Inspect webhooks on localhost without an account. Permanent slugs need OpenWebhook Pro.
Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.
OPENWEBHOOK_TOKENClé d’APIfacultatifOptional Pro token for permanent slugs. Leave empty for an anonymous inspect URL.
Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.
Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.
url.inspectGet the current anonymous HTTPS ingest URL for this process. Call this first, then watch.start with no slug.Get the current anonymous HTTPS ingest URL for this process. Call this first, then watch.start with no slug.
Aucun schéma d’entrée n’a été publié pour cet outil.
endpoint.listList permanent OpenWebhook slugs for the authenticated Pro account. Returns an empty list and a signup hint when no token is configured.List permanent OpenWebhook slugs for the authenticated Pro account. Returns an empty list and a signup hint when no token is configured.
Aucun schéma d’entrée n’a été publié pour cet outil.
endpoint.createCreate a permanent OpenWebhook slug such as billing. Requires OPENWEBHOOK_TOKEN. Use endpoint.list afterward to confirm.Create a permanent OpenWebhook slug such as billing. Requires OPENWEBHOOK_TOKEN. Use endpoint.list afterward to confirm.
Aucun schéma d’entrée n’a été publié pour cet outil.
endpoint.deleteDelete a permanent OpenWebhook endpoint. Pass the UUID from endpoint.list. This cannot be undone.Delete a permanent OpenWebhook endpoint. Pass the UUID from endpoint.list. This cannot be undone.
Aucun schéma d’entrée n’a été publié pour cet outil.
watch.startStart an in-memory SSE watch on the anonymous URL, or on a permanent slug with a Pro token. Call watch.wait next to receive the request.Start an in-memory SSE watch on the anonymous URL, or on a permanent slug with a Pro token. Call watch.wait next to receive the request.
Aucun schéma d’entrée n’a été publié pour cet outil.
watch.stopStop watching an endpoint and drop its local event buffer. Use after you are done inspecting, or before switching slugs.Stop watching an endpoint and drop its local event buffer. Use after you are done inspecting, or before switching slugs.
Aucun schéma d’entrée n’a été publié pour cet outil.
watch.waitWait for the next HTTP request on a watch started with watch.start. Returns method, path, headers, and body from the local buffer only.Wait for the next HTTP request on a watch started with watch.start. Returns method, path, headers, and body from the local buffer only.
Aucun schéma d’entrée n’a été publié pour cet outil.
watch.listList webhooks already stored in this process's ephemeral buffer. Call after watch.start; it does not wait for a new request.List webhooks already stored in this process's ephemeral buffer. Call after watch.start; it does not wait for a new request.
Aucun schéma d’entrée n’a été publié pour cet outil.
8 outils sur 8 ont publié une description.
Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.
Inspect webhooks on localhost without an account. Permanent slugs need OpenWebhook Pro.
Les noms cliquables ouvrent l’index Forge de toutes les entrées observées exposant cet outil. Parcourir tous les outils indexés.
L'exploration s'est arrêtée à la limite de profondeur 4. Tout ce qui se trouve en dessous n'a jamais été résolu.
L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.
36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)
53 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.
+41 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.
Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.