines to return, counting from the end. Defaults to 200.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.deploy.promotePromotes a tested deployment into the next environment (development -> uat, uat -> production). Reuses the already-built artifact rather than rebuilding, so the bytes that were tested are the bytes that ship. Promotion into an environment that requires approval will be refused until the approval e…

Promotes a tested deployment into the next environment (development -> uat, uat -> production). Reuses the already-built artifact rather than rebuilding, so the bytes that were tested are the bytes that ship. Promotion into an environment that requires approval will be refused until the approval e…

ParámetroTipoDescripción
deploymentId*stringThe tested deployment to promote.
targetEnvironmentType*stringCanonical environment class. SpringRoll promotes development -> uat -> production.
idempotencyKey*stringRequired. A stable, caller-generated key. Retrying with the same key returns the original result instead of creating a duplicate.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.placement.previewScores where SpringRoll would place this application and what it would cost, without deploying or writing anything. It shares its implementation with springroll.deploy, so the receipt it returns is what a deploy right now would decide: the provider and plan, the estimated monthly cost range, every…

Scores where SpringRoll would place this application and what it would cost, without deploying or writing anything. It shares its implementation with springroll.deploy, so the receipt it returns is what a deploy right now would decide: the provider and plan, the estimated monthly cost range, every…

ParámetroTipoDescripción
application*stringApplication slug or id.
environmentTypestringEnvironment class to score for. Defaults to production, which is the strictest: plans published as unsuitable for production are excluded there.
placementobjectOptional, provider-neutral hints about what this application needs. SpringRoll chooses the provider and plan; these only inform that choice. Leave out anything…
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.app.getReturns an application's registry record: metadata, lifecycle stage, risk score, and whichever of the optional sections you ask for. No secrets are included. Sections, all returned by default: • `source`: repository or uploaded bundle, and `cannotBuildReason` when a deploy would be refused for wa…

Returns an application's registry record: metadata, lifecycle stage, risk score, and whichever of the optional sections you ask for. No secrets are included. Sections, all returned by default: • `source`: repository or uploaded bundle, and `cannotBuildReason` when a deploy would be refused for wa…

ParámetroTipoDescripción
application*stringApplication slug or id.
includearraySections to return. Defaults to all of them.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.app.listLists applications in this organization, newest first. Use `search` to find one by name or slug.

Lists applications in this organization, newest first. Use `search` to find one by name or slug.

ParámetroTipoDescripción
searchstring—
limitinteger—
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.app.updateUpdates App Portal metadata: description, icon, tags, department, support contact, and data classification. Visibility is deliberately not editable here, because widening an audience requires an approval request (sec. 15.4).

Updates App Portal metadata: description, icon, tags, department, support contact, and data classification. Visibility is deliberately not editable here, because widening an audience requires an approval request (sec. 15.4).

ParámetroTipoDescripción
application*stringApplication slug or id.
descriptionstring—
iconUrlstring—
tagsarray—
departmentstring—
supportContactstring—
dataClassificationstring—
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.approval.submitSubmits an approval request of any supported type: UAT_PROMOTION, UAT_SIGN_OFF, PRODUCTION_PROMOTION, VISIBILITY_CHANGE, OWNERSHIP_TRANSFER, RETIREMENT, DOMAIN_CHANGE, or ROLLBACK. **An agent may submit but never decide**: SpringRoll requires a human approver, and an agent token cannot approve its…

Submits an approval request of any supported type: UAT_PROMOTION, UAT_SIGN_OFF, PRODUCTION_PROMOTION, VISIBILITY_CHANGE, OWNERSHIP_TRANSFER, RETIREMENT, DOMAIN_CHANGE, or ROLLBACK. **An agent may submit but never decide**: SpringRoll requires a human approver, and an agent token cannot approve its…

ParámetroTipoDescripción
application*stringApplication slug or id.
requestType*string—
releaseIdstringRelease this concerns. For PRODUCTION_PROMOTION, defaults to the latest release.
targetEnvironmentTypestringCanonical environment class. SpringRoll promotes development -> uat -> production.
justificationstringWhy this should happen. Shown to reviewers. Required for ROLLBACK and RETIREMENT, and at least 10 characters when required.
payloadobjectType-specific detail, e.g. { visibility: 'TENANT' }, { newOwnerMembershipId: '…' }, or { targetDeploymentId: '…' } for a rollback.
idempotencyKey*stringRequired. A stable, caller-generated key. Retrying with the same key returns the original result instead of creating a duplicate.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.approval.getReturns an approval request with its assigned reviewers, decisions so far, and the policy snapshot taken at submission. Poll this to find out whether a release has been approved.

Returns an approval request with its assigned reviewers, decisions so far, and the policy snapshot taken at submission. Poll this to find out whether a release has been approved.

ParámetroTipoDescripción
approvalRequestId*string—
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.policy.checkReports which governance policies an application would pass or fail for an environment. Send `manifest` (YAML or JSON) to validate a document without creating anything. Call this before springroll.deploy to avoid a rejected submission. Read the `springroll://manifest/example` resource for the docu…

Reports which governance policies an application would pass or fail for an environment. Send `manifest` (YAML or JSON) to validate a document without creating anything. Call this before springroll.deploy to avoid a rejected submission. Read the `springroll://manifest/example` resource for the docu…

ParámetroTipoDescripción
manifeststringThe manifest document, as YAML or JSON. Mutually exclusive with `application`.
applicationstringAn existing application to explain. Mutually exclusive with `manifest`.
environmentTypestringEnvironment to evaluate against. Defaults to production.
releaseIdstringRelease to evaluate. Only meaningful with `application`.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.connect.data_productsWithout `dataProduct`, lists the governed data products this organization publishes: what each one holds, who owns it, and how sensitive it is. With `dataProduct`, returns that product's schema: its datasets, the available fields with their types and sensitivity, the business glossary its owner wr…

Without `dataProduct`, lists the governed data products this organization publishes: what each one holds, who owns it, and how sensitive it is. With `dataProduct`, returns that product's schema: its datasets, the available fields with their types and sensitivity, the business glossary its owner wr…

ParámetroTipoDescripción
dataProductstringData product slug. Omit to list every product this organization publishes.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.connect.request_accessRequests access to a data product for one environment, naming the exact fields the application needs. A data owner must approve, and may narrow the field list or add a row filter before doing so. Nothing is readable until then. You never receive a credential: an approved grant lets the deployed app…

Requests access to a data product for one environment, naming the exact fields the application needs. A data owner must approve, and may narrow the field list or add a row filter before doing so. Nothing is readable until then. You never receive a credential: an approved grant lets the deployed app…

ParámetroTipoDescripción
application*stringApplication slug or id.
dataProduct*stringData product slug from springroll.connect.data_products.
environmentType*stringCanonical environment class. SpringRoll promotes development -> uat -> production.
fields*arrayQualified field names to request, as `dataset.field`. Ask for what the application actually reads, because a narrower request is approved faster and survives r…
purposestringWhy the application needs this data. Shown to the data owner.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.connect.access_statusReturns the status of a data access request: REQUESTED, APPROVED, REJECTED, REVOKED, or EXPIRED, with the fields actually approved. Approved fields are often narrower than requested, and a row filter may restrict which rows the application can see at all.

Returns the status of a data access request: REQUESTED, APPROVED, REJECTED, REVOKED, or EXPIRED, with the fields actually approved. Approved fields are often narrower than requested, and a row filter may restrict which rows the application can see at all.

ParámetroTipoDescripción
grantId*string—
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.app.record_promptsAttaches the conversation that produced this application to its record, as reference for whoever maintains it next and for the reviewer who has to approve it. Ask the user before calling this, every time. The transcript is STORED and is READABLE BY ANYONE who can see the application record. Spring…

Attaches the conversation that produced this application to its record, as reference for whoever maintains it next and for the reviewer who has to approve it. Ask the user before calling this, every time. The transcript is STORED and is READABLE BY ANYONE who can see the application record. Spring…

ParámetroTipoDescripción
application*stringApplication slug or id.
sessionKey*stringStable identifier for this build conversation.
turns*arrayUp to 50 turns per call, in order.
startTurnIndexintegerWhere this batch starts. Defaults to after the last recorded turn.
agentNamestring—
modelNamestring—
inputTokensinteger—
outputTokensinteger—
releaseIdstring—
idempotencyKey*stringRequired. A stable, caller-generated key. Retrying with the same key returns the original result instead of creating a duplicate.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…

15 de 15 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Register, deploy, review, and govern internal applications built with coding agents.

Palabras clave
mcp
Alternativas
Comparando superficies de herramientas…

Sin cobertura de dependencias

Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.