Personal RAG over your GitHub history (commits, code, reviews), served to Claude Code over MCP.
You reviewed a permission check six months ago. Claude doesn't remember it. github-twin does — it indexes your commits and review comments, and surfaces them as retrieval hits whenever an agent writes or reviews new code in your style. Try it now from Claude Code — drop this into and reload: Your code stays on your box. Embeddings are computed locally (Ollama or sentence-transformers); only the…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 0 source files from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
You reviewed a permission check six months ago. Claude doesn't remember it. github-twin does — it indexes your commits and review comments, and surfaces them as retrieval hits whenever an agent writes or reviews new code in your style. Try it now from Claude Code — drop this into and reload: Your code stays on your box. Embeddings are computed locally (Ollama or sentence-transformers); only the LLM seam (, , ) optionally calls a hosted provider, and even that's swappable to local Ollama. The…
Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.