# bundlebox

Where the work is, packed before the agent reads: brief, symbol tables, findings, token bill.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.8.0
- **Author:** io.github.blackswanalpha
- **License:** MIT
- **npm:** bundlebox
- **Source:** https://github.com/blackswanalpha/bundlebox
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-23T00:28:13.417Z
- **Version scanned:** 0.8.0
- **CVEs:** none found by OSV at scan time

## Tools

24 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `intake` — what is wrong, found locally; ends holding lanes, the last point before anything spends
- `orient` — what a session gets handed instead of searching
- `measure` — what sessions cost, what the local path displaced, and what packing a task is worth
- `ops` — is this box healthy
- `buckmaster` — train the process model on everything above, then turn it into automation
- `situation` — what is happening right now: services, what is failing, and what the detectors see
- `genesis` — the inlet: what the world declares that no scenario touches, packed to briefs
- `scenarios` — run the corpus against the running system and read what it means
- `audit` — which areas have no current audit, and the briefs that would produce one
- `watch` — fold what was spent, and rebuild the one page that shows it
- `bootstrap` — bring a fresh workspace up: find what is wrong, build what a session reads, rebuild the page
- `factory` — one tick of the whole free path: intake, orient, measure, buckmaster, watch
- `full` — the whole pipeline: what is happening, what is wrong, what a session gets, what the system does, what it cost
- `practice` — fill the corpus: plan, send a pack per gap to an agent, keep what the verifier passes, remember the rest, close one
- `bb_pinpoint` — One problem -> one focused brief: the files and symbol regions located already (quoted with line numbers), the scope that fits one window, evidence already on f
- `bb_context` — Does this set of files fit in one session? Returns FITS / TIGHT / SPLIT / HEAVY with the token parts (overhead, payload, churn, reserve) and, when SPLIT, the cu
- `bb_snapgen` — Reference tables built from the tree and kept fresh by fingerprint: layout, symbols-<dir> (name file:line), routes, docs, commands, hot, tests, deps. With no `t
- `bb_findings` — Open findings from the last `bb scan`: id, severity, detector, title, primary file. Filter by detector or minimum severity.
- `bb_scan` — Run the zero-token detectors now (seconds) and return the per-detector counts. Use bb_findings to read the results.
- `bb_oversight_brief` — What is already known about these files from the last oversight scan: god-shaped, duplicated, bloated, vibe-coded marks, and the guideline to apply while editin
- `bb_explain` — One finding in full: evidence, fix hint, actuator, and the triage derivation (why it was or was not promoted).
- `bb_tokens_estimate` — Estimated tokens per file and in total, with the calibrated estimator (not chars/4).
- `bb_situation` — Where this work stands, in one call: branch and what is uncommitted, what proves a change here, which artefacts are missing or stale, the work already packed, a
- `bb_session` — What the current or last session used (measured from the transcript) and what it was spared (cache: measured; automation: estimate range).

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"bundlebox\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"bundlebox\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 11, ceiling 29 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/bundlebox
- Install plan: https://forgeregistry.com/api/v1/packages/bundlebox/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/bundlebox
- HTML page: https://forgeregistry.com/registry/bundlebox
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
