One profile — skills, credentials, and memory — synced to every agent tool via one MCP URL.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
get_contextBootstrap this agent for the current user in one call: returns the user's enabled skills (names + summaries) and their most relevant recent memories. Call this at the start of a session.Bootstrap this agent for the current user in one call: returns the user's enabled skills (names + summaries) and their most relevant recent memories. Call this at the start of a session.
No input schema was published for this tool.
list_skillsList the user's enabled skills with slug, version, and summary.List the user's enabled skills with slug, version, and summary.
No input schema was published for this tool.
get_skillFetch the full content of one skill by slug, rendered for this client. format defaults to 'claude' (SKILL.md); other values: 'cursor', 'agents-md'.Fetch the full content of one skill by slug, rendered for this client. format defaults to 'claude' (SKILL.md); other values: 'cursor', 'agents-md'.
No input schema was published for this tool.
rememberSave a durable fact about the user so every agent tool can recall it later. Use for stable preferences, facts, and decisions — not transient task state.Save a durable fact about the user so every agent tool can recall it later. Use for stable preferences, facts, and decisions — not transient task state.
No input schema was published for this tool.
recallSearch the user's memories and return the most relevant facts with their provenance (where and when each was learned).Search the user's memories and return the most relevant facts with their provenance (where and when each was learned).
No input schema was published for this tool.
forgetDelete one memory by its id (as returned by recall).Delete one memory by its id (as returned by recall).
No input schema was published for this tool.
list_credentialsList the names of the user's stored API credentials (metadata only — never the values). Requires the secrets:read grant, which is off by default.List the names of the user's stored API credentials (metadata only — never the values). Requires the secrets:read grant, which is off by default.
No input schema was published for this tool.
get_credentialFetch one credential by name. Returns an ENCRYPTED blob (ciphertext + wrapped key) that must be decrypted client-side with the user's master key — the server never holds plaintext. Requires the secrets:read grant.Fetch one credential by name. Returns an ENCRYPTED blob (ciphertext + wrapped key) that must be decrypted client-side with the user's master key — the server never holds plaintext. Requires the secrets:read grant.
No input schema was published for this tool.
8 of 8 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
One profile — skills, credentials, and memory — synced to every agent tool via one MCP URL.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.