Permission-aware onboarding MCP server: answers about a codebase, filtered by the caller's role.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
ONBOARD_TOKENAPI keyrequiredThe token this client uses. Set it to the same value as one of the role tokens below; that role decides what you see.
ONBOARD_TOKEN_CONTRACTORAPI keyoptionalToken for the contractor role (any secret you choose)
ONBOARD_TOKEN_EMPLOYEEAPI keyoptionalToken for the employee role (any secret you choose)
ONBOARD_TOKEN_MAINTAINERAPI keyoptionalToken for the maintainer role (any secret you choose)
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge has not completed a tools/list handshake against this endpoint, so it holds no observation of what the server exposes. Nothing here says it exposes nothing.
Permission-aware onboarding MCP server: answers about a codebase, filtered by the caller's role.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.