pitroom

MCPattesté
v0.23.0io.github.ATASTECHMITMis à jour il y a 1 jnpmGitHub

Hands bounded coding work to cheaper worker agents: verified answers, exact diffs, cost receipts.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
4kTéléch./sem.
24Étoiles GitHub
2Forks
il y a 1 jDernière mise à jour
Paquet
Auteurio.github.ATASTECH
LicenceMIT
Version0.23.0
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
✓Listé dans l’index Forge+10/10
✓Identité vérifiée · build attesté+20/20
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Correspondance de mainteneur npm+0/5
→ Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance✓ Vérifié par Sigstore · 8647528
Dépendances✓ 0 résolues · aucune vulnérable
Surface d’outils21 outils · 1 privilégiés
Analyse de sécurité✓ Proprev0.23.0 · aujourd’huiQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé9 oct. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

21 outils · 1 privilégiés
Extrait statiquement du paquet publiév0.23.0 · 5h ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

run-reportThe report of a run: answer, receipt, verified references.

The report of a run: answer, receipt, verified references.

Aucun schéma d’entrée n’a été publié pour cet outil.

run-patchprivilégiéThe exact diff an isolated or in-place run made.

The exact diff an isolated or in-place run made.

Aucun schéma d’entrée n’a été publié pour cet outil.

researchFind, map or explain code through a read-only worker, and verify what comes back.

Find, map or explain code through a read-only worker, and verify what comes back.

Aucun schéma d’entrée n’a été publié pour cet outil.

questionWhat to find out about the project.

What to find out about the project.

Aucun schéma d’entrée n’a été publié pour cet outil.

implementA worker makes a change in an isolated copy; you review the exact diff and apply it only when it is right.

A worker makes a change in an isolated copy; you review the exact diff and apply it only when it is right.

Aucun schéma d’entrée n’a été publié pour cet outil.

taskThe change to make, with the context a worker needs.

The change to make, with the context a worker needs.

Aucun schéma d’entrée n’a été publié pour cet outil.

reviewA read-only reviewer from another model judges a commit range or the latest change.

A read-only reviewer from another model judges a commit range or the latest change.

Aucun schéma d’entrée n’a été publié pour cet outil.

rangeA commit range such as main..HEAD. Default: the latest run's change.

A commit range such as main..HEAD. Default: the latest run's change.

Aucun schéma d’entrée n’a été publié pour cet outil.

crewIndependent tasks run in parallel as one group of workers.

Independent tasks run in parallel as one group of workers.

Aucun schéma d’entrée n’a été publié pour cet outil.

tasksThe tasks, one per line.

The tasks, one per line.

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_runAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

pitroom_waitWait for runs that came back "still running" and return their reports.

Wait for runs that came back "still running" and return their reports.

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_showA run's report (live progress while it runs); patch: the exact diff; full: the untruncated answer.

A run's report (live progress while it runs); patch: the exact diff; full: the untruncated answer.

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_infoReports, changing nothing. topic: runs (latest runs; running, group), history (search earlier answers before asking again; text, state, model, since, limit), stats (success rate, time, tokens, audits per worker; since), savings (since, perModel), models (a backend's models and costs; worker, all),…

Reports, changing nothing. topic: runs (latest runs; running, group), history (search earlier answers before asking again; text, state, model, since, limit), stats (success rate, time, tokens, audits per worker; since), savings (since, perModel), models (a backend's models and costs; worker, all),…

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_reviewA read-only reviewer (another worker by default) judges a run's change or a commit range ("main..HEAD"): findings with severities and a SPEC / QUALITY verdict.

A read-only reviewer (another worker by default) judges a run's change or a commit range ("main..HEAD"): findings with severities and a SPEC / QUALITY verdict.

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_auditAnother worker re-checks a read run's answer: AGREE, PARTIAL or DISAGREE, with the disputed claims.

Another worker re-checks a read run's answer: AGREE, PARTIAL or DISAGREE, with the disputed claims.

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_applyLand an isolated run's patch (or a group's, in order) on the working tree; checked first. A patch deleting files needs allowDelete: pass it only after checking the deletions were asked for.

Land an isolated run's patch (or a group's, in order) on the working tree; checked first. A patch deleting files needs allowDelete: pass it only after checking the deletions were asked for.

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_discardDrop an isolated run's private copy (the patch is kept).

Drop an isolated run's private copy (the patch is kept).

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_revertUndo a mode "write" run's changes (refused if the files changed since).

Undo a mode "write" run's changes (refused if the files changed since).

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroom_stopStop a running or queued run, or a group; cooldowns: try rate-limited models again now.

Stop a running or queued run, or a group; cooldowns: try rate-limited models again now.

Aucun schéma d’entrée n’a été publié pour cet outil.

pitroomAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

19 outils sur 21 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Hands bounded coding work to cheaper worker agents: verified answers, exact diffs, cost receipts.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-10-10 — résolution observée, et non une déclaration de l'éditeur.

0 paquets résolus · 0 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

Ce paquet ne déclare aucune dépendance d'exécution.