Secure secret management with a Human-In-The-Loop (HITL) interceptor for agent mutations.
This MCP server exposes Envault read + mutation tooling for MCP clients (Claude Desktop, VS Code, etc). The MCP registry is a static phonebook. There is no onboarding UX and no safety net. If you skip this step, the server will start but every tool call will fail with . 1. Sign in to Envault. 2. Open Account Settings → Security. 3. Create a new MCP Token. 4. Copy the full unmasked token value…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
envault_statusNo description publishedThis tool published no description. Forge does not invent one.
envault_contextNo description publishedThis tool published no description. Forge does not invent one.
envault_pullNo description publishedThis tool published no description. Forge does not invent one.
envault_pushNo description publishedThis tool published no description. Forge does not invent one.
envault_deployNo description publishedThis tool published no description. Forge does not invent one.
envault_approveNo description publishedThis tool published no description. Forge does not invent one.
envault_diffNo description publishedThis tool published no description. Forge does not invent one.
envault_runNo description publishedThis tool published no description. Forge does not invent one.
envault_loginNo description publishedThis tool published no description. Forge does not invent one.
envault_initNo description publishedThis tool published no description. Forge does not invent one.
envault_generate_hooksNo description publishedThis tool published no description. Forge does not invent one.
envault_auditNo description publishedThis tool published no description. Forge does not invent one.
envault_env_mapNo description publishedThis tool published no description. Forge does not invent one.
envault_env_unmapNo description publishedThis tool published no description. Forge does not invent one.
envault_env_defaultNo description publishedThis tool published no description. Forge does not invent one.
envault_mcp_installNo description publishedThis tool published no description. Forge does not invent one.
envault_mcp_updateNo description publishedThis tool published no description. Forge does not invent one.
envault_sdk_installNo description publishedThis tool published no description. Forge does not invent one.
envault_sdk_updateNo description publishedThis tool published no description. Forge does not invent one.
envault_doctorNo description publishedThis tool published no description. Forge does not invent one.
envault_versionNo description publishedThis tool published no description. Forge does not invent one.
envault_set_local_keyNo description publishedThis tool published no description. Forge does not invent one.
envault_remove_local_keyprivilegedNo description publishedThis tool published no description. Forge does not invent one.
0 of 23 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
This MCP server exposes Envault read + mutation tooling for MCP clients (Claude Desktop, VS Code, etc). The MCP registry is a static phonebook. There is no onboarding UX and no safety net. If you skip this step, the server will start but every tool call will fail with . 1. Sign in to Envault. 2. Open Account Settings → Security. 3. Create a new MCP Token. 4. Copy the full unmasked token value (you won’t be able to see it again). 5. Use it as in your MCP client config (examples below). Cloud is…
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This package was last scanned before Forge began storing the resolved tree. The next scan will record it.