# com.boosthis/boosthis

Read-only performance insights for your Boosthis projects: speed, crashes, traces, and fixes.

- **Type:** MCP server
- **Trust:** 30/100 (D), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0-alpha.82
- **Author:** com.boosthis
- **License:** Unknown
- **Endpoints:** streamable-http https://www.boosthis.com/mcp
- **Source:** https://www.boosthis.com/
- **Endpoint health:** reachable (last checked 2026-09-30T00:24:21.591Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

30/100 (D), scored on the content rubric
- Publisher verified: no
- Install scripts: suspicious script found
- Prompt-injection scan: findings present
- Obfuscation scan: clean
- Evidence age: 16 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-09-19T05:05:44.974Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (warning) in the `boosthis_get_integration_kit` tool: Exfiltration-shaped instruction

## Tools

29 declared. Observed from a live `tools/list` probe.
- `boosthis_list_rules` — Every Boosthis performance rule available to this runtime, as ids and titles. The index for boosthis_get_rule.
- `boosthis_get_rule` — Full detail for one rule: title, when_to_apply, evidence, and - for a registered project - the fix_template. fix_available: false means no fix text is served he
- `boosthis_get_integration_kit` — A Boosthis kit for THIS project - no upload; the single-use address needs no key, include_files no shell. Withheld reply? Same kit at GET https://www.boosthis.c
- `boosthis_get_removal_kit` — Removing Boosthis from this project: the ordered sequence, every kit file, the package entries, the config, the calls to strip, and the Boosthis entries in an A
- `boosthis_match_rules_for_code` — Ranks Boosthis rules against a code snippet on each rule's id tokens and when_to_apply text, up to 8 candidates. Ranked guesses from a text match, not findings:
- `boosthis_check_for_update` — Whether a newer Boosthis kit exists for this project, without fetching it: latest_version, update_available, comparison (behind/current/ahead/unknown), the chan
- `boosthis_session_summary` — Per-screen p50/p75/p95 and worst rating, worst screens first, with p99, spike ratio and stdev spread where the server has them. No read credentials: a dashboard
- `boosthis_what_should_i_look_at_next` — A triage ordering: the worst-rated and slowest screens first, each with a one-line reason. No read credentials: a dashboard pointer, never empty. Read-only. Mor
- `boosthis_snapshot` — The latest upload from one install, whichever sections that runtime records: a phone app has a boot ladder, frame meters and Frustration, a back end none of the
- `boosthis_crash_risk` — Crash classes this app recorded - uncaught errors, unhandled rejections and caught render near-misses - newest first, each with an error name, a redacted top fr
- `boosthis_full_stack_trace` — One user action across the stack as a nested waterfall of spans (layer, route label, duration, start offset, rating), each under the call that caused it; critic
- `boosthis_connection_status` — What Boosthis knows about this account's installs (same check over plain HTTPS: GET /api/connection-status, project key as bearer): for each, the runtime, its s
- `boosthis_which_kits` — Names which Boosthis kits this project needs, from manifest file names already visible in it - nothing is downloaded or executed. The inventory step before boos
- `boosthis_verify_kit_install` — Check a Boosthis kit's FILES ON DISK are byte-perfect (same check over plain HTTPS: POST https://www.boosthis.com/api/kit/<runtime>/verify) - a pass proves the 
- `boosthis_maintenance_mix` — The Maintenance Mix: of the issues a project actually fixed, how many were fixed before users felt them (flagged by a Boosthis rule, app still healthy) versus a
- `boosthis_trend` — One project's last 30 days: for each finished day, how many measurements arrived, typical and worst-case screen time, how many were rated poor, new crashes, and
- `boosthis_vigilance` — One project's Vigilance verdict and every watch behind it, worst first: what each watches, what it says now, and its evidence. Also what it cannot watch and why
- `boosthis_jobs` — Every scheduled job this runtime reports, each in one state: on time; late; app unheard (the app, not the job, went quiet); never reported a run; or no rhythm d
- `boosthis_exposure` — What this app was OBSERVED exposing: leaks, cookie flags, dev settings left on, turned-away traffic, build age, swallowed errors. Each carries its limits; never
- `boosthis_structure` — What is structurally wrong with this app, from the actions it traced: the route to fix first, single points of failure, pairs bouncing back and forth, call burs
- `boosthis_alerts` — This account's Boosthis alerts, in the dashboard's words: Open, Read, Fixed, Returned (marked fixed, then happened again) or Dismissed, each saying whether its 
- `boosthis_promises` — The standing promises this project's developer has recorded - what they want kept as the project changes, surviving earlier sessions and assistants. Each says w
- `boosthis_remember_promise` — Saves what the developer wants kept true from now on as a promise on the project, in their words, surviving later sessions and other assistants. Restating one r
- `boosthis_check_claim` — Holds a sentence an assistant is about to say against what the running app actually did. Exactly one of four answers: supported, not supported by the measuremen
- `boosthis_release_check` — How the last release held up, from the running app after it shipped, against the version this project's own measurements reported. Six answers: did served fixes
- `boosthis_ai_changes` — What happened after the changes Boosthis witnessed here - only those that passed through it: a fix it served, or a sentence it was asked to check. Each reads ke
- `boosthis_platform_allowances` — What this project's hosting platform allows, confirmed on real installs. One answer per fact: the time and memory limits a run can read, a live countdown, a pro
- `boosthis_project_diary` — This project's life in order, joined from what Boosthis already keeps: fixes served, claims checked, promises and their verdicts, history moves, and changes ass
- `boosthis_record_change` — File a change you made here, so the next assistant knows it happened - Boosthis cannot see code or commits. Kept as YOUR claim, never becoming evidence. Passwor

## Install

**Verdict: do-not-install** — Do not install: 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it.
**Blocking**
- 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it. — tool:boosthis_get_integration_kit: Exfiltration-shaped instruction
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Client configuration withheld.** Client configs are withheld because this entry has a blocking finding. Show the warnings below to the person installing it.
If they have seen the findings and still want to proceed, request the plan again with acknowledge_warnings=true.

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: mutates data; runs on someone else's infrastructure.
- Floor 26, ceiling 50 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.boosthis%2Fboosthis
- Install plan: https://forgeregistry.com/api/v1/packages/com.boosthis%2Fboosthis/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.boosthis%2Fboosthis
- HTML page: https://forgeregistry.com/registry/com.boosthis%2Fboosthis
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
