Pre-commit code quality guardian. Detects semantic drift in AI-generated code.
After your AI wrote the code, but before it ships. HefestoAI verifies that what your project declares — deps, configs, install artifacts — matches what it actually does. HefestoAI's core contribution: detecting drift between what your project declares and what it does. These analyzers run automatically on every and catch issues that linters and security scanners miss because they're not in any…
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 2 source files from the repository archive and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
After your AI wrote the code, but before it ships. HefestoAI verifies that what your project declares — deps, configs, install artifacts — matches what it actually does. HefestoAI's core contribution: detecting drift between what your project declares and what it does. These analyzers run automatically on every and catch issues that linters and security scanners miss because they're not in any single file — they're in the inconsistency between files. Analyzer | What it catches | Rule ID |…
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.