# ambit-cli

What you, your agents, and your machines can jointly do — and where your own time is going.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.5.0
- **Author:** Unknown
- **License:** MIT
- **npm:** ambit-cli
- **Source:** https://github.com/zz-plant/ambit
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-05T01:57:01.502Z
- **Version scanned:** 0.5.0
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `stats` — Counts of capabilities: total, reached, verified and failing, and reached per domain.
- `context` — The session briefing as one block of prose, the text ambit_briefing returns with text: true.
- `cap` — Find capabilities by domain or name. Returns the ids the other tools take.
- `decay` — Capabilities not touched for long enough to doubt, with days since the last config change.
- `combos` — Combos the graph can already support: every prerequisite in place, with a confidence.
- `diff` — Per domain, what was recently practiced, improved or regretted, from the last 50 outcomes.
- `health` — Domain health scores.
- `bottlenecks` — The capabilities the most others depend on: where an improvement pays most and a loss costs most.
- `impact` — What would stop, and what would only lose a provider, if a capability went away.
- `near` — Near-miss combos: one or two prerequisites away, with high existing maturity.
- `verify` — Run a capability's declared check and record the outcome: proof that it works, not that it is configured. Omit capId to run every declared check.
- `evidence` — Verification history of one capability: what was tried, when, and whether it passed.
- `authority` — Which reached capabilities may run unattended and which need approval. Being able to act is not permission to. Pass detail: true for every grant.
- `actions` — The actions a capability confers and whether each may be performed: read a repository yes, merge to its default branch no. Omit capId for all. To ask before act
- `plan` — What is missing for a capability, in the order it must be closed, and which steps need a person.
- `goal` — Route a goal, in words, to the capabilities that cover it: ranked, each with its plan delta.
- `paths` — The ways to reach a capability compared by setup time, risk and lock-in: which steps are config changes that can be undone, and which are installers that cannot
- `preferences` — What each person prefers, and which plans would fight it (local or hosted, one-off or recurring). Pass who for one person.
- `scope` — What a scope covers and what it does not. For a target (repo:owner/name, device:nuc, svc:ollama): every grant, whether it covers the target, and the effective m
- `affordances` — The domain of each capability, from the graph: institutional (needs an authority holder), economic (a budget), cognitive (a person), physical (a device).
- `digest` — How much work still runs through the human, and which interventions are reducible: recurring approvals and permission blocks are infrastructure shaped like a pe
- `work` — Recent work runs and what each cost: elapsed time, events, capabilities exercised, human interventions, resources.
- `usage` — Where effort went over a window in days (default 30): times exercised, duration and interventions per capability. unmapped: tools used that no node covers.
- `run_begin` — Start a work run. Returns the run id every later telemetry call attaches to. The run stays open until run_end.
- `run_end` — Close a work run with its outcome, and the value of that outcome in cents when known.
- `work_event` — Record one observation into a run. kind: event, use, intervention, resource or outcome. interventionKind: judgment, authority, knowledge, physical, clerical or 
- `economics` — Declared costs and goal values: attention value per hour, recurring and purchase costs, what each goal is worth.
- `goal_value` — One goal's economics (occurrence rate, success value, failure cost), matched by id or name.
- `opportunities` — Ranked changes worth making, from recurring human burden in the ledger priced by attention. by: attention (default), cash, roi, reliability, frontier. budget (d
- `opportunity` — One ranked opportunity in full: burden, proposed capability, acquisition, expected effect, payback, confidence.
- `can` — Ask before running a tool you have not used this session. yes: act. ask: put it to the person. no: do not retry it under another name. Also returns the reason, 
- `roi` — Realized ROI of an applied proposal: interventions, hours, attention dollars and reliability before and after, against its prediction. Writes the observation ba
- `roi_summary` — Every applied proposal's observed hours and dollars saved per year, and forecast accuracy: the cumulative headline.
- `catalog` — The ways to acquire a capability (build, buy, subscribe, delegate, hire) compared by setup, one-time and recurring cost, privacy, verification and rollback.
- `audit` — The audit trail: a run end to end, a proposal's steps, approval and result, or one person's approvals and interventions. target: run id, proposal id, human name
- `incidents` — Probe the hosts the infrastructure manifest names and open an incident run per offline service, with the authority decision for recovery (restart ALLOW, CONFIRM
- `incident_resolve` — Close the open incident run for a service with its outcome. MTTR is the ledger's own elapsed time.
- `portfolio` — Across imported federation receipts: burden that recurs in several environments, person-specific single points of failure, and (with budget) where spend gains m
- `since` — What entered the reachable frontier between two ISO timestamps (default: earliest observation to now), split into acquired and emerged through composition.
- `blocked` — Record that a task was blocked by a missing capability. The same deficit hit repeatedly is infrastructure that should exist.

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"ambit-cli\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"ambit-cli\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 11, ceiling 29 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/ambit-cli
- Install plan: https://forgeregistry.com/api/v1/packages/ambit-cli/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/ambit-cli
- HTML page: https://forgeregistry.com/registry/ambit-cli
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
