meshfleet

MCPattesté
v0.22.0UnknownMITMis à jour il y a 4 jnpmGitHub

Auditable multi-agent coordination for OpenCode — parallel agent fleets with P2P messaging, witnessed receipts, and quorum ratification. Who saw this, who approved it, prove it.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
217Téléch./sem.
1Étoiles GitHub
il y a 4 jDernière mise à jour
Paquet
AuteurUnknown
LicenceMIT
Version0.22.0
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
✓Listé dans l’index Forge+10/10
✓Identité vérifiée · build attesté+20/20
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Correspondance de mainteneur npm+0/5
→ Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance✓ Vérifié par Sigstore · 87bd059
Dépendances✓ 60 résolues+ · aucune vulnérable
Surface d’outils40 outils · 2 privilégiés
Analyse de sécurité✓ Proprev0.22.0 · il y a 1 jQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé2 oct. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

40 outils · 2 privilégiés
Extrait statiquement du paquet publiév0.22.0 · 1d ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

spawn_fleetprivilégiéSpawn parallel agents. Returns fleet_id. An agent banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.

Spawn parallel agents. Returns fleet_id. An agent banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.

Aucun schéma d’entrée n’a été publié pour cet outil.

fleet_statusCheck fleet and agent status.

Check fleet and agent status.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_fleetsList all fleets with summaries (agent count, status, completion).

List all fleets with summaries (agent count, status, completion).

Aucun schéma d’entrée n’a été publié pour cet outil.

set_fleet_timeoutSet a per-fleet timeout override (in milliseconds). Agents exceeding this are auto-failed.

Set a per-fleet timeout override (in milliseconds). Agents exceeding this are auto-failed.

Aucun schéma d’entrée n’a été publié pour cet outil.

collect_resultsGet fleet outputs and loss tally. Only result_contract ok can bank complete; refused, blocked, artifact_missing, invalid, or absent banks failed. Declared outcome, not quality. Check lost first.

Get fleet outputs and loss tally. Only result_contract ok can bank complete; refused, blocked, artifact_missing, invalid, or absent banks failed. Declared outcome, not quality. Check lost first.

Aucun schéma d’entrée n’a été publié pour cet outil.

send_messageSend a P2P message from one agent to another within the same fleet. Set to_agent_id to "*" to broadcast to every other agent in the fleet (each recipient acks independently; see get_receipts).

Send a P2P message from one agent to another within the same fleet. Set to_agent_id to "*" to broadcast to every other agent in the fleet (each recipient acks independently; see get_receipts).

Aucun schéma d’entrée n’a été publié pour cet outil.

send_messagesSend a batch of P2P messages in ONE ledger transaction — use instead of repeated send_message calls for bulk fan-out (much faster: the recipient inbox is updated once per batch, not once per message). Atomic: one invalid message rejects the whole batch. Max 1000 messages per call.

Send a batch of P2P messages in ONE ledger transaction — use instead of repeated send_message calls for bulk fan-out (much faster: the recipient inbox is updated once per batch, not once per message). Atomic: one invalid message rejects the whole batch. Max 1000 messages per call.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_inboxGet messages in an agent's inbox, optionally since a timestamp.

Get messages in an agent's inbox, optionally since a timestamp.

Aucun schéma d’entrée n’a été publié pour cet outil.

ack_messageAcknowledge a message, removing it from the agent's inbox. Writes an 'ack' receipt (per-recipient — a broadcast is acked independently by each recipient).

Acknowledge a message, removing it from the agent's inbox. Writes an 'ack' receipt (per-recipient — a broadcast is acked independently by each recipient).

Aucun schéma d’entrée n’a été publié pour cet outil.

receiptWrite a non-consuming receipt on a message — the audit primitive. Use actions like 'seen', 'r-ack' (approve), 'retracted'. Unlike ack_message, the message stays in the inbox. One receipt per (message, agent, action); repeat calls are idempotent.

Write a non-consuming receipt on a message — the audit primitive. Use actions like 'seen', 'r-ack' (approve), 'retracted'. Unlike ack_message, the message stays in the inbox. One receipt per (message, agent, action); repeat calls are idempotent.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_receiptsGet the full receipt trail for a message: who acked, who annotated, when. Answers 'who saw this and who acted on it'.

Get the full receipt trail for a message: who acked, who annotated, when. Answers 'who saw this and who acted on it'.

Aucun schéma d’entrée n’a été publié pour cet outil.

verify_ledgerAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

verify_ledger_v2Versioned verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Normal parent-server startup recovery or migration may initialize or change the configured ledger before tool dispatch. Returns the unchanged internal-consistency report inside meshfleet.…

Versioned verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Normal parent-server startup recovery or migration may initialize or change the configured ledger before tool dispatch. Returns the unchanged internal-consistency report inside meshfleet.…

Aucun schéma d’entrée n’a été publié pour cet outil.

verify_ledger_v3Opt-in verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Returns a detached meshfleet.verify/v3 report with one local consistency band per finding, derived only from its severity. Those labels are not provenance or confidence and do not establish…

Opt-in verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Returns a detached meshfleet.verify/v3 report with one local consistency band per finding, derived only from its severity. Those labels are not provenance or confidence and do not establish…

Aucun schéma d’entrée n’a été publié pour cet outil.

open_ratificationOpen a quorum vote ('council') over the fleet. Broadcasts a proposal; peers vote with cast_vote. Ratifies when approvals reach the quorum and every required signoff approves. Returns the proposal message_id.

Open a quorum vote ('council') over the fleet. Broadcasts a proposal; peers vote with cast_vote. Ratifies when approvals reach the quorum and every required signoff approves. Returns the proposal message_id.

Aucun schéma d’entrée n’a été publié pour cet outil.

cast_voteCast a vote on an open ratification. approve=true records approval, approve=false rejection. Re-casting CHANGES your effective vote (each change appends a new sequenced receipt — history is never rewritten); repeating your current vote is a no-op.

Cast a vote on an open ratification. approve=true records approval, approve=false rejection. Re-casting CHANGES your effective vote (each change appends a new sequenced receipt — history is never rewritten); repeating your current vote is a no-op.

Aucun schéma d’entrée n’a été publié pour cet outil.

tally_ratificationRead the live vote tally and current status (open / ratified / rejected / expired) of a ratification, and persist the status if it has reached a terminal state.

Read the live vote tally and current status (open / ratified / rejected / expired) of a ratification, and persist the status if it has reached a terminal state.

Aucun schéma d’entrée n’a été publié pour cet outil.

sweep_ratificationsEvaluate every open ratification now and persist any that reached a terminal state (deadline expiry, silent-approval, unreachable quorum). The server also sweeps automatically every AGENT_MESH_RATIFY_SWEEP_MS (default 60s).

Evaluate every open ratification now and persist any that reached a terminal state (deadline expiry, silent-approval, unreachable quorum). The server also sweeps automatically every AGENT_MESH_RATIFY_SWEEP_MS (default 60s).

Aucun schéma d’entrée n’a été publié pour cet outil.

register_capabilityRegister an agent's capabilities (role, skills, model) for routing.

Register an agent's capabilities (role, skills, model) for routing.

Aucun schéma d’entrée n’a été publié pour cet outil.

route_workRoute a work description to the best-matching registered agents by keyword + role/skill overlap scoring (with synonym expansion), weighted by routing feedback (success/fail history). top_n controls how many matches to return (default 1, max = fleet size).

Route a work description to the best-matching registered agents by keyword + role/skill overlap scoring (with synonym expansion), weighted by routing feedback (success/fail history). top_n controls how many matches to return (default 1, max = fleet size).

Aucun schéma d’entrée n’a été publié pour cet outil.

compile_route_candidatesOffline projection of caller-supplied route-candidate snapshots. Does not persist, rank, execute, authorize, wake, or contact providers.

Offline projection of caller-supplied route-candidate snapshots. Does not persist, rank, execute, authorize, wake, or contact providers.

Aucun schéma d’entrée n’a été publié pour cet outil.

recommend_routeAdvisory-only ranking over caller-supplied sanitized task traits and candidate snapshots. Does not persist, execute, authorize, wake agents, or contact providers.

Advisory-only ranking over caller-supplied sanitized task traits and candidate snapshots. Does not persist, execute, authorize, wake agents, or contact providers.

Aucun schéma d’entrée n’a été publié pour cet outil.

plan_speculative_backlogPure, caller-approved speculative backlog projection. Does not persist, execute, authorize, wake agents, contact providers, poll, allocate capacity, schedule, spend, send, or publish.

Pure, caller-approved speculative backlog projection. Does not persist, execute, authorize, wake agents, contact providers, poll, allocate capacity, schedule, spend, send, or publish.

Aucun schéma d’entrée n’a été publié pour cet outil.

record_routing_outcomeRecord whether a routed task succeeded or failed. Future route_work calls for the same agent weight their score by accumulated outcomes (Wilson-style). NOTE: outcomes are currently accumulated PER AGENT, not per capability — capability_key is recorded for forward compatibility but does not yet scop…

Record whether a routed task succeeded or failed. Future route_work calls for the same agent weight their score by accumulated outcomes (Wilson-style). NOTE: outcomes are currently accumulated PER AGENT, not per capability — capability_key is recorded for forward compatibility but does not yet scop…

Aucun schéma d’entrée n’a été publié pour cet outil.

list_agentsList all available premade agents from .opencode/agents/ directories.

List all available premade agents from .opencode/agents/ directories.

Aucun schéma d’entrée n’a été publié pour cet outil.

attach_agentAttach an agent to a running fleet. It banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.

Attach an agent to a running fleet. It banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.

Aucun schéma d’entrée n’a été publié pour cet outil.

pingMinimal liveness check. Returns { status: 'ok', timestamp }.

Minimal liveness check. Returns { status: 'ok', timestamp }.

Aucun schéma d’entrée n’a été publié pour cet outil.

subscribe_inboxSubscribe to an agent's inbox via Server-Sent Events (SSE). Returns a stream URL that the agent opens to receive real-time push of incoming P2P messages. Falls back to polling get_inbox if SSE is unreachable. If the operator set MESHFLEET_AUTH_TOKEN, requests to the stream must carry it (Authorizat…

Subscribe to an agent's inbox via Server-Sent Events (SSE). Returns a stream URL that the agent opens to receive real-time push of incoming P2P messages. Falls back to polling get_inbox if SSE is unreachable. If the operator set MESHFLEET_AUTH_TOKEN, requests to the stream must carry it (Authorizat…

Aucun schéma d’entrée n’a été publié pour cet outil.

subscribe_eventsSubscribe to the unified fleet-wide event stream via Server-Sent Events (SSE). Returns a stream URL that emits every ledger event (messages, receipts, ratifications, spawns, completions, discussions) as it is appended. Keep-alive :hb comment frames are sent every 30s. Optional fleet_id filter narro…

Subscribe to the unified fleet-wide event stream via Server-Sent Events (SSE). Returns a stream URL that emits every ledger event (messages, receipts, ratifications, spawns, completions, discussions) as it is appended. Keep-alive :hb comment frames are sent every 30s. Optional fleet_id filter narro…

Aucun schéma d’entrée n’a été publié pour cet outil.

get_healthFleet health + liveness. Pass verbosity="summary" for a smaller routine probe (entrypoints map omitted); default "full" is the full BuildIdentityReport. Use `get_build_identity` for diagnostics.

Fleet health + liveness. Pass verbosity="summary" for a smaller routine probe (entrypoints map omitted); default "full" is the full BuildIdentityReport. Use `get_build_identity` for diagnostics.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_build_identityFull BuildIdentityReport for the running install: package name/version, source_commit, entrypoint_count, per-entrypoint SHA-256 map, entrypoints_match_runtime bit. Diagnostic access to the install's identity.

Full BuildIdentityReport for the running install: package name/version, source_commit, entrypoint_count, per-entrypoint SHA-256 map, entrypoints_match_runtime bit. Diagnostic access to the install's identity.

Aucun schéma d’entrée n’a été publié pour cet outil.

save_fleet_templateSave a named fleet template (set of agent specs) for reuse. Names: lowercase letters, numbers, dashes, underscores.

Save a named fleet template (set of agent specs) for reuse. Names: lowercase letters, numbers, dashes, underscores.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_fleet_templatesList all saved fleet templates, sorted by name.

List all saved fleet templates, sorted by name.

Aucun schéma d’entrée n’a été publié pour cet outil.

spawn_from_templateprivilégiéReturn a fleet spec from a saved template, ready to pass to spawn_fleet.

Return a fleet spec from a saved template, ready to pass to spawn_fleet.

Aucun schéma d’entrée n’a été publié pour cet outil.

ask_peerOpen a bounded, two-agent Discussion: sends the root question and (optionally) explicitly reserves one peer attempt, then waits until the conversation deadline for a settled answer. Message arrival never starts an agent by itself — wake_peer:true is the explicit, budgeted authority to run the peer…

Open a bounded, two-agent Discussion: sends the root question and (optionally) explicitly reserves one peer attempt, then waits until the conversation deadline for a settled answer. Message arrival never starts an agent by itself — wake_peer:true is the explicit, budgeted authority to run the peer…

Aucun schéma d’entrée n’a été publié pour cet outil.

wake_agentAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

reply_discussionAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

get_discussionAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

record_work_receiptAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

get_work_receiptAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

34 outils sur 40 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Auditable multi-agent coordination for OpenCode — parallel agent fleets with P2P messaging, witnessed receipts, and quorum ratification. Who saw this, who approved it, prove it.

Mots-clés
mcpopencodeagentorchestrationswarmfleetp2ppeer-to-peermodel-context-protocolauditreceiptsquorummulti-agent
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-10-02 — résolution observée, et non une déclaration de l'éditeur.

60 paquets résolus · 2 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.

36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)

Déclarées mais non résolues

76 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.

+64 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.