bundlebox

MCPattested
v0.8.0io.github.blackswanalphaMITUpdated 1d agonpmGitHub

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
150Downloads/wk
2GitHub stars
1d agoLast update
Package
Authorio.github.blackswanalpha
LicenseMIT
Version0.8.0
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
Listed in Forge index+10/10
Identity verified · attested build+20/20
Ed25519 publish signature+0/5
Included automatically when the publisher runs `forge publish`
Domain verification+0/5
Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
npm maintainer match+0/5
Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
CVE scan · clean+30/30
Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain
Provenance✓ Sigstore-verified · 2907a91
Dependencies✓ 0 resolved · none vulnerable
Tool surface24 tools · none privileged
Security scan✓ Cleanv0.8.0 · 1d agoHow well does this scan work?
EvalsNone
IndexedSep 22, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

24 tools · none privileged
Statically extracted from the published packagev0.8.0 · 1d ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

intakewhat is wrong, found locally; ends holding lanes, the last point before anything spends

what is wrong, found locally; ends holding lanes, the last point before anything spends

No input schema was published for this tool.

orientwhat a session gets handed instead of searching

what a session gets handed instead of searching

No input schema was published for this tool.

measurewhat sessions cost, what the local path displaced, and what packing a task is worth

what sessions cost, what the local path displaced, and what packing a task is worth

No input schema was published for this tool.

opsis this box healthy

is this box healthy

No input schema was published for this tool.

buckmastertrain the process model on everything above, then turn it into automation

train the process model on everything above, then turn it into automation

No input schema was published for this tool.

situationwhat is happening right now: services, what is failing, and what the detectors see

what is happening right now: services, what is failing, and what the detectors see

No input schema was published for this tool.

genesisthe inlet: what the world declares that no scenario touches, packed to briefs

the inlet: what the world declares that no scenario touches, packed to briefs

No input schema was published for this tool.

scenariosrun the corpus against the running system and read what it means

run the corpus against the running system and read what it means

No input schema was published for this tool.

auditwhich areas have no current audit, and the briefs that would produce one

which areas have no current audit, and the briefs that would produce one

No input schema was published for this tool.

watchfold what was spent, and rebuild the one page that shows it

fold what was spent, and rebuild the one page that shows it

No input schema was published for this tool.

bootstrapbring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page

bring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page

No input schema was published for this tool.

factoryone tick of the whole free path: intake, orient, measure, buckmaster, watch

one tick of the whole free path: intake, orient, measure, buckmaster, watch

No input schema was published for this tool.

fullthe whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost

the whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost

No input schema was published for this tool.

practicefill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one

fill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one

No input schema was published for this tool.

bb_pinpointOne problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on file, the acceptance command, traps and guidelines. Call this BEFORE searching the tree.

One problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on file, the acceptance command, traps and guidelines. Call this BEFORE searching the tree.

No input schema was published for this tool.

bb_contextDoes this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cut.

Does this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cut.

No input schema was published for this tool.

bb_snapgenReference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `table` returns the INDEX with each table's token cost so you can choose. Read a table instead of grepping.

Reference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `table` returns the INDEX with each table's token cost so you can choose. Read a table instead of grepping.

No input schema was published for this tool.

bb_findingsOpen findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.

Open findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.

No input schema was published for this tool.

bb_scanRun the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.

Run the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.

No input schema was published for this tool.

bb_oversight_briefWhat is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editing. About 300 tokens.

What is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editing. About 300 tokens.

No input schema was published for this tool.

bb_explainOne finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).

One finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).

No input schema was published for this tool.

bb_tokens_estimateEstimated tokens per file and in total, with the calibrated estimator (not chars/4).

Estimated tokens per file and in total, with the calibrated estimator (not chars/4).

No input schema was published for this tool.

bb_situationWhere this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, and what the last echos run saw. Call this instead of git status + git diff + bb env + bb findings + bb echos.

Where this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, and what the last echos run saw. Call this instead of git status + git diff + bb env + bb findings + bb echos.

No input schema was published for this tool.

bb_sessionWhat the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

What the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

No input schema was published for this tool.

24 of 24 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

Keywords
mcp
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-09-23 — observed resolution, not a publisher declaration.

0 packages resolved · 0 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

This package declares no runtime dependencies.