meshfleet

MCPattested
v0.22.0UnknownMITUpdated 4d agonpmGitHub

Auditable multi-agent coordination for OpenCode — parallel agent fleets with P2P messaging, witnessed receipts, and quorum ratification. Who saw this, who approved it, prove it.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
217Downloads/wk
1GitHub stars
4d agoLast update
Package
AuthorUnknown
LicenseMIT
Version0.22.0
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · 87bd059
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface40 tools · 2 privileged
Security scan✓ Cleanv0.22.0 · 1d agoHow well does this scan work?
EvalsNone
IndexedOct 2, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 2 privileged
Statically extracted from the published packagev0.22.0 · 1d ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

spawn_fleetprivilegedSpawn parallel agents. Returns fleet_id. An agent banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.

Spawn parallel agents. Returns fleet_id. An agent banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.

No input schema was published for this tool.

fleet_statusCheck fleet and agent status.

Check fleet and agent status.

No input schema was published for this tool.

list_fleetsList all fleets with summaries (agent count, status, completion).

List all fleets with summaries (agent count, status, completion).

No input schema was published for this tool.

set_fleet_timeoutSet a per-fleet timeout override (in milliseconds). Agents exceeding this are auto-failed.

Set a per-fleet timeout override (in milliseconds). Agents exceeding this are auto-failed.

No input schema was published for this tool.

collect_resultsGet fleet outputs and loss tally. Only result_contract ok can bank complete; refused, blocked, artifact_missing, invalid, or absent banks failed. Declared outcome, not quality. Check lost first.

Get fleet outputs and loss tally. Only result_contract ok can bank complete; refused, blocked, artifact_missing, invalid, or absent banks failed. Declared outcome, not quality. Check lost first.

No input schema was published for this tool.

send_messageSend a P2P message from one agent to another within the same fleet. Set to_agent_id to "*" to broadcast to every other agent in the fleet (each recipient acks independently; see get_receipts).

Send a P2P message from one agent to another within the same fleet. Set to_agent_id to "*" to broadcast to every other agent in the fleet (each recipient acks independently; see get_receipts).

No input schema was published for this tool.

send_messagesSend a batch of P2P messages in ONE ledger transaction — use instead of repeated send_message calls for bulk fan-out (much faster: the recipient inbox is updated once per batch, not once per message). Atomic: one invalid message rejects the whole batch. Max 1000 messages per call.

Send a batch of P2P messages in ONE ledger transaction — use instead of repeated send_message calls for bulk fan-out (much faster: the recipient inbox is updated once per batch, not once per message). Atomic: one invalid message rejects the whole batch. Max 1000 messages per call.

No input schema was published for this tool.

get_inboxGet messages in an agent's inbox, optionally since a timestamp.

Get messages in an agent's inbox, optionally since a timestamp.

No input schema was published for this tool.

ack_messageAcknowledge a message, removing it from the agent's inbox. Writes an 'ack' receipt (per-recipient — a broadcast is acked independently by each recipient).

Acknowledge a message, removing it from the agent's inbox. Writes an 'ack' receipt (per-recipient — a broadcast is acked independently by each recipient).

No input schema was published for this tool.

receiptWrite a non-consuming receipt on a message — the audit primitive. Use actions like 'seen', 'r-ack' (approve), 'retracted'. Unlike ack_message, the message stays in the inbox. One receipt per (message, agent, action); repeat calls are idempotent.

Write a non-consuming receipt on a message — the audit primitive. Use actions like 'seen', 'r-ack' (approve), 'retracted'. Unlike ack_message, the message stays in the inbox. One receipt per (message, agent, action); repeat calls are idempotent.

No input schema was published for this tool.

get_receiptsGet the full receipt trail for a message: who acked, who annotated, when. Answers 'who saw this and who acted on it'.

Get the full receipt trail for a message: who acked, who annotated, when. Answers 'who saw this and who acted on it'.

No input schema was published for this tool.

verify_ledgerNo description published

This tool published no description. Forge does not invent one.

verify_ledger_v2Versioned verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Normal parent-server startup recovery or migration may initialize or change the configured ledger before tool dispatch. Returns the unchanged internal-consistency report inside meshfleet.…

Versioned verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Normal parent-server startup recovery or migration may initialize or change the configured ledger before tool dispatch. Returns the unchanged internal-consistency report inside meshfleet.…

No input schema was published for this tool.

verify_ledger_v3Opt-in verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Returns a detached meshfleet.verify/v3 report with one local consistency band per finding, derived only from its severity. Those labels are not provenance or confidence and do not establish…

Opt-in verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Returns a detached meshfleet.verify/v3 report with one local consistency band per finding, derived only from its severity. Those labels are not provenance or confidence and do not establish…

No input schema was published for this tool.

open_ratificationOpen a quorum vote ('council') over the fleet. Broadcasts a proposal; peers vote with cast_vote. Ratifies when approvals reach the quorum and every required signoff approves. Returns the proposal message_id.

Open a quorum vote ('council') over the fleet. Broadcasts a proposal; peers vote with cast_vote. Ratifies when approvals reach the quorum and every required signoff approves. Returns the proposal message_id.

No input schema was published for this tool.

cast_voteCast a vote on an open ratification. approve=true records approval, approve=false rejection. Re-casting CHANGES your effective vote (each change appends a new sequenced receipt — history is never rewritten); repeating your current vote is a no-op.

Cast a vote on an open ratification. approve=true records approval, approve=false rejection. Re-casting CHANGES your effective vote (each change appends a new sequenced receipt — history is never rewritten); repeating your current vote is a no-op.

No input schema was published for this tool.

tally_ratificationRead the live vote tally and current status (open / ratified / rejected / expired) of a ratification, and persist the status if it has reached a terminal state.

Read the live vote tally and current status (open / ratified / rejected / expired) of a ratification, and persist the status if it has reached a terminal state.

No input schema was published for this tool.

sweep_ratificationsEvaluate every open ratification now and persist any that reached a terminal state (deadline expiry, silent-approval, unreachable quorum). The server also sweeps automatically every AGENT_MESH_RATIFY_SWEEP_MS (default 60s).

Evaluate every open ratification now and persist any that reached a terminal state (deadline expiry, silent-approval, unreachable quorum). The server also sweeps automatically every AGENT_MESH_RATIFY_SWEEP_MS (default 60s).

No input schema was published for this tool.

register_capabilityRegister an agent's capabilities (role, skills, model) for routing.

Register an agent's capabilities (role, skills, model) for routing.

No input schema was published for this tool.

route_workRoute a work description to the best-matching registered agents by keyword + role/skill overlap scoring (with synonym expansion), weighted by routing feedback (success/fail history). top_n controls how many matches to return (default 1, max = fleet size).

Route a work description to the best-matching registered agents by keyword + role/skill overlap scoring (with synonym expansion), weighted by routing feedback (success/fail history). top_n controls how many matches to return (default 1, max = fleet size).

No input schema was published for this tool.

compile_route_candidatesOffline projection of caller-supplied route-candidate snapshots. Does not persist, rank, execute, authorize, wake, or contact providers.

Offline projection of caller-supplied route-candidate snapshots. Does not persist, rank, execute, authorize, wake, or contact providers.

No input schema was published for this tool.

recommend_routeAdvisory-only ranking over caller-supplied sanitized task traits and candidate snapshots. Does not persist, execute, authorize, wake agents, or contact providers.

Advisory-only ranking over caller-supplied sanitized task traits and candidate snapshots. Does not persist, execute, authorize, wake agents, or contact providers.

No input schema was published for this tool.

plan_speculative_backlogPure, caller-approved speculative backlog projection. Does not persist, execute, authorize, wake agents, contact providers, poll, allocate capacity, schedule, spend, send, or publish.

Pure, caller-approved speculative backlog projection. Does not persist, execute, authorize, wake agents, contact providers, poll, allocate capacity, schedule, spend, send, or publish.

No input schema was published for this tool.

record_routing_outcomeRecord whether a routed task succeeded or failed. Future route_work calls for the same agent weight their score by accumulated outcomes (Wilson-style). NOTE: outcomes are currently accumulated PER AGENT, not per capability — capability_key is recorded for forward compatibility but does not yet scop…

Record whether a routed task succeeded or failed. Future route_work calls for the same agent weight their score by accumulated outcomes (Wilson-style). NOTE: outcomes are currently accumulated PER AGENT, not per capability — capability_key is recorded for forward compatibility but does not yet scop…

No input schema was published for this tool.

list_agentsList all available premade agents from .opencode/agents/ directories.

List all available premade agents from .opencode/agents/ directories.

No input schema was published for this tool.

attach_agentAttach an agent to a running fleet. It banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.

Attach an agent to a running fleet. It banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.

No input schema was published for this tool.

pingMinimal liveness check. Returns { status: 'ok', timestamp }.

Minimal liveness check. Returns { status: 'ok', timestamp }.

No input schema was published for this tool.

subscribe_inboxSubscribe to an agent's inbox via Server-Sent Events (SSE). Returns a stream URL that the agent opens to receive real-time push of incoming P2P messages. Falls back to polling get_inbox if SSE is unreachable. If the operator set MESHFLEET_AUTH_TOKEN, requests to the stream must carry it (Authorizat…

Subscribe to an agent's inbox via Server-Sent Events (SSE). Returns a stream URL that the agent opens to receive real-time push of incoming P2P messages. Falls back to polling get_inbox if SSE is unreachable. If the operator set MESHFLEET_AUTH_TOKEN, requests to the stream must carry it (Authorizat…

No input schema was published for this tool.

subscribe_eventsSubscribe to the unified fleet-wide event stream via Server-Sent Events (SSE). Returns a stream URL that emits every ledger event (messages, receipts, ratifications, spawns, completions, discussions) as it is appended. Keep-alive :hb comment frames are sent every 30s. Optional fleet_id filter narro…

Subscribe to the unified fleet-wide event stream via Server-Sent Events (SSE). Returns a stream URL that emits every ledger event (messages, receipts, ratifications, spawns, completions, discussions) as it is appended. Keep-alive :hb comment frames are sent every 30s. Optional fleet_id filter narro…

No input schema was published for this tool.

get_healthFleet health + liveness. Pass verbosity="summary" for a smaller routine probe (entrypoints map omitted); default "full" is the full BuildIdentityReport. Use `get_build_identity` for diagnostics.

Fleet health + liveness. Pass verbosity="summary" for a smaller routine probe (entrypoints map omitted); default "full" is the full BuildIdentityReport. Use `get_build_identity` for diagnostics.

No input schema was published for this tool.

get_build_identityFull BuildIdentityReport for the running install: package name/version, source_commit, entrypoint_count, per-entrypoint SHA-256 map, entrypoints_match_runtime bit. Diagnostic access to the install's identity.

Full BuildIdentityReport for the running install: package name/version, source_commit, entrypoint_count, per-entrypoint SHA-256 map, entrypoints_match_runtime bit. Diagnostic access to the install's identity.

No input schema was published for this tool.

save_fleet_templateSave a named fleet template (set of agent specs) for reuse. Names: lowercase letters, numbers, dashes, underscores.

Save a named fleet template (set of agent specs) for reuse. Names: lowercase letters, numbers, dashes, underscores.

No input schema was published for this tool.

list_fleet_templatesList all saved fleet templates, sorted by name.

List all saved fleet templates, sorted by name.

No input schema was published for this tool.

spawn_from_templateprivilegedReturn a fleet spec from a saved template, ready to pass to spawn_fleet.

Return a fleet spec from a saved template, ready to pass to spawn_fleet.

No input schema was published for this tool.

ask_peerOpen a bounded, two-agent Discussion: sends the root question and (optionally) explicitly reserves one peer attempt, then waits until the conversation deadline for a settled answer. Message arrival never starts an agent by itself — wake_peer:true is the explicit, budgeted authority to run the peer…

Open a bounded, two-agent Discussion: sends the root question and (optionally) explicitly reserves one peer attempt, then waits until the conversation deadline for a settled answer. Message arrival never starts an agent by itself — wake_peer:true is the explicit, budgeted authority to run the peer…

No input schema was published for this tool.

wake_agentNo description published

This tool published no description. Forge does not invent one.

reply_discussionNo description published

This tool published no description. Forge does not invent one.

get_discussionNo description published

This tool published no description. Forge does not invent one.

record_work_receiptNo description published

This tool published no description. Forge does not invent one.

get_work_receiptNo description published

This tool published no description. Forge does not invent one.

34 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Auditable multi-agent coordination for OpenCode — parallel agent fleets with P2P messaging, witnessed receipts, and quorum ratification. Who saw this, who approved it, prove it.

Keywords
mcpopencodeagentorchestrationswarmfleetp2ppeer-to-peermodel-context-protocolauditreceiptsquorummulti-agent
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-10-02 — observed resolution, not a publisher declaration.

60 packages resolved · 2 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

76 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+64 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.