@lexq/cli

MCPattestedlive
v1.0.0io.lexqApache-2.0Updated 19d agonpmGitHub

The Decision Operations Platform for engineering teams

Endpoint healthlive
checked 11 days ago · 46ms · auth required
100% of the last 2 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (stdio, streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
707Downloads/wk
19d agoLast update
Needs 1 credential before it runs
  • LEXQ_API_KEYAPI keyrequired

    LexQ API key. Or leave it unset and run `lexq auth login` once.

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorio.lexq
LicenseApache-2.0
Version1.0.0
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · e156fe0
Dependencies✓ 12 resolved · none vulnerable
Tool surface40 tools · 4 privileged
Security scan✓ Cleanv0.4.0 · 20d agoHow well does this scan work?
EvalsNone
IndexedSep 13, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 4 privileged
Statically extracted from the published packagev0.4.0 · 20d ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

lexq_whoamiShow current authentication info (tenant ID, user ID, role).

Show current authentication info (tenant ID, user ID, role).

No input schema was published for this tool.

lexq_groups_listList all policy groups (tenant-wide, priority ASC).

List all policy groups (tenant-wide, priority ASC).

No input schema was published for this tool.

lexq_groups_getGet a single policy group by ID.

Get a single policy group by ID.

No input schema was published for this tool.

lexq_groups_createCreate a new policy group. Requires name. Priority is auto-assigned (appended last, tenant-wide); use lexq_groups_reorder to change order. Optionally set conflict resolution, activation group, and description. Policy groups that share an activationGroup form a cluster and must share the same activa…

Create a new policy group. Requires name. Priority is auto-assigned (appended last, tenant-wide); use lexq_groups_reorder to change order. Optionally set conflict resolution, activation group, and description. Policy groups that share an activationGroup form a cluster and must share the same activa…

No input schema was published for this tool.

lexq_groups_updateUpdate a policy group. Only provided fields are updated; omitted fields remain unchanged.

Update a policy group. Only provided fields are updated; omitted fields remain unchanged.

No input schema was published for this tool.

lexq_groups_deleteprivilegedArchive a policy group. Only non-live groups can be deleted. This is irreversible.

Archive a policy group. Only non-live groups can be deleted. This is irreversible.

No input schema was published for this tool.

lexq_groups_reorderReorder policy groups by priority. Priority is tenant-wide and flat (1...N continuous); array index 0 = priority 1 (highest precedence). activationGroup is not affected — this only changes priority.

Reorder policy groups by priority. Priority is tenant-wide and flat (1...N continuous); array index 0 = priority 1 (highest precedence). activationGroup is not affected — this only changes priority.

No input schema was published for this tool.

lexq_ab_test_startStart an A/B test on a policy group. Requires a challenger version ID and traffic rate. The split is computed from context.trafficKey on each execution request; requests that omit it never reach the challenger and the test stays at 0%.

Start an A/B test on a policy group. Requires a challenger version ID and traffic rate. The split is computed from context.trafficKey on each execution request; requests that omit it never reach the challenger and the test stays at 0%.

No input schema was published for this tool.

lexq_ab_test_stopStop a running A/B test. All traffic is restored to the control (current) version.

Stop a running A/B test. All traffic is restored to the control (current) version.

No input schema was published for this tool.

lexq_ab_test_adjustAdjust traffic rate of a running A/B test.

Adjust traffic rate of a running A/B test.

No input schema was published for this tool.

lexq_versions_listList all versions of a policy group.

List all versions of a policy group.

No input schema was published for this tool.

lexq_versions_getGet a single version by ID, including its rules and fact requirements.

Get a single version by ID, including its rules and fact requirements.

No input schema was published for this tool.

lexq_versions_createCreate a new DRAFT version in a policy group. Optionally provide a commit message and effective date range.

Create a new DRAFT version in a policy group. Optionally provide a commit message and effective date range.

No input schema was published for this tool.

lexq_versions_updateUpdate a DRAFT version. Only DRAFT versions can be modified. Only provided fields are changed.

Update a DRAFT version. Only DRAFT versions can be modified. Only provided fields are changed.

No input schema was published for this tool.

lexq_versions_deleteprivilegedDelete a DRAFT version. Only DRAFT versions can be deleted.

Delete a DRAFT version. Only DRAFT versions can be deleted.

No input schema was published for this tool.

lexq_versions_cloneClone an existing version to create a new DRAFT. Useful when the source version is already published.

Clone an existing version to create a new DRAFT. Useful when the source version is already published.

No input schema was published for this tool.

lexq_rules_listList all rules in a version (priority ASC). Returns summary with conditionSummary and actionSummary.

List all rules in a version (priority ASC). Returns summary with conditionSummary and actionSummary.

No input schema was published for this tool.

lexq_rules_getGet full rule detail including condition tree and action definitions.

Get full rule detail including condition tree and action definitions.

No input schema was published for this tool.

lexq_rules_createNo description published

This tool published no description. Forge does not invent one.

lexq_rules_updateUpdate an existing rule in a DRAFT version. Only provided fields are changed.

Update an existing rule in a DRAFT version. Only provided fields are changed.

No input schema was published for this tool.

lexq_rules_deleteprivilegedDelete a rule from a DRAFT version.

Delete a rule from a DRAFT version.

No input schema was published for this tool.

lexq_rules_reorderReorder rules by specifying rule IDs in desired order. Priorities are assigned 1...N (1-based, continuous); array index 0 = priority 1 (highest precedence).

Reorder rules by specifying rule IDs in desired order. Priorities are assigned 1...N (1-based, continuous); array index 0 = priority 1 (highest precedence).

No input schema was published for this tool.

lexq_rules_toggleEnable or disable a rule without deleting it.

Enable or disable a rule without deleting it.

No input schema was published for this tool.

lexq_facts_listList all fact definitions (input variable schema). Shows key, type, required, and PII status. Always check this before creating rules.

List all fact definitions (input variable schema). Shows key, type, required, and PII status. Always check this before creating rules.

No input schema was published for this tool.

lexq_facts_createRegister a new input variable. Key starts with a letter, then letters, numbers, and underscores (e.g. paymentAmount). Casing is not enforced. Types: STRING, NUMBER, BOOLEAN, LIST_STRING, LIST_NUMBER.

Register a new input variable. Key starts with a letter, then letters, numbers, and underscores (e.g. paymentAmount). Casing is not enforced. Types: STRING, NUMBER, BOOLEAN, LIST_STRING, LIST_NUMBER.

No input schema was published for this tool.

lexq_facts_updateUpdate a fact definition. The key is immutable. The type can change only while no rule references the fact; if any does, the call fails with FD-007 and reports the count. Only the fields you send are changed. System facts accept name, description, and PII only.

Update a fact definition. The key is immutable. The type can change only while no rule references the fact; if any does, the call fails with FD-007 and reports the count. Only the fields you send are changed. System facts accept name, description, and PII only.

No input schema was published for this tool.

lexq_facts_deleteprivilegedDelete a fact definition. System facts cannot be deleted. Neither can a fact that any rule references: that call fails with FD-006 and reports the count. Remove the references first.

Delete a fact definition. System facts cannot be deleted. Neither can a fact that any rule references: that call fails with FD-006 and reports the count. Remove the references first.

No input schema was published for this tool.

lexq_facts_action_metadataNo description published

This tool published no description. Forge does not invent one.

lexq_facts_unregisteredList facts referenced by a version's rules but not yet defined (read-only — does not block publish/deploy, INV-4). Version-wide: covers every rule in the version. Each entry carries the inferred type, suggested name, and where it is referenced (condition/action). Register them with lexq_facts_creat…

List facts referenced by a version's rules but not yet defined (read-only — does not block publish/deploy, INV-4). Version-wide: covers every rule in the version. Each entry carries the inferred type, suggested name, and where it is referenced (condition/action). Register them with lexq_facts_creat…

No input schema was published for this tool.

lexq_facts_exportExport the fact catalog. The two formats carry different things: CSV is the catalog as it stands, system facts included, for reading in a spreadsheet; JSON matches the shape that batch create accepts, so it can be fed straight back in, which is why it leaves out the fields that endpoint does not ta…

Export the fact catalog. The two formats carry different things: CSV is the catalog as it stands, system facts included, for reading in a spreadsheet; JSON matches the shape that batch create accepts, so it can be fed straight back in, which is why it leaves out the fields that endpoint does not ta…

No input schema was published for this tool.

lexq_deploy_publishPublish a DRAFT version (DRAFT → ACTIVE). Locks the version from further edits. Must have at least one rule. Undefined facts referenced by rules do not block publishing (INV-4); call lexq_facts_unregistered first to review them.

Publish a DRAFT version (DRAFT → ACTIVE). Locks the version from further edits. Must have at least one rule. Undefined facts referenced by rules do not block publishing (INV-4); call lexq_facts_unregistered first to review them.

No input schema was published for this tool.

lexq_deploy_liveDeploy an ACTIVE (published) version to live traffic. Takes effect immediately. Versions whose effective start date has not arrived are rejected (P-037) — use lexq_deploy_schedule for those. Undefined facts do not block deployment (INV-4); use lexq_facts_unregistered to review what the version refe…

Deploy an ACTIVE (published) version to live traffic. Takes effect immediately. Versions whose effective start date has not arrived are rejected (P-037) — use lexq_deploy_schedule for those. Undefined facts do not block deployment (INV-4); use lexq_facts_unregistered to review what the version refe…

No input schema was published for this tool.

lexq_deploy_rollbackRollback to the previous deployed version. Only available if there is a previous version.

Rollback to the previous deployed version. Only available if there is a previous version.

No input schema was published for this tool.

lexq_deploy_undeployRemove the live version from traffic. The version stays ACTIVE but no longer serves requests.

Remove the live version from traffic. The version stays ACTIVE but no longer serves requests.

No input schema was published for this tool.

lexq_deploy_scheduleSchedule an ACTIVE version with a future effective start date to auto-deploy at that time (Scheduled Deployment). One pending schedule per group; manual deploy/rollback/undeploy, starting an A/B test, or archiving the group cancels it. The snapshot hash is sealed at scheduling and re-verified at ex…

Schedule an ACTIVE version with a future effective start date to auto-deploy at that time (Scheduled Deployment). One pending schedule per group; manual deploy/rollback/undeploy, starting an A/B test, or archiving the group cancels it. The snapshot hash is sealed at scheduling and re-verified at ex…

No input schema was published for this tool.

lexq_deploy_unscheduleCancel the pending scheduled deployment for a group. The version itself is not affected. Fails with P-039 if no pending schedule exists.

Cancel the pending scheduled deployment for a group. The version itself is not affected. Fails with P-039 if no pending schedule exists.

No input schema was published for this tool.

lexq_deploy_schedulesList scheduled deployments across all groups (all statuses: PENDING, EXECUTED, CANCELED, FAILED), newest first.

List scheduled deployments across all groups (all statuses: PENDING, EXECUTED, CANCELED, FAILED), newest first.

No input schema was published for this tool.

lexq_deploy_historyList deployment history across all groups.

List deployment history across all groups.

No input schema was published for this tool.

lexq_deploy_detailGet detailed info about a specific deployment including snapshot hash and integrity check.

Get detailed info about a specific deployment including snapshot hash and integrity check.

No input schema was published for this tool.

lexq_deploy_overviewShow current deployment status of all groups — which version is live, last deployment type, and deployer.

Show current deployment status of all groups — which version is live, last deployment type, and deployer.

No input schema was published for this tool.

38 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

The Decision Operations Platform for engineering teams

Keywords
mcp
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-09-13 — observed resolution, not a publisher declaration.

12 packages resolved · 6 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

Not followed: peerDependencies, optionalDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.