Assertion checks for status, headers and content - no API key.
Dedotto dai trasporti dichiarati da questo annuncio (stdio). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.
assert_statusRun a synthetic check on a URL: does it answer with the status you expect, inside the time budget, without a redirect loop.Run a synthetic check on a URL: does it answer with the status you expect, inside the time budget, without a redirect loop.
Per questo strumento non è stato pubblicato alcuno schema di input.
assert_headersCheck that required headers are present, forbidden ones are absent, or one header contains a given value.Check that required headers are present, forbidden ones are absent, or one header contains a given value.
Per questo strumento non è stato pubblicato alcuno schema di input.
assert_contentCheck that a page's HTML contains expected text and does not contain forbidden text — a smoke test for deploys.Check that a page's HTML contains expected text and does not contain forbidden text — a smoke test for deploys.
Per questo strumento non è stato pubblicato alcuno schema di input.
check_urlPlain reachability check: HTTP status, response time, server header and any redirects.Plain reachability check: HTTP status, response time, server header and any redirects.
Per questo strumento non è stato pubblicato alcuno schema di input.
check_redirectsTrace every redirect hop with its timing, and flag loops or an http-to-https upgrade that never happens.Trace every redirect hop with its timing, and flag loops or an http-to-https upgrade that never happens.
Per questo strumento non è stato pubblicato alcuno schema di input.
broken_linksRead the links on a page and report which ones answer with an error status, so a deploy cannot ship dead links.Read the links on a page and report which ones answer with an error status, so a deploy cannot ship dead links.
Per questo strumento non è stato pubblicato alcuno schema di input.
assert_response_timeSample a URL a few times and assert the median and worst time stay inside a budget, reporting each sample.Sample a URL a few times and assert the median and worst time stay inside a budget, reporting each sample.
Per questo strumento non è stato pubblicato alcuno schema di input.
assert_jsonTreat a URL as a JSON API: check it parses, then assert a dot-path exists and optionally equals or contains a value.Treat a URL as a JSON API: check it parses, then assert a dot-path exists and optionally equals or contains a value.
Per questo strumento non è stato pubblicato alcuno schema di input.
assert_redirectAssert that a URL redirects, optionally that it lands on a given Location and answers with a specific status.Assert that a URL redirects, optionally that it lands on a given Location and answers with a specific status.
Per questo strumento non è stato pubblicato alcuno schema di input.
http_security_reportTransport and browser-side security for one URL: HTTPS upgrade, HSTS, CSP, nosniff, referrer and permissions policy, COOP, Secure and HttpOnly cookie flags, and any plain-HTTP resource referenced by the page.Transport and browser-side security for one URL: HTTPS upgrade, HSTS, CSP, nosniff, referrer and permissions policy, COOP, Secure and HttpOnly cookie flags, and any plain-HTTP resource referenced by the page.
Per questo strumento non è stato pubblicato alcuno schema di input.
a11y_basicsThe machine-checkable part of an accessibility audit: html lang, document title, single h1 and heading levels, image alt attributes, blank alt text, viewport zoom locking, landmark elements and a skip link.The machine-checkable part of an accessibility audit: html lang, document title, single h1 and heading levels, image alt attributes, blank alt text, viewport zoom locking, landmark elements and a skip link.
Per questo strumento non è stato pubblicato alcuno schema di input.
seo_metaSearch metadata actually served by one URL: title length, meta description, rel=canonical, Open Graph and Twitter card tags, robots meta, hreflang alternates and whether every JSON-LD block parses.Search metadata actually served by one URL: title length, meta description, rel=canonical, Open Graph and Twitter card tags, robots meta, hreflang alternates and whether every JSON-LD block parses.
Per questo strumento non è stato pubblicato alcuno schema di input.
12 strumenti su 12 hanno pubblicato una descrizione.
I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.
Assertion checks for status, headers and content - no API key.
I nomi collegati aprono l’indice Forge di tutte le voci osservate esporre quello strumento. Sfoglia tutti gli strumenti indicizzati.
La scansione si è fermata al limite di profondità 4. Tutto ciò che sta sotto quel livello non è mai stato risolto.
La scansione si è fermata al limite di 60 pacchetti. Il resto dell'albero non è mai stato risolto.
Altri 36 pacchetti risolti non vengono disegnati qui (limite di visualizzazione: 24). Ogni dipendenza con un avviso di sicurezza viene disegnata comunque. Inventario completo (SBOM CycloneDX)
54 dipendenze dichiarate non sono mai arrivate nell'albero. Mancano dalla risoluzione di Forge, non dal pacchetto.
+42 altre non elencate. I conteggi per motivo qui sopra le comprendono tutte.
Non seguite: peerDependencies. Questo albero copre solo le dipendenze di runtime, quindi ciò che queste comportano non è mai stato risolto.