@bpmnkit/cli

MCPattested
v1.1.0UnknownMITUpdated 1d agonpmGitHub

Command-line interface for Camunda 8 — deploy, manage, and monitor processes from the terminal

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
228Downloads/wk
9GitHub stars
1Forks
1d agoLast update
Reads these credentials
  • ZEEBE_CLIENT_SECRETOAuth appoptional

    OAuth client secret for Camunda SaaS

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
AuthorUnknown
LicenseMIT
Version1.1.0
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · 44ffa16
Dependencies55 resolved · 1 with advisories
Tool surface40 tools · none privileged
Security scan⚠ Warnings (3)v1.1.0 · todayHow well does this scan work?
EvalsNone
IndexedSep 30, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · none privileged
Statically extracted from the published packagev1.1.0 · 9h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

sort-bySort field

Sort field

No input schema was published for this tool.

sort-orderSort order: asc|desc

Sort order: asc|desc

No input schema was published for this tool.

askNatural language search using a local AI (claude/copilot/gemini)

Natural language search using a local AI (claude/copilot/gemini)

No input schema was published for this tool.

queryAsk in plain language; the AI translates it to a Camunda API search

Ask in plain language; the AI translates it to a Camunda API search

No input schema was published for this tool.

get-xmlGet process definition XML and render as ASCII art

Get process definition XML and render as ASCII art

No input schema was published for this tool.

processDefinitionKeyProcess definition key

Process definition key

No input schema was published for this tool.

renderRender process definition as ASCII art in the terminal

Render process definition as ASCII art in the terminal

No input schema was published for this tool.

decisionDefinitionKeyDecision definition key

Decision definition key

No input schema was published for this tool.

decisionRequirementsKeyDecision requirements key

Decision requirements key

No input schema was published for this tool.

get-start-formGet process start form and render as ASCII art

Get process start form and render as ASCII art

No input schema was published for this tool.

get-formGet user task form and render as ASCII art

Get user task form and render as ASCII art

No input schema was published for this tool.

userTaskKeyUser task key

User task key

No input schema was published for this tool.

completionGenerate shell completion scripts

Generate shell completion scripts

No input schema was published for this tool.

bashGenerate bash completion script

Generate bash completion script

No input schema was published for this tool.

zshGenerate zsh completion script

Generate zsh completion script

No input schema was published for this tool.

fishGenerate fish completion script

Generate fish completion script

No input schema was published for this tool.

workspaceProject root to search for .camunda/element-templates (default: current directory)

Project root to search for .camunda/element-templates (default: current directory)

No input schema was published for this tool.

config-folderConfig folder name searched at each level (default: .camunda)

Config folder name searched at each level (default: .camunda)

No input schema was published for this tool.

searchSearch the bundled Camunda 8 out-of-the-box connector catalog (Slack, HTTP, AWS, AI Agent, …)

Search the bundled Camunda 8 out-of-the-box connector catalog (Slack, HTTP, AWS, AI Agent, …)

No input schema was published for this tool.

listList every connector template — the bundled Camunda 8 catalog plus the project's own

List every connector template — the bundled Camunda 8 catalog plus the project's own

No input schema was published for this tool.

showShow a connector template's required/optional input keys

Show a connector template's required/optional input keys

No input schema was published for this tool.

templateIdTemplate id, e.g. io.camunda.connectors.Slack.v1

Template id, e.g. io.camunda.connectors.Slack.v1

No input schema was published for this tool.

validateValidate element templates against the Camunda schema — a .json file, or every template a project holds

Validate element templates against the Camunda schema — a .json file, or every template a project holds

No input schema was published for this tool.

pathA template .json file, or a project directory (default: the current directory)

A template .json file, or a project directory (default: the current directory)

No input schema was published for this tool.

formatOutput format: text (default) or json

Output format: text (default) or json

No input schema was published for this tool.

connectorConnector element templates — generate from OpenAPI, browse the catalog, validate a project's own

Connector element templates — generate from OpenAPI, browse the catalog, validate a project's own

No input schema was published for this tool.

generateGenerate connector templates from a local OpenAPI spec or catalog entry

Generate connector templates from a local OpenAPI spec or catalog entry

No input schema was published for this tool.

apiCatalog API id (e.g. github, stripe). Use 'connector catalog' to list.

Catalog API id (e.g. github, stripe). Use 'connector catalog' to list.

No input schema was published for this tool.

base-urlOverride the base URL from the spec

Override the base URL from the spec

No input schema was published for this tool.

id-prefixReverse-DNS id prefix (default: io.generated)

Reverse-DNS id prefix (default: io.generated)

No input schema was published for this tool.

filterRegex filter on operationId/summary (case-insensitive)

Regex filter on operationId/summary (case-insensitive)

No input schema was published for this tool.

expand-bodyDecompose top-level request body properties into individual fields

Decompose top-level request body properties into individual fields

No input schema was published for this tool.

authDefault auth type: noAuth, apiKey, basic, bearer, oauth-client-credentials-flow

Default auth type: noAuth, apiKey, basic, bearer, oauth-client-credentials-flow

No input schema was published for this tool.

dry-runPrint templates to stdout without writing files

Print templates to stdout without writing files

No input schema was published for this tool.

catalogList available API catalog entries

List available API catalog entries

No input schema was published for this tool.

deployDeploy a BPMN (or DMN/form) file to local Reebe or the active Camunda 8 profile

Deploy a BPMN (or DMN/form) file to local Reebe or the active Camunda 8 profile

No input schema was published for this tool.

filePath to the resource file

Path to the resource file

No input schema was published for this tool.

targetDeployment target: "local" (Reebe, via ZEEBE_ADDRESS) or "camunda8" (active profile)

Deployment target: "local" (Reebe, via ZEEBE_ADDRESS) or "camunda8" (active profile)

No input schema was published for this tool.

devLocal development loop — edit, simulate, lint and test every process in a folder in the browser

Local development loop — edit, simulate, lint and test every process in a folder in the browser

No input schema was published for this tool.

dirProject directory (default: current directory)

Project directory (default: current directory)

No input schema was published for this tool.

40 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Command-line interface for Camunda 8 — deploy, manage, and monitor processes from the terminal

Keywords
camundabpmncliterminalzeebeworkflowtypescriptcasen
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-09-30 — observed resolution, not a publisher declaration.

55 packages resolved · 9 direct · 1 carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the depth-4 limit. Anything below that level was never resolved.

31 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

18 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+6 more not listed. The counts by reason above cover all of them.

Not followed: optionalDependencies, peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.