Generate and validate a .specs/ bundle for your repo, then hand it to your AI coding agent
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
statusShow sprint statusShow sprint status
No input schema was published for this tool.
refineRefine specsRefine specs
No input schema was published for this tool.
reanchorRestore full project context after losing it mid-sessionRestore full project context after losing it mid-session
No input schema was published for this tool.
reportRun the Spec-First review gate: classify the change, update specs, then wait for confirmation before codingRun the Spec-First review gate: classify the change, update specs, then wait for confirmation before coding
No input schema was published for this tool.
syncCompare .specs/ against actual project state and propose fixes for driftCompare .specs/ against actual project state and propose fixes for drift
No input schema was published for this tool.
validateValidate .specs/ structure, front-matter, and cross-references; suggest fixes without auto-applyingValidate .specs/ structure, front-matter, and cross-references; suggest fixes without auto-applying
No input schema was published for this tool.
archiveArchive oversized .specs/ files (tasks.md Completed section, prompts.md) with a branch safety guardArchive oversized .specs/ files (tasks.md Completed section, prompts.md) with a branch safety guard
No input schema was published for this tool.
backfillAppend missing mandate sections (Critical Mandates, Code Philosophy, Code Rules, Re-Anchor) to existing IDE filesAppend missing mandate sections (Critical Mandates, Code Philosophy, Code Rules, Re-Anchor) to existing IDE files
No input schema was published for this tool.
api.yamlCLI / REST API / GraphQL interface specCLI / REST API / GraphQL interface spec
No input schema was published for this tool.
architecture.mdsystem design decisions and patternssystem design decisions and patterns
No input schema was published for this tool.
context.mddevelopment memory, decisions, learningsdevelopment memory, decisions, learnings
No input schema was published for this tool.
prompts.mdAI interaction log — MANDATED, update every sessionAI interaction log — MANDATED, update every session
No input schema was published for this tool.
onboarding.mdone-time onboarding prompt — delete after first useone-time onboarding prompt — delete after first use
No input schema was published for this tool.
roadmap.mdrelease milestones and objectivesrelease milestones and objectives
No input schema was published for this tool.
tasks.mdsprint tracker (backlog / current / completed)sprint tracker (backlog / current / completed)
No input schema was published for this tool.
project.yamlproject config, rules, AI context (MANDATED)project config, rules, AI context (MANDATED)
No input schema was published for this tool.
requirements.mdfunctional and non-functional requirementsfunctional and non-functional requirements
No input schema was published for this tool.
tests.mdtest strategy and coverage targetstest strategy and coverage targets
No input schema was published for this tool.
security-decisions.mdsecurity ADR log (mitigations and rationale)security ADR log (mitigations and rationale)
No input schema was published for this tool.
threat-model.mdthreat model and attack surface analysisthreat model and attack surface analysis
No input schema was published for this tool.
20 of 20 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Generate and validate a .specs/ bundle for your repo, then hand it to your AI coding agent
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.