# @inite/ideaudit-tools

The scoring behind an audit allowed to say no. Twenty deterministic tools, offline, no account.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.1.0
- **Author:** studio.inite
- **License:** Apache-2.0
- **npm:** @inite/ideaudit-tools
- **Endpoints:** streamable-http https://api.inite.studio/mcp
- **Source:** https://github.com/inite-ai/ideaudit-mcp
- **Endpoint health:** reachable (last checked 2026-09-17T01:22:06.799Z, 2 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 16 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-08T01:10:11.251Z
- **Version scanned:** 1.0.0
- **CVEs:** none found by OSV at scan time

## Tools

20 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `compute_barrier` — Compute barrier_score (0-24) + label (PRISTINE/OPEN/COMPETITIVE/CROWDED) from competitor counts + SERP noise fraction.
- `compute_budget_proof` — Compute budget_proof_score (0-10) + label (STRONG/CONFIRMED/WEAK/ABSENT) + purchase_intent_pct from pricing hits + review-site hits + intent mentions.
- `compute_build_complexity` — Compute build_complexity_penalty (0-10, higher = worse) + per-factor breakdown. Hard tags: ml/realtime/blockchain/hardware/compliance/custom-ai/regulated/on-dev
- `compute_collection_scores` — Compute 12 deterministic collection scores (0-100) + badges + death reason for an enriched idea. Pure math. No external calls.
- `compute_dealbreakers_v2` — Methodology v2 dealbreakers — stage-aware weights + confidence-weighted lens scoring + risk-asymmetric verdict (GO requires score≥80 AND zero red flags AND avg 
- `compute_crossed_matrix` — Crossed-product audit explorer. Same input as compute_dealbreakers_v2 — returns substrate verdict (no-observer baseline) + crossed verdict (when observer suppli
- `compute_funding_momentum` — Compute funding_momentum_score (0-10) + badge (HOT/WARM/COOL/COLD) from tier-weighted funding-article hit counts.
- `compute_hiring_demand` — Compute hiring_demand_score (0-10) from priority-weighted ATS site hit counts (use registries/hiring-sources for priorities).
- `compute_lrs_composite_v2` — LRS composite v2 — 6 components (SV, Pain, Barrier, Monet, X-Signal, Budget-Proof). Default Python weights 0.18/0.22/0.18/0.14/0.18/0.10 sum=1.0. Returns BOTH w
- `compute_lrs_composite` — Compose lrs_final_100 (0-100) + label (WEAK/EMERGING/GOOD/STRONG/ELITE) + leaderboard_eligible flag + sub-percent breakdown. Weights: sv 0.25, sp 0.30, barrier 
- `compute_monetization` — Compute monetization_score (0-21) + label + has_pricing_anchors from pricing anchors + model tags + deal cycle hint.
- `compute_multi_source_tam` — Multi-source TAM consensus. Pass 2-3 sources of market-size text. Optional `estimateYear` per source — when supplied, the result includes yearRange and a hasSta
- `compute_ppc_spend_signal` — Wave 5 N.4 — compute ppc_spend_score (0-10) + label (STRONG/CONFIRMED/WEAK/ABSENT) + market_saturation from PPC traffic projection (avgCpcUsd, totalMonthlySpend
- `compute_search_velocity_v2` — Search velocity (0-25) v2 — canonical 0.40*volume + 0.30*trend + 0.20*intent + 0.10*geo. CRITICAL: externalVolumeNorm MUST come from external sources (Amazon BS
- `compute_search_velocity` — Compute search_velocity_score (0-25) from Trends timeline values + rising queries count + geo region count.
- `compute_social_pain` — Compute social_pain_score (0-30) + total mentions + dominant perspective (business/consumer/trend/mixed).
- `compute_urgency_composite` — Compose composite_urgency_score (0-10) + badge (LOW/MEDIUM/HIGH/VERY_HIGH/EXTREME) from 3 sub-scores: news, pain, hiring.
- `compute_x_signal` — Compute x_signal_score (0-20) + recency share + positivity rate from X/Twitter mention counts.
- `derive_kill_criteria` — Derive a falsifiable, data-driven list of kill criteria from upstream signals — the outputs of validate_unit_economics and compute_dealbreakers_v2, plus an ICP 
- `validate_unit_economics` — Sanity-check a unit-economics row before publishing it in a business-model slide. Catches the math-drift class of failures (customers × ARPU ≠ revenue), enforce

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"ideaudit-tools\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@inite/ideaudit-tools\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs locally and hosted.
- Floor 40, ceiling 64 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40inite%2Fideaudit-tools
- Install plan: https://forgeregistry.com/api/v1/packages/%40inite%2Fideaudit-tools/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40inite%2Fideaudit-tools
- HTML page: https://forgeregistry.com/registry/%40inite%2Fideaudit-tools
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
