Fixes the names and jargon speech-to-text gets wrong before your agent acts on a dictated prompt.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
pbcopypbpaste / pbcopy (macOS)pbpaste / pbcopy (macOS)
No input schema was published for this tool.
xclipxclip -selection clipboard -o / -i (X11)xclip -selection clipboard -o / -i (X11)
No input schema was published for this tool.
xselxsel --clipboard --output / --input (X11)xsel --clipboard --output / --input (X11)
No input schema was published for this tool.
powershellNo description publishedThis tool published no description. Forge does not invent one.
injectedinjected read/writeinjected read/write
No input schema was published for this tool.
harvest_repoScan a repository for proper nouns an STT engine is likely to mangle: package and dependency names, git authors, README brands, the project directory.Scan a repository for proper nouns an STT engine is likely to mangle: package and dependency names, git authors, README brands, the project directory.
No input schema was published for this tool.
suggest_termsPropose new aliases, terms and never-words from the user's voice history, usage and repo.Propose new aliases, terms and never-words from the user's voice history, usage and repo.
No input schema was published for this tool.
apply_suggestionApply a suggestion returned by suggest_terms after the user accepted it: 'alias' merges the alias into the term, 'term' adds the term (aliases auto-suggested when none given),Apply a suggestion returned by suggest_terms after the user accepted it: 'alias' merges the alias into the term, 'term' adds the term (aliases auto-suggested when none given),
No input schema was published for this tool.
list_packsList the starter packs shipped with the lexicon (developer, ai, business, voice-tools: curated names with the misspellings STT produces for them) and which are already installed.List the starter packs shipped with the lexicon (developer, ai, business, voice-tools: curated names with the misspellings STT produces for them) and which are already installed.
No input schema was published for this tool.
add_packInstall one starter pack from list_packs into the global lexicon (or the project .lexicon.yaml with scope: project).Install one starter pack from list_packs into the global lexicon (or the project .lexicon.yaml with scope: project).
No input schema was published for this tool.
import_dictionaryImport a dictionary the user already has (Wispr Flow CSV, Superwhisper JSON, macOS Text Replacement plist, espanso YAML, plain text 'Canonical: alias1, alias2', generic CSV, or a lexicon JSON/YAML) into the lexicon.Import a dictionary the user already has (Wispr Flow CSV, Superwhisper JSON, macOS Text Replacement plist, espanso YAML, plain text 'Canonical: alias1, alias2', generic CSV, or a lexicon JSON/YAML) into the lexicon.
No input schema was published for this tool.
lexicon_doctorAnswers "is lexicon set up for this user, and what is the one command that fixes it" in a single call.Answers "is lexicon set up for this user, and what is the one command that fixes it" in a single call.
No input schema was published for this tool.
install_clientprivilegedRegister the lexicon MCP server (and, for Claude Code, its hooks) in an agent client's config: claude, codex, cursor, windsurf, gemini, vscode or claude-desktop.Register the lexicon MCP server (and, for Claude Code, its hooks) in an agent client's config: claude, codex, cursor, windsurf, gemini, vscode or claude-desktop.
No input schema was published for this tool.
setup_lexiconOne-shot onboarding: seed the lexicon with the user's company and name, register the MCP server and hooks in their agent clients, optionally harvest the repo and install the local API as a login service.One-shot onboarding: seed the lexicon with the user's company and name, register the MCP server and hooks in their agent clients, optionally harvest the repo and install the local API as a login service.
No input schema was published for this tool.
serve_statusCheck whether the local lexicon API (`lexicon serve`, used by the browser extension, Claude Desktop, Shortcuts and the menu bar app) is running on 127.0.0.1:41733.Check whether the local lexicon API (`lexicon serve`, used by the browser extension, Claude Desktop, Shortcuts and the menu bar app) is running on 127.0.0.1:41733.
No input schema was published for this tool.
normalize_transcriptFix the proper nouns speech-to-text got wrong, using this user's personal lexicon of names, brands, acronyms and identifiers.Fix the proper nouns speech-to-text got wrong, using this user's personal lexicon of names, brands, acronyms and identifiers.
No input schema was published for this tool.
add_termTeach the lexicon a name, so dictation is corrected to it from now on.Teach the lexicon a name, so dictation is corrected to it from now on.
No input schema was published for this tool.
remove_termprivilegedDelete a term from the user's lexicon by canonical spelling (case-insensitive).Delete a term from the user's lexicon by canonical spelling (case-insensitive).
No input schema was published for this tool.
list_termsList the user's lexicon terms, global and project merged. Optional case-insensitive substring filter over canonicalList the user's lexicon terms, global and project merged. Optional case-insensitive substring filter over canonical
No input schema was published for this tool.
export_lexiconExport the merged lexicon in a format for another tool: 'claude-md' (markdown for CLAUDE.md / system prompts), 'markdown', 'text', 'wispr', 'superwhisper', 'whisper-prompt', 'openai', 'macos', 'espanso', 'deepgram', 'assemblyai', 'azure', 'google', 'csv', or raw 'json'.Export the merged lexicon in a format for another tool: 'claude-md' (markdown for CLAUDE.md / system prompts), 'markdown', 'text', 'wispr', 'superwhisper', 'whisper-prompt', 'openai', 'macos', 'espanso', 'deepgram', 'assemblyai', 'azure', 'google', 'csv', or raw 'json'.
No input schema was published for this tool.
learn_correctionRecord that the user corrected a spelling: they meant `meant`, but the transcript or you wrote `heard`.Record that the user corrected a spelling: they meant `meant`, but the transcript or you wrote `heard`.
No input schema was published for this tool.
suggest_canonicalLook up what a garbled word was probably meant to be.Look up what a garbled word was probably meant to be.
No input schema was published for this tool.
lexicon_statsCounts of terms and aliases, total hits, the most-used terms, terms that never fired, and a per-file breakdown of the merged lexicon.Counts of terms and aliases, total hits, the most-used terms, terms that never fired, and a per-file breakdown of the merged lexicon.
No input schema was published for this tool.
trust_projectManage trust for a repo's .lexicon.yaml, which is merged only after the user approves it (it can inject text into every session).Manage trust for a repo's .lexicon.yaml, which is merged only after the user approves it (it can inject text into every session).
No input schema was published for this tool.
23 of 24 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Fixes the names and jargon speech-to-text gets wrong before your agent acts on a dictated prompt.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
The crawl stopped at the 60-package limit. The rest of the tree was never resolved.
36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)
57 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.
+45 more not listed. The counts by reason above cover all of them.
Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.