Governed MCP workflows with policy validation, findings tracking, and review gates.
This package is a bootstrap installer for the native ControlKeel CLI. Both npmjs and GitHub Packages publish the same bootstrap package. The native binary is downloaded from GitHub Releases on first use, not during installation. The package installs the command. The native binary is automatically downloaded on first use. Published companion packages that tie into the main CLI: for OpenCode plugin…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 3 source files from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
This package is a bootstrap installer for the native ControlKeel CLI. Both npmjs and GitHub Packages publish the same bootstrap package. The native binary is downloaded from GitHub Releases on first use, not during installation. The package installs the command. The native binary is automatically downloaded on first use. Published companion packages that tie into the main CLI: for OpenCode plugin installs for Pi extension installs You can also install the same bootstrap package from GitHub…
This package was last scanned before Forge began storing the resolved tree. The next scan will record it.