@octocrawl/mcp

MCPattestatoattivo
v0.4.1io.github.77777R7AGPL-3.0-onlyAggiornato 1 g fanpmGitHub

Web scraper for agents: blocked, empty and wrong pages reported as such, with an Evidence Record.

Stato dell’endpointattivo
verificato 1 giorno fa · 1594 ms
100 % degli ultimi 1 controllo ha raggiunto questo endpoint
Funziona in
ClaudeCursorCopilotChatGPTGemini

Dedotto dai trasporti dichiarati da questo annuncio (stdio, streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.

Build attestato
Un’attestation di provenienza verificata lega questo artefatto al repository indicato. Nessuno ha ancora rivendicato l’annuncio — questo dimostra dove è stato costruito il codice, non chi lo sostiene.
338Download/sett.
1 g faUltimo aggiornamento
Legge queste credenziali
  • W2L_API_TOKENChiave APIfacoltativa

    A bearer token for a hosted or self-hosted API; none for a local one

Dichiarato dall’autore nel registro MCP ufficiale. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Pacchetto
Autoreio.github.77777R7
LicenzaAGPL-3.0-only
Versione0.4.1
Fontenpm+mcp-registry
Stato di fiducia
B
65/100Buono
✓Presente nell’indice di Forge+10/10
✓Identità verificata · build attestato+20/20
—Firma di pubblicazione Ed25519+0/5
→ Inclusa automaticamente quando il publisher esegue `forge publish`
—Verifica del dominio+0/5
→ Publisher: ospita /.well-known/forge.json sulla homepage del pacchetto con { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Corrispondenza del maintainer npm+0/5
→ Publisher: aggiungi il login GitHub verificato ai maintainer del pacchetto npm (npm owner add <login>)
✓Analisi CVE · pulita+30/30
—Analisi statica · pulita+0/20
→ Rilevati script di installazione sospetti o codice offuscato
Incollalo in Claude Code, Cursor o qualsiasi assistente di IA per colmare tutte le lacune
StatoIdentità verificata
PublisherNon verificato
FirmaNon firmato
Dominio—
Provenienza✓ Verificato con Sigstore · da3842f
Dipendenze✓ 60 risolte+ · nessuna vulnerabile
Superficie di strumenti32 strumenti · 1 privilegiati
Analisi di sicurezza⚠ Avvisi (1)v0.4.1 · 1 g faQuanto è efficace questa analisi?
PROMPTtool:create_delivery_destinationExfiltration-shaped instruction
ValutazioniNessuna
Indicizzato9 ott 2026

La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.

Strumenti

32 strumenti · 1 privilegiati · 1 segnalati per injection
Estratto staticamente dal pacchetto pubblicatov0.4.1 · 1d ago

Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.

preview_monitorCapture a nonpersistent sample and assess identity, fields, evidence, and missing reasons. Start with preset firecrawl-introduction.

Capture a nonpersistent sample and assess identity, fields, evidence, and missing reasons. Start with preset firecrawl-introduction.

Per questo strumento non è stato pubblicato alcuno schema di input.

create_monitorCreate a public-document Monitor. Defaults to paused so a delivery destination can be configured first. Use preset firecrawl-introduction for first use.

Create a public-document Monitor. Defaults to paused so a delivery destination can be configured first. Use preset firecrawl-introduction for first use.

Per questo strumento non è stato pubblicato alcuno schema di input.

list_monitorsList current Monitor state and freshness.

List current Monitor state and freshness.

Per questo strumento non è stato pubblicato alcuno schema di input.

get_monitorCheck a Monitor baseline, latest run, latest event, and next schedule.

Check a Monitor baseline, latest run, latest event, and next schedule.

Per questo strumento non è stato pubblicato alcuno schema di input.

run_monitorQueue a durable manual run. Returns runId immediately; disconnection does not cancel execution.

Queue a durable manual run. Returns runId immediately; disconnection does not cancel execution.

Per questo strumento non è stato pubblicato alcuno schema di input.

get_monitor_runInspect a run and field assessment with evidence and failure reasons.

Inspect a run and field assessment with evidence and failure reasons.

Per questo strumento non è stato pubblicato alcuno schema di input.

pause_monitorPause scheduling and cancel active Monitor execution.

Pause scheduling and cancel active Monitor execution.

Per questo strumento non è stato pubblicato alcuno schema di input.

resume_monitorResume Monitor scheduling; first run becomes due immediately.

Resume Monitor scheduling; first run becomes due immediately.

Per questo strumento non è stato pubblicato alcuno schema di input.

cancel_monitor_runExplicitly cancel a queued or running Monitor run.

Explicitly cancel a queued or running Monitor run.

Per questo strumento non è stato pubblicato alcuno schema di input.

create_delivery_destinationrischio di injectionRegister an HTTPS webhook for a Monitor. The secretEnv names an operator environment variable; never send the secret value.

Register an HTTPS webhook for a Monitor. The secretEnv names an operator environment variable; never send the secret value.

INIEZIONEExfiltration-shaped instructionr environment variable; never send the secret value.

Per questo strumento non è stato pubblicato alcuno schema di input.

list_delivery_destinationsList webhook destinations, optionally for one Monitor (monitorId) or one crawl or batch (jobId, the taskId); custom header names are listed, never their values.

List webhook destinations, optionally for one Monitor (monitorId) or one crawl or batch (jobId, the taskId); custom header names are listed, never their values.

Per questo strumento non è stato pubblicato alcuno schema di input.

list_deliveriesPage through delivery state and failures, for a Monitor (monitorId) or a crawl or batch (jobId, the taskId). Defaults to 20 compact results.

Page through delivery state and failures, for a Monitor (monitorId) or a crawl or batch (jobId, the taskId). Defaults to 20 compact results.

Per questo strumento non è stato pubblicato alcuno schema di input.

get_deliveryInspect one delivery and its retry attempts.

Inspect one delivery and its retry attempts.

Per questo strumento non è stato pubblicato alcuno schema di input.

retry_dead_letterExplicitly retry a dead-letter delivery with the same eventId.

Explicitly retry a dead-letter delivery with the same eventId.

Per questo strumento non è stato pubblicato alcuno schema di input.

scrape_productGet evidence-backed JSON for one anonymous Amazon.sg /dp/{ASIN} product. No schema or model setup needed.

Get evidence-backed JSON for one anonymous Amazon.sg /dp/{ASIN} product. No schema or model setup needed.

Per questo strumento non è stato pubblicato alcuno schema di input.

batch_productsQueue 1-1000 distinct Amazon.sg product URLs with the reviewed JSON schema. Returns taskId; page results with get_batch_items.

Queue 1-1000 distinct Amazon.sg product URLs with the reviewed JSON schema. Returns taskId; page results with get_batch_items.

Per questo strumento non è stato pubblicato alcuno schema di input.

scrapeFetch one URL through the Octocrawl coverage ladder. Compact by default; set debug=true for the full audit. The result's warnings name what its content cannot vouch for: robots_overridden (robots.txt disallows the URL; a local server fetched it because you named it), or client_rendered_suspected wh…

Fetch one URL through the Octocrawl coverage ladder. Compact by default; set debug=true for the full audit. The result's warnings name what its content cannot vouch for: robots_overridden (robots.txt disallows the URL; a local server fetched it because you named it), or client_rendered_suspected wh…

Per questo strumento non è stato pubblicato alcuno schema di input.

get_scrapeRead the record of one scrape call by the scrapeId its response carried (metadata.scrapeId): the request (header values replaced by their names), who made it (origin, integration), the verdict, the lanes tried, the metadata, the snapshot, the usage, the warnings and the hints. No page body. Records…

Read the record of one scrape call by the scrapeId its response carried (metadata.scrapeId): the request (header values replaced by their names), who made it (origin, integration), the verdict, the lanes tried, the metadata, the snapshot, the usage, the warnings and the hints. No page body. Records…

Per questo strumento non è stato pubblicato alcuno schema di input.

mapNessuna descrizione pubblicata

Questo strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.

crawlStart a multi-page crawl. Returns { taskId } (HTTP 202 equivalent). By default it follows links in the start URL's path subtree on its host and www twin, folds similar URLs into one page, and reports every collapsed or refused link in get_crawl's discovery counters and each page's links_offered tra…

Start a multi-page crawl. Returns { taskId } (HTTP 202 equivalent). By default it follows links in the start URL's path subtree on its host and www twin, folds similar URLs into one page, and reports every collapsed or refused link in get_crawl's discovery counters and each page's links_offered tra…

Per questo strumento non è stato pubblicato alcuno schema di input.

get_crawlRead a crawl by task id. Returns a CrawlReport.

Read a crawl by task id. Returns a CrawlReport.

Per questo strumento non è stato pubblicato alcuno schema di input.

get_crawl_pagesRead a paginated list of crawl page results by task id (the latest attempt's unless attemptId is given). Pages omit the routing audit and trace unless debug is true, and leave out pages whose content repeated an earlier page's (status duplicate) unless includeDuplicates is true. With maxResults the…

Read a paginated list of crawl page results by task id (the latest attempt's unless attemptId is given). Pages omit the routing audit and trace unless debug is true, and leave out pages whose content repeated an earlier page's (status duplicate) unless includeDuplicates is true. With maxResults the…

Per questo strumento non è stato pubblicato alcuno schema di input.

get_crawl_errorsRead a paginated list of crawl errors by task id.

Read a paginated list of crawl errors by task id.

Per questo strumento non è stato pubblicato alcuno schema di input.

cancel_crawlCancel a crawl task. Completed pages remain queryable.

Cancel a crawl task. Completed pages remain queryable.

Per questo strumento non è stato pubblicato alcuno schema di input.

resume_crawlRestart a paused or failed crawl with the options it was started with. Returns { taskId }; poll get_crawl.

Restart a paused or failed crawl with the options it was started with. Returns { taskId }; poll get_crawl.

Per questo strumento non è stato pubblicato alcuno schema di input.

list_active_crawlsList the crawls the API process is running (those it started and those it resumed at startup; never a batch): each with its id, start URL, status, pages so far and the options it was started with. Empty when nothing runs.

List the crawls the API process is running (those it started and those it resumed at startup; never a batch): each with its id, start URL, status, pages so far and the options it was started with. Empty when nothing runs.

Per questo strumento non è stato pubblicato alcuno schema di input.

batch_scrapePersist and run 1-1000 explicit URLs. Returns a taskId (with ignoreInvalidURLs also invalidURLs, the entries skipped); use get_batch_items for paginated results and get_batch_errors for the URLs that failed or that robots.txt refused. With appendToId the urls are added to that existing batch instea…

Persist and run 1-1000 explicit URLs. Returns a taskId (with ignoreInvalidURLs also invalidURLs, the entries skipped); use get_batch_items for paginated results and get_batch_errors for the URLs that failed or that robots.txt refused. With appendToId the urls are added to that existing batch instea…

Per questo strumento non è stato pubblicato alcuno schema di input.

get_batch_errorsThe items of a batch that did not succeed, across every attempt (a resumed batch keeps its earlier failures): errors [{ id, timestamp, url, status, code, error, httpStatus }] in pages of up to 1000 (cursor, limit), and robotsBlocked, every URL robots.txt refused (policy_denied by a robots_disallowe…

The items of a batch that did not succeed, across every attempt (a resumed batch keeps its earlier failures): errors [{ id, timestamp, url, status, code, error, httpStatus }] in pages of up to 1000 (cursor, limit), and robotsBlocked, every URL robots.txt refused (policy_denied by a robots_disallowe…

Per questo strumento non è stato pubblicato alcuno schema di input.

hand_off_batchNessuna descrizione pubblicata

Questo strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.

import_loginNessuna descrizione pubblicata

Questo strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.

list_loginsThe person's saved logins (import_login, octocrawl login import): { logins: [{ domain, savedAt, cookieCount, localStorage, sessionSha256 }] }, never a cookie or a stored value.

The person's saved logins (import_login, octocrawl login import): { logins: [{ domain, savedAt, cookieCount, localStorage, sessionSha256 }] }, never a cookie or a stored value.

Per questo strumento non è stato pubblicato alcuno schema di input.

remove_loginprivilegiatoForget the person's saved login to a site (a domain or a page URL on it).

Forget the person's saved login to a site (a domain or a page URL on it).

Per questo strumento non è stato pubblicato alcuno schema di input.

29 strumenti su 32 hanno pubblicato una descrizione.

I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.

Descrizione

Web scraper for agents: blocked, empty and wrong pages reported as such, with an Evidence Record.

Parole chiave
mcp
Alternative
Confronto delle superfici di strumenti…

Albero delle dipendenze

Ciò che una scansione di Forge ha risolto dai metadati npm il 2026-10-10: risoluzione osservata, non una dichiarazione dell'editore.

60 pacchetti risolti · 1 diretti · nessuno con avvisi di sicurezza La risoluzione si ferma alla profondità 4 e a 60 pacchetti.

La scansione si è fermata al limite di profondità 4. Tutto ciò che sta sotto quel livello non è mai stato risolto.

La scansione si è fermata al limite di 60 pacchetti. Il resto dell'albero non è mai stato risolto.

Altri 36 pacchetti risolti non vengono disegnati qui (limite di visualizzazione: 24). Ogni dipendenza con un avviso di sicurezza viene disegnata comunque. Inventario completo (SBOM CycloneDX)

Dichiarate ma non risolte

54 dipendenze dichiarate non sono mai arrivate nell'albero. Mancano dalla risoluzione di Forge, non dal pacchetto.

+42 altre non elencate. I conteggi per motivo qui sopra le comprendono tutte.

Non seguite: peerDependencies. Questo albero copre solo le dipendenze di runtime, quindi ciò che queste comportano non è mai stato risolto.