Check if a dependency's license obligates you, based on how you ship. npm, PyPI, Go.
Dedotto dai trasporti dichiarati da questo annuncio (streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.
audit_projectFind this project's dependency manifest and check every dependency, including transitive ones, against the way the project ships.Find this project's dependency manifest and check every dependency, including transitive ones, against the way the project ships.
Per questo strumento non è stato pubblicato alcuno schema di input.
distribution_modelNessuna descrizione pubblicataQuesto strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.
compare_licensesExplain how two licenses differ for one specific way of shipping software, rather than in the abstract.Explain how two licenses differ for one specific way of shipping software, rather than in the abstract.
Per questo strumento non è stato pubblicato alcuno schema di input.
license_aSPDX identifier, e.g. "AGPL-3.0-only".SPDX identifier, e.g. "AGPL-3.0-only".
Per questo strumento non è stato pubblicato alcuno schema di input.
license_bSPDX identifier, e.g. "GPL-3.0-only".SPDX identifier, e.g. "GPL-3.0-only".
Per questo strumento non è stato pubblicato alcuno schema di input.
licenseguardNessuna descrizione pubblicataQuesto strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.
check_dependency_licenseDetermine whether adding or keeping a single open source dependency creates a legal obligation, given how this project ships. Call this BEFORE adding a new dependency to a project, and when auditing an existing one. A permissive result means no source-disclosure duty; a blocked result means the lic…Determine whether adding or keeping a single open source dependency creates a legal obligation, given how this project ships. Call this BEFORE adding a new dependency to a project, and when auditing an existing one. A permissive result means no source-disclosure duty; a blocked result means the lic…
Per questo strumento non è stato pubblicato alcuno schema di input.
check_manifest_licensesScan an entire dependency manifest and report every dependency whose license creates an obligation for this shipping model. Use when reviewing a project as a whole, preparing for due diligence, or after a large dependency change. Pass a package-lock.json when one exists: problematic licenses usuall…Scan an entire dependency manifest and report every dependency whose license creates an obligation for this shipping model. Use when reviewing a project as a whole, preparing for due diligence, or after a large dependency change. Pass a package-lock.json when one exists: problematic licenses usuall…
Per questo strumento non è stato pubblicato alcuno schema di input.
explain_licenseGiven an SPDX license identifier or expression, explain what it requires across every shipping model at once. Use when the question is about the license itself rather than a specific package — for example when comparing AGPL-3.0 against GPL-3.0 for a hosted service, or deciding what a project may s…Given an SPDX license identifier or expression, explain what it requires across every shipping model at once. Use when the question is about the license itself rather than a specific package — for example when comparing AGPL-3.0 against GPL-3.0 for a hosted service, or deciding what a project may s…
Per questo strumento non è stato pubblicato alcuno schema di input.
7 strumenti su 9 hanno pubblicato una descrizione.
I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.
Check if a dependency's license obligates you, based on how you ship. npm, PyPI, Go.
I nomi collegati aprono l’indice Forge di tutte le voci osservate esporre quello strumento. Sfoglia tutti gli strumenti indicizzati.
Questa voce non pubblica alcun pacchetto npm, quindi Forge non ha un albero delle dipendenze per essa. È una lacuna di copertura, non l'affermazione che non abbia dipendenze.