Agent governance with A2A/Shopify/MCP trust audits, action screening, and decision UI.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://cibcxqrqiqvzpardbdrw.supabase.co/functions/v1/ghosbc-safety-gate-mcp9 tools · 1294msaudit_a2a_agent_cardUse before depending on an unfamiliar A2A agent. Reads only the public Agent Card and optional public registry metadata, checks declared bindings/protocol versions, skill descriptions, security declarations and registry task-verification evidence, then returns a trust/readiness score plus shareable…Use before depending on an unfamiliar A2A agent. Reads only the public Agent Card and optional public registry metadata, checks declared bindings/protocol versions, skill descriptions, security declarations and registry task-verification evidence, then returns a trust/readiness score plus shareable…
| Parameter | Type | Description |
|---|---|---|
| card_url* | string | Public HTTPS A2A Agent Card URL, normally /.well-known/agent-card.json. |
audit_shopify_agentic_storefrontUse to inspect a public Shopify store's AI-shopping surface before an autonomous agent trusts it. Reads only public /.well-known/ucp, /agents.md and /api/ucp/mcp metadata, runs initialize/tools/list, screens exposed tool definitions, and returns a readiness/risk packet. It never creates or mutates…Use to inspect a public Shopify store's AI-shopping surface before an autonomous agent trusts it. Reads only public /.well-known/ucp, /agents.md and /api/ucp/mcp metadata, runs initialize/tools/list, screens exposed tool definitions, and returns a readiness/risk packet. It never creates or mutates…
| Parameter | Type | Description |
|---|---|---|
| store* | string | Public Shopify store domain or HTTPS URL, for example store.myshopify.com. |
audit_mcp_dependencyUse for a public remote MCP server that an autonomous agent depends on. Remembers the tools/list baseline, returns only added/removed/modified tools, screens new or changed tool definitions, and produces one aggregate ALLOW/REVIEW/BLOCK decision. It does not inspect server source code or authentica…Use for a public remote MCP server that an autonomous agent depends on. Remembers the tools/list baseline, returns only added/removed/modified tools, screens new or changed tool definitions, and produces one aggregate ALLOW/REVIEW/BLOCK decision. It does not inspect server source code or authentica…
| Parameter | Type | Description |
|---|---|---|
| endpoint_url* | string | Public HTTPS MCP endpoint. |
screen_agent_requestUse before an agent follows untrusted instructions or requests capabilities. Returns ALLOW, REVIEW, or BLOCK plus an audit digest. Best for prompt/policy routing; use screen_consequential_action for a concrete purchase, write, deployment, deletion or other bounded action.Use before an agent follows untrusted instructions or requests capabilities. Returns ALLOW, REVIEW, or BLOCK plus an audit digest. Best for prompt/policy routing; use screen_consequential_action for a concrete purchase, write, deployment, deletion or other bounded action.
| Parameter | Type | Description |
|---|---|---|
| text* | string | — |
| capabilities | array | — |
| mode | string | — |
screen_mcp_tool_definitionUse before exposing a third-party MCP tool to an autonomous agent, or after a tool definition changed. Screens name, description, schema and annotations for injection-like language, credential/private-context surfaces, side-effect risk and weak contracts. Advisory metadata gate, not source-code ver…Use before exposing a third-party MCP tool to an autonomous agent, or after a tool definition changed. Screens name, description, schema and annotations for injection-like language, credential/private-context surfaces, side-effect risk and weak contracts. Advisory metadata gate, not source-code ver…
| Parameter | Type | Description |
|---|---|---|
| name* | string | — |
| description | string | — |
| inputSchema | object | null | — |
| annotations | object | null | — |
screen_consequential_actionUse immediately before a consequential agent action such as purchase, payment, transfer, send, deploy, publish, execute, cart mutation, checkout mutation, or delete. Compares the proposed action with caller-declared allowed actions/targets, amount ceiling, currency and expiry. ALLOW only when expli…Use immediately before a consequential agent action such as purchase, payment, transfer, send, deploy, publish, execute, cart mutation, checkout mutation, or delete. Compares the proposed action with caller-declared allowed actions/targets, amount ceiling, currency and expiry. ALLOW only when expli…
| Parameter | Type | Description |
|---|---|---|
| action* | string | — |
| target | string | — |
| amount | number | — |
| currency | string | — |
| constraints | object | — |
sanitize_agent_payloadUse before sending context to an external model, tool or agent when the payload may contain credentials or private material. Redacts common secret patterns and flags policy-extraction language. Not a complete DLP/compliance system.Use before sending context to an external model, tool or agent when the payload may contain credentials or private material. Redacts common secret patterns and flags policy-extraction language. Not a complete DLP/compliance system.
| Parameter | Type | Description |
|---|---|---|
| payload* | — | — |
validate_agent_responseUse immediately before an agent delivers a response outside its trust boundary. Flags likely credential leakage or policy-extraction content and returns a sanitized response when review is needed. Not factuality verification.Use immediately before an agent delivers a response outside its trust boundary. Flags likely credential leakage or policy-extraction content and returns a sanitized response when review is needed. Not factuality verification.
| Parameter | Type | Description |
|---|---|---|
| response* | — | — |
buy_policy_checksUse only when free usage is exhausted or production volume is needed. Returns Stripe checkout for 10,000 prepaid GHOSBC Safety Gate checks for $19; it does not charge or receive payment credentials.Use only when free usage is exhausted or production volume is needed. Returns Stripe checkout for 10,000 prepaid GHOSBC Safety Gate checks for $19; it does not charge or receive payment credentials.
No input schema was published for this tool.
9 of 9 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Agent governance with A2A/Shopify/MCP trust audits, action screening, and decision UI.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.