toolfactory

MCPattesté
v0.3.1io.github.GoatInAHatMITMis à jour il y a 2 jnpmGitHub

Build an agent tool once; ship it as Agent Skills, MCP servers, Agent Plugins / Claude / Codex / Cursor bundles, OpenClaw and Hermes plugins, CLIs, and packages, with the tests and releases to match.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
271Téléch./sem.
il y a 2 jDernière mise à jour
Paquet
Auteurio.github.GoatInAHat
LicenceMIT
Version0.3.1
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
Listé dans l’index Forge+10/10
Identité vérifiée · build attesté+20/20
Signature de publication Ed25519+0/5
Incluse automatiquement quand l’éditeur exécute `forge publish`
Vérification de domaine+0/5
Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
Correspondance de mainteneur npm+0/5
Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
Analyse CVE · propre+30/30
Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine
Provenance✓ Vérifié par Sigstore · c1d4f9a
Dépendances✓ 24 résolues · aucune vulnérable
Surface d’outils28 outils · aucun privilégié
Analyse de sécurité✓ Proprev0.3.1 · il y a 1 jQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé8 sept. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

28 outils · aucun privilégié
Extrait statiquement du paquet publiév0.3.1 · 1d ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

echokey

key

Aucun schéma d’entrée n’a été publié pour cet outil.

scrapeAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

summarizeAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

loginAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

screenshotCapture the current page.

Capture the current page.

Aucun schéma d’entrée n’a été publié pour cet outil.

notifyPost a message into the live conversation.

Post a message into the live conversation.

Aucun schéma d’entrée n’a été publié pour cet outil.

browseService region.

Service region.

Aucun schéma d’entrée n’a été publié pour cet outil.

regionService region.

Service region.

Aucun schéma d’entrée n’a été publié pour cet outil.

shootSay hello

Say hello

Aucun schéma d’entrée n’a été publié pour cet outil.

webOpen the generated operations page.

Open the generated operations page.

Aucun schéma d’entrée n’a été publié pour cet outil.

adoptStop regenerating one file; it becomes the author's (recorded as manual in the lock).

Stop regenerating one file; it becomes the author's (recorded as manual in the lock).

Aucun schéma d’entrée n’a été publié pour cet outil.

bootstrap-repoPrepare the GitHub repository from the local .env: the `live-tests` environment with its required reviewers and the sensitive config keys inside it, the release registries' tokens at repository scope, GitHub Pages with source = Actions, and npm's trusted publisher. Values go to `gh` on stdin and ar…

Prepare the GitHub repository from the local .env: the `live-tests` environment with its required reviewers and the sensitive config keys inside it, the release registries' tokens at repository scope, GitHub Pages with source = Actions, and npm's trusted publisher. Values go to `gh` on stdin and ar…

Aucun schéma d’entrée n’a été publié pour cet outil.

buildGenerate every selected surface in-tree from the identity file and the operation snapshot, and refresh the lock.

Generate every selected surface in-tree from the identity file and the operation snapshot, and refresh the lock.

Aucun schéma d’entrée n’a été publié pour cet outil.

checkFail if the operation snapshot or any generated file drifted from the code (the CI drift gate).

Fail if the operation snapshot or any generated file drifted from the code (the CI drift gate).

Aucun schéma d’entrée n’a été publié pour cet outil.

coverageThe operation × surface verdict matrix: native, bridged, degraded, or excluded, with reasons.

The operation × surface verdict matrix: native, bridged, degraded, or excluded, with reasons.

Aucun schéma d’entrée n’a été publié pour cet outil.

doctorReport which upstream CLIs this machine can delegate to (git, gh, npm, uv, claude, openclaw, clawhub, hermes, uvx, agentskills, MCP Inspector, docker).

Report which upstream CLIs this machine can delegate to (git, gh, npm, uv, claude, openclaw, clawhub, hermes, uvx, agentskills, MCP Inspector, docker).

Aucun schéma d’entrée n’a été publié pour cet outil.

ejectAdopt every file a surface owns, so the author takes it over entirely.

Adopt every file a surface owns, so the author takes it over entirely.

Aucun schéma d’entrée n’a été publié pour cet outil.

gateRun the gate here, in order: build, the drift check, every selected surface's upstream validator, the author's checks and tests, and the credential-free host end-to-end. The same step list the generated ci.yml renders, so a project with no CI has the identical gate.

Run the gate here, in order: build, the drift check, every selected surface's upstream validator, the author's checks and tests, and the credential-free host end-to-end. The same step list the generated ci.yml renders, so a project with no CI has the identical gate.

Aucun schéma d’entrée n’a été publié pour cet outil.

initCreate a new tool: dev.toolfactory/tool.json, the authored identity file, the kernel scaffold for the chosen language, and the first build of every selected surface.

Create a new tool: dev.toolfactory/tool.json, the authored identity file, the kernel scaffold for the chosen language, and the first build of every selected surface.

Aucun schéma d’entrée n’a été publié pour cet outil.

introspectSpawn the kernel MCP server, list its tools, and snapshot them to dev.toolfactory/ops.json.

Spawn the kernel MCP server, list its tools, and snapshot them to dev.toolfactory/ops.json.

Aucun schéma d’entrée n’a été publié pour cet outil.

packageBuild every release asset into dist/release/ — npm tarball, Python distributions, OpenClaw plugin tarball, plugin bundle zip, web build, coverage — by the same steps the release workflow's package job runs. Publishing stays a CI concern.

Build every release asset into dist/release/ — npm tarball, Python distributions, OpenClaw plugin tarball, plugin bundle zip, web build, coverage — by the same steps the release workflow's package job runs. Publishing stays a CI concern.

Aucun schéma d’entrée n’a été publié pour cet outil.

review-promptEvaluate a prompt draft against the codex-prompt-standard rubric: anatomy sections, convention checks, and concrete directives. Draft, run this, fix what it flags, and re-run until it passes.

Evaluate a prompt draft against the codex-prompt-standard rubric: anatomy sections, convention checks, and concrete directives. Draft, run this, fix what it flags, and re-run until it passes.

Aucun schéma d’entrée n’a été publié pour cet outil.

secrets-usageEvery credential this project's surfaces need — the tool's own sensitive config keys and the release registries' tokens — with where each one is set, whether it is present locally and on GitHub, and (check) whether the registry accepts it. Never a value.

Every credential this project's surfaces need — the tool's own sensitive config keys and the release registries' tokens — with where each one is set, whether it is present locally and on GitHub, and (check) whether the registry accepts it. Never a value.

Aucun schéma d’entrée n’a été publié pour cet outil.

unadoptReturn an adopted file to toolfactory and regenerate it.

Return an adopted file to toolfactory and regenerate it.

Aucun schéma d’entrée n’a été publié pour cet outil.

unpublishRetract what a deselected surface used to publish. Git is the ledger: the previous tag's dev.toolfactory/tool.json says what was selected then, and every registry row that lost its surface is checked for the version that tag published and then retracted with the registry's own CLI — or reported wit…

Retract what a deselected surface used to publish. Git is the ledger: the previous tag's dev.toolfactory/tool.json says what was selected then, and every registry row that lost its surface is checked for the version that tag published and then retracted with the registry's own CLI — or reported wit…

Aucun schéma d’entrée n’a été publié pour cet outil.

validateRun each selected surface's own upstream validator (agentskills, claude plugin validate, MCP Inspector, openclaw, hermes, npm pack, uv build).

Run each selected surface's own upstream validator (agentskills, claude plugin validate, MCP Inspector, openclaw, hermes, npm pack, uv build).

Aucun schéma d’entrée n’a été publié pour cet outil.

helloSay hello

Say hello

Aucun schéma d’entrée n’a été publié pour cet outil.

nativeAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

24 outils sur 28 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Build an agent tool once; ship it as Agent Skills, MCP servers, Agent Plugins / Claude / Codex / Cursor bundles, OpenClaw and Hermes plugins, CLIs, and packages, with the tests and releases to match.

Mots-clés
agentmcpskillsagent-pluginsopenclawhermesclaude-codecodexcursor
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-09-17 — résolution observée, et non une déclaration de l'éditeur.

24 paquets résolus · 8 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.