Check tokens, pages and x402 payments before your agent trusts them. Offline verdicts.
Dedotto dai trasporti dichiarati da questo annuncio (stdio). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
WORMHOLE_API_KEYChiave APIfacoltativaOptional. Hosted-mode key from dashboard.agentwormhole.com: adds URL checks with change history, and the operator's spend policy (budgets, approvals, kill switch) on payments.
Dichiarato dall’autore nel registro MCP ufficiale. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.
verify_paymentCheck an x402 payment against the merchant's quote BEFORE signing it.Check an x402 payment against the merchant's quote BEFORE signing it.
Per questo strumento non è stato pubblicato alcuno schema di input.
verify_deliveryCheck what a PAID request actually delivered, AFTER the payment — theCheck what a PAID request actually delivered, AFTER the payment — the
Per questo strumento non è stato pubblicato alcuno schema di input.
check_before_useCheck anything BEFORE trusting it — a web page you are about to read,Check anything BEFORE trusting it — a web page you are about to read,
Per questo strumento non è stato pubblicato alcuno schema di input.
check_tokenCheck a token launch BEFORE reading its metadata. A token's name,Check a token launch BEFORE reading its metadata. A token's name,
Per questo strumento non è stato pubblicato alcuno schema di input.
scan_textScan untrusted text or a JSON document (a 402 quote body, a merchantScan untrusted text or a JSON document (a 402 quote body, a merchant
Per questo strumento non è stato pubblicato alcuno schema di input.
5 strumenti su 5 hanno pubblicato una descrizione.
I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.
Check tokens, pages and x402 payments before your agent trusts them. Offline verdicts.
I nomi collegati aprono l’indice Forge di tutte le voci osservate esporre quello strumento. Sfoglia tutti gli strumenti indicizzati.