Deterministic IR/IR-LINT validation, policy packs, drift vs exports (archrad). Apache-2.0.
Your architecture drifts before you write a single line of code. catches it — deterministically, in CI, before the PR merges. Define your system as a graph. ArchRAD compiles it, lints it against architecture rules, and tells you exactly what's wrong — with rule codes, not opinions. You should see something like (exact wording may vary slightly by version): For a smaller graph (single endpoint, no…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
archrad_validate_irNo description publishedThis tool published no description. Forge does not invent one.
archrad_lint_summaryNo description publishedThis tool published no description. Forge does not invent one.
archrad_suggest_fixNo description publishedThis tool published no description. Forge does not invent one.
archrad_list_rule_codesNo description publishedThis tool published no description. Forge does not invent one.
archrad_validate_driftNo description publishedThis tool published no description. Forge does not invent one.
archrad_policy_packs_loadNo description publishedThis tool published no description. Forge does not invent one.
0 of 6 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Your architecture drifts before you write a single line of code. catches it — deterministically, in CI, before the PR merges. Define your system as a graph. ArchRAD compiles it, lints it against architecture rules, and tells you exactly what's wrong — with rule codes, not opinions. You should see something like (exact wording may vary slightly by version): For a smaller graph (single endpoint, no DB edge), try ** — you will get different warnings (e.g. health/auth heuristics), not . No IR file…
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This package was last scanned before Forge began storing the resolved tree. The next scan will record it.