bundlebox

MCPattestato
v0.8.0io.github.blackswanalphaMITAggiornato 1 g fanpmGitHub

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

Funziona in
ClaudeCursorCopilotGemini

Dedotto dai trasporti dichiarati da questo annuncio (stdio). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.

Build attestato
Un’attestation di provenienza verificata lega questo artefatto al repository indicato. Nessuno ha ancora rivendicato l’annuncio — questo dimostra dove è stato costruito il codice, non chi lo sostiene.
150Download/sett.
2Stelle su GitHub
1 g faUltimo aggiornamento
Pacchetto
Autoreio.github.blackswanalpha
LicenzaMIT
Versione0.8.0
Fontenpm+mcp-registry
Stato di fiducia
A
85/100Affidabile
Presente nell’indice di Forge+10/10
Identità verificata · build attestato+20/20
Firma di pubblicazione Ed25519+0/5
Inclusa automaticamente quando il publisher esegue `forge publish`
Verifica del dominio+0/5
Publisher: ospita /.well-known/forge.json sulla homepage del pacchetto con { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
Corrispondenza del maintainer npm+0/5
Publisher: aggiungi il login GitHub verificato ai maintainer del pacchetto npm (npm owner add <login>)
Analisi CVE · pulita+30/30
Analisi statica · pulita+20/20
Incollalo in Claude Code, Cursor o qualsiasi assistente di IA per colmare tutte le lacune
StatoIdentità verificata
PublisherNon verificato
FirmaNon firmato
Dominio
Provenienza✓ Verificato con Sigstore · 2907a91
Dipendenze✓ 0 risolte · nessuna vulnerabile
Superficie di strumenti24 strumenti · nessuno privilegiato
Analisi di sicurezza✓ Pulitov0.8.0 · 1 g faQuanto è efficace questa analisi?
ValutazioniNessuna
Indicizzato22 set 2026

La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.

Strumenti

24 strumenti · nessuno privilegiato
Estratto staticamente dal pacchetto pubblicatov0.8.0 · 1d ago

Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.

intakewhat is wrong, found locally; ends holding lanes, the last point before anything spends

what is wrong, found locally; ends holding lanes, the last point before anything spends

Per questo strumento non è stato pubblicato alcuno schema di input.

orientwhat a session gets handed instead of searching

what a session gets handed instead of searching

Per questo strumento non è stato pubblicato alcuno schema di input.

measurewhat sessions cost, what the local path displaced, and what packing a task is worth

what sessions cost, what the local path displaced, and what packing a task is worth

Per questo strumento non è stato pubblicato alcuno schema di input.

opsis this box healthy

is this box healthy

Per questo strumento non è stato pubblicato alcuno schema di input.

buckmastertrain the process model on everything above, then turn it into automation

train the process model on everything above, then turn it into automation

Per questo strumento non è stato pubblicato alcuno schema di input.

situationwhat is happening right now: services, what is failing, and what the detectors see

what is happening right now: services, what is failing, and what the detectors see

Per questo strumento non è stato pubblicato alcuno schema di input.

genesisthe inlet: what the world declares that no scenario touches, packed to briefs

the inlet: what the world declares that no scenario touches, packed to briefs

Per questo strumento non è stato pubblicato alcuno schema di input.

scenariosrun the corpus against the running system and read what it means

run the corpus against the running system and read what it means

Per questo strumento non è stato pubblicato alcuno schema di input.

auditwhich areas have no current audit, and the briefs that would produce one

which areas have no current audit, and the briefs that would produce one

Per questo strumento non è stato pubblicato alcuno schema di input.

watchfold what was spent, and rebuild the one page that shows it

fold what was spent, and rebuild the one page that shows it

Per questo strumento non è stato pubblicato alcuno schema di input.

bootstrapbring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page

bring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page

Per questo strumento non è stato pubblicato alcuno schema di input.

factoryone tick of the whole free path: intake, orient, measure, buckmaster, watch

one tick of the whole free path: intake, orient, measure, buckmaster, watch

Per questo strumento non è stato pubblicato alcuno schema di input.

fullthe whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost

the whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost

Per questo strumento non è stato pubblicato alcuno schema di input.

practicefill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one

fill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_pinpointOne problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on file, the acceptance command, traps and guidelines. Call this BEFORE searching the tree.

One problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on file, the acceptance command, traps and guidelines. Call this BEFORE searching the tree.

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_contextDoes this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cut.

Does this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cut.

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_snapgenReference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `table` returns the INDEX with each table's token cost so you can choose. Read a table instead of grepping.

Reference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `table` returns the INDEX with each table's token cost so you can choose. Read a table instead of grepping.

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_findingsOpen findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.

Open findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_scanRun the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.

Run the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_oversight_briefWhat is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editing. About 300 tokens.

What is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editing. About 300 tokens.

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_explainOne finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).

One finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_tokens_estimateEstimated tokens per file and in total, with the calibrated estimator (not chars/4).

Estimated tokens per file and in total, with the calibrated estimator (not chars/4).

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_situationWhere this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, and what the last echos run saw. Call this instead of git status + git diff + bb env + bb findings + bb echos.

Where this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, and what the last echos run saw. Call this instead of git status + git diff + bb env + bb findings + bb echos.

Per questo strumento non è stato pubblicato alcuno schema di input.

bb_sessionWhat the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

What the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

Per questo strumento non è stato pubblicato alcuno schema di input.

24 strumenti su 24 hanno pubblicato una descrizione.

I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.

Descrizione

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

Parole chiave
mcp
Alternative
Confronto delle superfici di strumenti…

Albero delle dipendenze

Ciò che una scansione di Forge ha risolto dai metadati npm il 2026-09-23: risoluzione osservata, non una dichiarazione dell'editore.

0 pacchetti risolti · 0 diretti · nessuno con avvisi di sicurezza La risoluzione si ferma alla profondità 4 e a 60 pacchetti.

Questo pacchetto non dichiara dipendenze di runtime.