A deterministic eval engine for coding agents. Fires the edge cases your sandbox never sends, then proves a fix: the same scenario fails on the old code and passes on the new.
Dedotto dai trasporti dichiarati da questo annuncio (stdio). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
FETCHSANDBOX_API_KEYChiave APIfacoltativaOptional. Sign in without a browser — useful in CI. Left unset, the server runs anonymously and asks you to sign in the first time a run produces a receipt.
Dichiarato dall’autore nel registro MCP ufficiale. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.
coachConversational integration coach for FetchSandbox. Server-sideConversational integration coach for FetchSandbox. Server-side
Per questo strumento non è stato pubblicato alcuno schema di input.
find_bugsFIRST STEP for any API-integration bug — webhooks, payments, auth, email,FIRST STEP for any API-integration bug — webhooks, payments, auth, email,
Per questo strumento non è stato pubblicato alcuno schema di input.
fix_bugFetchSandbox remediation: get a proposed fix for a specific bug in YOURFetchSandbox remediation: get a proposed fix for a specific bug in YOUR
Per questo strumento non è stato pubblicato alcuno schema di input.
guideROUTE a symptom to the provider behaviour that explains it. Use this whenROUTE a symptom to the provider behaviour that explains it. Use this when
Per questo strumento non è stato pubblicato alcuno schema di input.
import_specIngest an OpenAPI spec and get a working sandbox you can call immediately.Ingest an OpenAPI spec and get a working sandbox you can call immediately.
Per questo strumento non è stato pubblicato alcuno schema di input.
list_runsList recent workflow runs (and ad-hoc traffic) for a sandbox, newestList recent workflow runs (and ad-hoc traffic) for a sandbox, newest
Per questo strumento non è stato pubblicato alcuno schema di input.
list_specsBrowse the FetchSandbox spec catalog — every API (Stripe, GitHub,Browse the FetchSandbox spec catalog — every API (Stripe, GitHub,
Per questo strumento non è stato pubblicato alcuno schema di input.
list_workflowsList the named, runnable workflows for a previously-imported spec.List the named, runnable workflows for a previously-imported spec.
Per questo strumento non è stato pubblicato alcuno schema di input.
prove_fixTHE PROOF STEP. The only way to establish that a fix actually works, andTHE PROOF STEP. The only way to establish that a fix actually works, and
Per questo strumento non è stato pubblicato alcuno schema di input.
quickrunRun a curated proof workflow against a KNOWN, bundled spec (stripe, clerk,Run a curated proof workflow against a KNOWN, bundled spec (stripe, clerk,
Per questo strumento non è stato pubblicato alcuno schema di input.
run_all_workflowsExecute EVERY workflow (or a scoped subset) for a sandbox in ONE call.Execute EVERY workflow (or a scoped subset) for a sandbox in ONE call.
Per questo strumento non è stato pubblicato alcuno schema di input.
run_workflowExecute ONE specific workflow by name and return its step-by-step traceExecute ONE specific workflow by name and return its step-by-step trace
Per questo strumento non è stato pubblicato alcuno schema di input.
submit_proofReceipts are readable by anyone with the link — do not attach bodies theReceipts are readable by anyone with the link — do not attach bodies the
Per questo strumento non è stato pubblicato alcuno schema di input.
verify_behaviorProve a known fix survives a bug — the 'prove' half of reproduce→prove.Prove a known fix survives a bug — the 'prove' half of reproduce→prove.
Per questo strumento non è stato pubblicato alcuno schema di input.
14 strumenti su 14 hanno pubblicato una descrizione.
I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.
A deterministic eval engine for coding agents. Fires the edge cases your sandbox never sends, then proves a fix: the same scenario fails on the old code and passes on the new.
I nomi collegati aprono l’indice Forge di tutte le voci osservate esporre quello strumento. Sfoglia tutti gli strumenti indicizzati.
La scansione si è fermata al limite di profondità 4. Tutto ciò che sta sotto quel livello non è mai stato risolto.
La scansione si è fermata al limite di 60 pacchetti. Il resto dell'albero non è mai stato risolto.
Altri 36 pacchetti risolti non vengono disegnati qui (limite di visualizzazione: 24). Ogni dipendenza con un avviso di sicurezza viene disegnata comunque. Inventario completo (SBOM CycloneDX)
53 dipendenze dichiarate non sono mai arrivate nell'albero. Mancano dalla risoluzione di Forge, non dal pacchetto.
+41 altre non elencate. I conteggi per motivo qui sopra le comprendono tutte.
Non seguite: peerDependencies. Questo albero copre solo le dipendenze di runtime, quindi ciò che queste comportano non è mai stato risolto.