Local-first secret scanning, rotation, vault, and audit-log tools for AI agents.
Local-first API key manager for AI developers. 1. Download + from the latest release: 5. If macOS blocks first run: 1. Download + from the latest release. 2. Same extract / verify / install steps as above. 1. Download + from the latest release. Password handling on Linux: macOS Keychain is not available. Use to read the vault password from an environment variable, or to pipe it via stdin. 1.…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 0 source files from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
Local-first API key manager for AI developers. 1. Download + from the latest release: 5. If macOS blocks first run: 1. Download + from the latest release. 2. Same extract / verify / install steps as above. 1. Download + from the latest release. Password handling on Linux: macOS Keychain is not available. Use to read the vault password from an environment variable, or to pipe it via stdin. 1. Download + from the latest release. 2. Verify: in PowerShell, should match the value in the file. 4.…
Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.