toolfactory

MCPcon attestation
v0.3.1io.github.GoatInAHatMITActualizado hace 2 dnpmGitHub

Build an agent tool once; ship it as Agent Skills, MCP servers, Agent Plugins / Claude / Codex / Cursor bundles, OpenClaw and Hermes plugins, CLIs, and packages, with the tests and releases to match.

Funciona en
ClaudeCursorCopilotGemini

Inferido de los transportes que declara este listado (stdio). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Build con attestation
Una attestation de procedencia verificada vincula este artefacto al repositorio listado. Nadie ha reclamado todavía el listado: esto demuestra dónde se construyó el código, no quién lo respalda.
271Descargas/sem.
hace 2 dÚltima actualización
Paquete
Autorio.github.GoatInAHat
LicenciaMIT
Versión0.3.1
Fuentenpm+mcp-registry
Estado de confianza
A
85/100Fiable
Listado en el índice de Forge+10/10
Identidad verificada · build con attestation+20/20
Firma de publicación Ed25519+0/5
Se incluye automáticamente cuando el publicador ejecuta `forge publish`
Verificación de dominio+0/5
Publicador: aloja /.well-known/forge.json en la página del paquete con { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
Coincidencia de maintainer en npm+0/5
Publicador: añade el login de GitHub verificado a los maintainers del paquete de npm (npm owner add <login>)
Análisis CVE · limpio+30/30
Análisis estático · limpio+20/20
Pégalo en Claude Code, Cursor o cualquier asistente de IA para corregir todas las carencias
EstadoIdentidad verificada
PublicadorSin verificar
FirmaSin firmar
Dominio
Procedencia✓ Verificado con Sigstore · c1d4f9a
Dependencias✓ 24 resueltas · ninguna vulnerable
Superficie de herramientas28 herramientas · ninguna privilegiada
Análisis de seguridad✓ Limpiov0.3.1 · hace 1 d¿Qué tan bien funciona este análisis?
EvaluacionesNinguna
Indexado8 sept 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

28 herramientas · ninguna privilegiada
Extraído estáticamente del paquete publicadov0.3.1 · 1d ago

Leído del código que npm publica realmente, en el momento del análisis. El paquete nunca se ejecutó. Las herramientas registradas dinámicamente en tiempo de ejecución, o escondidas en código empaquetado o minificado, pueden pasarse por alto — así que esto es un mínimo de la superficie de herramientas, no un censo completo.

echokey

key

No se publicó ningún esquema de entrada para esta herramienta.

scrapeSin descripción publicada

Esta herramienta no publicó ninguna descripción. Forge no se la inventa.

summarizeSin descripción publicada

Esta herramienta no publicó ninguna descripción. Forge no se la inventa.

loginSin descripción publicada

Esta herramienta no publicó ninguna descripción. Forge no se la inventa.

screenshotCapture the current page.

Capture the current page.

No se publicó ningún esquema de entrada para esta herramienta.

notifyPost a message into the live conversation.

Post a message into the live conversation.

No se publicó ningún esquema de entrada para esta herramienta.

browseService region.

Service region.

No se publicó ningún esquema de entrada para esta herramienta.

regionService region.

Service region.

No se publicó ningún esquema de entrada para esta herramienta.

shootSay hello

Say hello

No se publicó ningún esquema de entrada para esta herramienta.

webOpen the generated operations page.

Open the generated operations page.

No se publicó ningún esquema de entrada para esta herramienta.

adoptStop regenerating one file; it becomes the author's (recorded as manual in the lock).

Stop regenerating one file; it becomes the author's (recorded as manual in the lock).

No se publicó ningún esquema de entrada para esta herramienta.

bootstrap-repoPrepare the GitHub repository from the local .env: the `live-tests` environment with its required reviewers and the sensitive config keys inside it, the release registries' tokens at repository scope, GitHub Pages with source = Actions, and npm's trusted publisher. Values go to `gh` on stdin and ar…

Prepare the GitHub repository from the local .env: the `live-tests` environment with its required reviewers and the sensitive config keys inside it, the release registries' tokens at repository scope, GitHub Pages with source = Actions, and npm's trusted publisher. Values go to `gh` on stdin and ar…

No se publicó ningún esquema de entrada para esta herramienta.

buildGenerate every selected surface in-tree from the identity file and the operation snapshot, and refresh the lock.

Generate every selected surface in-tree from the identity file and the operation snapshot, and refresh the lock.

No se publicó ningún esquema de entrada para esta herramienta.

checkFail if the operation snapshot or any generated file drifted from the code (the CI drift gate).

Fail if the operation snapshot or any generated file drifted from the code (the CI drift gate).

No se publicó ningún esquema de entrada para esta herramienta.

coverageThe operation × surface verdict matrix: native, bridged, degraded, or excluded, with reasons.

The operation × surface verdict matrix: native, bridged, degraded, or excluded, with reasons.

No se publicó ningún esquema de entrada para esta herramienta.

doctorReport which upstream CLIs this machine can delegate to (git, gh, npm, uv, claude, openclaw, clawhub, hermes, uvx, agentskills, MCP Inspector, docker).

Report which upstream CLIs this machine can delegate to (git, gh, npm, uv, claude, openclaw, clawhub, hermes, uvx, agentskills, MCP Inspector, docker).

No se publicó ningún esquema de entrada para esta herramienta.

ejectAdopt every file a surface owns, so the author takes it over entirely.

Adopt every file a surface owns, so the author takes it over entirely.

No se publicó ningún esquema de entrada para esta herramienta.

gateRun the gate here, in order: build, the drift check, every selected surface's upstream validator, the author's checks and tests, and the credential-free host end-to-end. The same step list the generated ci.yml renders, so a project with no CI has the identical gate.

Run the gate here, in order: build, the drift check, every selected surface's upstream validator, the author's checks and tests, and the credential-free host end-to-end. The same step list the generated ci.yml renders, so a project with no CI has the identical gate.

No se publicó ningún esquema de entrada para esta herramienta.

initCreate a new tool: dev.toolfactory/tool.json, the authored identity file, the kernel scaffold for the chosen language, and the first build of every selected surface.

Create a new tool: dev.toolfactory/tool.json, the authored identity file, the kernel scaffold for the chosen language, and the first build of every selected surface.

No se publicó ningún esquema de entrada para esta herramienta.

introspectSpawn the kernel MCP server, list its tools, and snapshot them to dev.toolfactory/ops.json.

Spawn the kernel MCP server, list its tools, and snapshot them to dev.toolfactory/ops.json.

No se publicó ningún esquema de entrada para esta herramienta.

packageBuild every release asset into dist/release/ — npm tarball, Python distributions, OpenClaw plugin tarball, plugin bundle zip, web build, coverage — by the same steps the release workflow's package job runs. Publishing stays a CI concern.

Build every release asset into dist/release/ — npm tarball, Python distributions, OpenClaw plugin tarball, plugin bundle zip, web build, coverage — by the same steps the release workflow's package job runs. Publishing stays a CI concern.

No se publicó ningún esquema de entrada para esta herramienta.

review-promptEvaluate a prompt draft against the codex-prompt-standard rubric: anatomy sections, convention checks, and concrete directives. Draft, run this, fix what it flags, and re-run until it passes.

Evaluate a prompt draft against the codex-prompt-standard rubric: anatomy sections, convention checks, and concrete directives. Draft, run this, fix what it flags, and re-run until it passes.

No se publicó ningún esquema de entrada para esta herramienta.

secrets-usageEvery credential this project's surfaces need — the tool's own sensitive config keys and the release registries' tokens — with where each one is set, whether it is present locally and on GitHub, and (check) whether the registry accepts it. Never a value.

Every credential this project's surfaces need — the tool's own sensitive config keys and the release registries' tokens — with where each one is set, whether it is present locally and on GitHub, and (check) whether the registry accepts it. Never a value.

No se publicó ningún esquema de entrada para esta herramienta.

unadoptReturn an adopted file to toolfactory and regenerate it.

Return an adopted file to toolfactory and regenerate it.

No se publicó ningún esquema de entrada para esta herramienta.

unpublishRetract what a deselected surface used to publish. Git is the ledger: the previous tag's dev.toolfactory/tool.json says what was selected then, and every registry row that lost its surface is checked for the version that tag published and then retracted with the registry's own CLI — or reported wit…

Retract what a deselected surface used to publish. Git is the ledger: the previous tag's dev.toolfactory/tool.json says what was selected then, and every registry row that lost its surface is checked for the version that tag published and then retracted with the registry's own CLI — or reported wit…

No se publicó ningún esquema de entrada para esta herramienta.

validateRun each selected surface's own upstream validator (agentskills, claude plugin validate, MCP Inspector, openclaw, hermes, npm pack, uv build).

Run each selected surface's own upstream validator (agentskills, claude plugin validate, MCP Inspector, openclaw, hermes, npm pack, uv build).

No se publicó ningún esquema de entrada para esta herramienta.

helloSay hello

Say hello

No se publicó ningún esquema de entrada para esta herramienta.

nativeSin descripción publicada

Esta herramienta no publicó ninguna descripción. Forge no se la inventa.

24 de 28 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Build an agent tool once; ship it as Agent Skills, MCP servers, Agent Plugins / Claude / Codex / Cursor bundles, OpenClaw and Hermes plugins, CLIs, and packages, with the tests and releases to match.

Palabras clave
agentmcpskillsagent-pluginsopenclawhermesclaude-codecodexcursor
Alternativas
Comparando superficies de herramientas…

Árbol de dependencias

Lo que un análisis de Forge resolvió a partir de los metadatos de npm el 2026-09-17: resolución observada, no una declaración del publicador.

24 paquetes resueltos · 8 directos · ninguno con avisos de seguridad La resolución se detiene en la profundidad 4 y en 60 paquetes.

No se siguen: peerDependencies. Este árbol cubre solo dependencias en tiempo de ejecución, así que lo que estas arrastren nunca se resolvió.