# com.apished/apished

Validates PESEL/NIP/REGON/IBAN/Luhn/ISBN/EAN/BIC/VAT; RPN, dates, hash, tokens, random, encode, time

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.3.0
- **Author:** com.apished
- **License:** Unknown
- **Endpoints:** streamable-http https://apished.com/mcp
- **Source:** https://apished.com
- **Endpoint health:** reachable (last checked 2026-09-30T05:59:27.090Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-30T05:59:27.090Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

52 declared. Observed from a live `tools/list` probe.
- `color_contrast` — Computes the WCAG 2.1 contrast ratio between two hex colors. Alpha, if present, is composited over white first.
- `color_convert` — Converts a color between hex, rgb, hsl, and hsv. value's shape depends on from/to: a string for hex, an object ({r,g,b,a?} etc.) otherwise.
- `csv_from_json` — Converts JSON records to CSV text. columns is the explicit, ordered header — JSON object key order can't be relied on to infer it.
- `csv_parse` — Parses CSV text into rows of string fields (no type guessing). Ragged rows are tolerated — use csv_validate to detect them.
- `csv_stats` — Parses CSV text (header row required) and reports per-column non-empty/empty value counts across the data rows. No numeric aggregation.
- `csv_to_json` — Converts CSV text to JSON: header=true (default) returns one object per data row keyed by the header row; header=false returns raw rows. Every value is a string
- `csv_validate` — Reports whether CSV text is structurally well-formed: every row has the same field count as the first.
- `datemath_add` — Adds years/months/days to date. years/months are applied together with end-of-month clamping — e.g. 2026-01-31 + 1 month = 2026-02-28, not an overflowed 2026-03
- `datemath_age` — Age in whole years as of asOf (optional, defaults to the current UTC date). A Feb-29 birthDate is treated as falling on March 1 in a non-leap asOf year.
- `datemath_businessdays` — Counts days in [from, to] (inclusive on both ends) whose weekday is in weekdays (default mon-fri) and which aren't in holidays.
- `datemath_dayofweek` — Day of the week for date: both the weekday name and its ISO 8601 weekday number (1=Monday..7=Sunday).
- `datemath_diff` — Day difference between two YYYY-MM-DD dates: to minus from, in whole days. Negative if to is before from.
- `datemath_leapyear` — Checks whether year is a leap year in the Gregorian calendar.
- `datetime_now` — Returns the actual current date/time — an LLM has a training cutoff and no live clock, so it can't know what time it actually is right now.
- `ean_validate` — Validates an 8-digit (EAN-8), 12-digit (UPC-A), 13-digit (EAN-13), or 14-digit (GTIN-14) barcode checksum: alternating weights 1 3 applied right-to-left, check 
- `email_validate` — Checks value is a single, bare RFC 5322 email address — syntax only, not a deliverability check. user@localhost is valid (no TLD required). "Name <email>" displ
- `encode_decode` — Decodes rot13, base64, base64url, base32, hex, uuencode, urlcomponent, urlform, or html text back to the original. encoding in the result is "text" if the decod
- `encode_encode` — Encodes plain UTF-8 text into rot13, base64, base64url, base32, hex, uuencode, urlcomponent (RFC 3986 percent-encoding, space -> %20), urlform (application/x-ww
- `hash_digest` — Computes a hash digest of input (decoded per encoding: "text" default, "base64", or "hex") using algo: md5, sha1, sha256, sha512, or crc32. Returns the digest a
- `hash_hmac` — Computes an HMAC of input (decoded per encoding) using algo: md5, sha1, sha256, or sha512 (crc32 isn't offered — it's a checksum, not a cryptographic primitive 
- `iban_validate` — Validates an IBAN's length for its issuing country (per the SWIFT IBAN registry) and its mod-97 checksum. Does not decompose the BBAN into a bank code/account n
- `isbn_validate` — Validates a 10- or 13-character ISBN. ISBN-10 uses weights 10..1 over 10 characters (last may be X, worth 10), sum mod 11 must be 0. ISBN-13 uses the same GTIN 
- `jsonschema_validate` — Validates document against schema (JSON Schema draft-07 or 2020-12). Reports one specific violation per call, not an aggregated list.
- `luhn_validate` — Validates a numeric string against the Luhn (mod-10) checksum — payment card numbers, IMEI numbers, and similar identifiers.
- `network_cidr_contains` — Reports whether a CIDR block contains an address. Different address families (IPv4 vs IPv6) never match.
- `network_cidr_info` — Parses a CIDR block and reports its network address, address range, and address count. An address with host bits set (e.g. 10.14.32.17/21) is normalized to its 
- `network_cidr_overlaps` — Reports whether two CIDR blocks share any address.
- `nip_validate` — Validates the checksum of a 10-digit Polish tax identification number (NIP). Checksum uses weights 6 5 7 2 3 4 5 6 7 over the first 9 digits; sum mod 11 must eq
- `pesel_validate` — Validates the checksum of an 11-digit Polish national identification number (PESEL). Checksum uses weights 1 3 7 9 1 3 7 9 1 3 over the first 10 digits; control
- `pipe_run` — Runs a short ordered chain of existing apished operations in one call (same as POST /v1/pipe/run), passing one named field of each step's result into the next s
- `random_int` — Generates cryptographically random integers in [min, max] (inclusive), using crypto/rand — an actual random value, not a guess. count defaults to 1, max 1000.
- `regex_extract` — Extracts up to maxMatches non-overlapping regex matches from input, using Go's RE2-based regexp engine (linear-time, no backreferences/lookaround). Named groups
- `regex_match` — Tests input against pattern (Go's regexp package: RE2 syntax, not PCRE — no backreferences or lookaround; use inline flags like (?i) for case-insensitive matchi
- `regex_replace` — Replaces every regex match of pattern in input with replacement, which may reference capture groups as $1, $name, etc. (Go's Regexp.Expand syntax).
- `regex_split` — Splits input around regex matches of pattern, returning at most limit substrings (the last holds the unsplit remainder). limit<=0 means no limit.
- `regon_validate` — Validates the checksum of a 9- or 14-digit Polish business registry number (REGON). 9-digit: weights 8 9 2 3 4 5 6 7 over the first 8 digits, sum mod 11 (10 map
- `rpncalc_eval` — Evaluates a Reverse Polish Notation (postfix) expression: whitespace-separated tokens, each a number or an operator/function that pops its operands off a stack 
- `swiftbic_validate` — Structural format validation only for a SWIFT/BIC code: 8 or 11 characters (4 letters bank code + 2 letters country code + 2 alphanumeric location code + option
- `text_charat` — Returns the 0-indexed character (rune) at index in text.
- `text_count` — Counts non-overlapping occurrences of substring in text (rune-safe, not byte-based).
- …and 12 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"apished\": {\n      \"type\": \"http\",\n      \"url\": \"https://apished.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs commands; runs on someone else's infrastructure.
- Floor 40, ceiling 68 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.apished%2Fapished
- Install plan: https://forgeregistry.com/api/v1/packages/com.apished%2Fapished/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.apished%2Fapished
- HTML page: https://forgeregistry.com/registry/com.apished%2Fapished
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
