# meshfleet

Auditable multi-agent coordination for OpenCode — parallel agent fleets with P2P messaging, witnessed receipts, and quorum ratification. Who saw this, who approved it, prove it.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.22.0
- **Author:** Unknown
- **License:** MIT
- **npm:** meshfleet
- **Source:** https://github.com/johnmwhitman/agent-mesh
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-02T08:26:52.144Z
- **Version scanned:** 0.22.0
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `spawn_fleet` — Spawn parallel agents. Returns fleet_id. An agent banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks f
- `fleet_status` — Check fleet and agent status.
- `list_fleets` — List all fleets with summaries (agent count, status, completion).
- `set_fleet_timeout` — Set a per-fleet timeout override (in milliseconds). Agents exceeding this are auto-failed.
- `collect_results` — Get fleet outputs and loss tally. Only result_contract ok can bank complete; refused, blocked, artifact_missing, invalid, or absent banks failed. Declared outco
- `send_message` — Send a P2P message from one agent to another within the same fleet. Set to_agent_id to "*" to broadcast to every other agent in the fleet (each recipient acks i
- `send_messages` — Send a batch of P2P messages in ONE ledger transaction — use instead of repeated send_message calls for bulk fan-out (much faster: the recipient inbox is update
- `get_inbox` — Get messages in an agent's inbox, optionally since a timestamp.
- `ack_message` — Acknowledge a message, removing it from the agent's inbox. Writes an 'ack' receipt (per-recipient — a broadcast is acked independently by each recipient).
- `receipt` — Write a non-consuming receipt on a message — the audit primitive. Use actions like 'seen', 'r-ack' (approve), 'retracted'. Unlike ack_message, the message stays
- `get_receipts` — Get the full receipt trail for a message: who acked, who annotated, when. Answers 'who saw this and who acted on it'.
- `verify_ledger`
- `verify_ledger_v2` — Versioned verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Normal parent-server startup recovery or migrati
- `verify_ledger_v3` — Opt-in verifier output read from a dedicated read-only file snapshot; the handler performs no ledger writes. Returns a detached meshfleet.verify/v3 report with 
- `open_ratification` — Open a quorum vote ('council') over the fleet. Broadcasts a proposal; peers vote with cast_vote. Ratifies when approvals reach the quorum and every required sig
- `cast_vote` — Cast a vote on an open ratification. approve=true records approval, approve=false rejection. Re-casting CHANGES your effective vote (each change appends a new s
- `tally_ratification` — Read the live vote tally and current status (open / ratified / rejected / expired) of a ratification, and persist the status if it has reached a terminal state.
- `sweep_ratifications` — Evaluate every open ratification now and persist any that reached a terminal state (deadline expiry, silent-approval, unreachable quorum). The server also sweep
- `register_capability` — Register an agent's capabilities (role, skills, model) for routing.
- `route_work` — Route a work description to the best-matching registered agents by keyword + role/skill overlap scoring (with synonym expansion), weighted by routing feedback (
- `compile_route_candidates` — Offline projection of caller-supplied route-candidate snapshots. Does not persist, rank, execute, authorize, wake, or contact providers.
- `recommend_route` — Advisory-only ranking over caller-supplied sanitized task traits and candidate snapshots. Does not persist, execute, authorize, wake agents, or contact provider
- `plan_speculative_backlog` — Pure, caller-approved speculative backlog projection. Does not persist, execute, authorize, wake agents, contact providers, poll, allocate capacity, schedule, s
- `record_routing_outcome` — Record whether a routed task succeeded or failed. Future route_work calls for the same agent weight their score by accumulated outcomes (Wilson-style). NOTE: ou
- `list_agents` — List all available premade agents from .opencode/agents/ directories.
- `attach_agent` — Attach an agent to a running fleet. It banks complete only when result_contract is ok; refused, blocked, artifact_missing, invalid, or absent banks failed.
- `ping` — Minimal liveness check. Returns { status: 'ok', timestamp }.
- `subscribe_inbox` — Subscribe to an agent's inbox via Server-Sent Events (SSE). Returns a stream URL that the agent opens to receive real-time push of incoming P2P messages. Falls 
- `subscribe_events` — Subscribe to the unified fleet-wide event stream via Server-Sent Events (SSE). Returns a stream URL that emits every ledger event (messages, receipts, ratificat
- `get_health` — Fleet health + liveness. Pass verbosity="summary" for a smaller routine probe (entrypoints map omitted); default "full" is the full BuildIdentityReport. Use `ge
- `get_build_identity` — Full BuildIdentityReport for the running install: package name/version, source_commit, entrypoint_count, per-entrypoint SHA-256 map, entrypoints_match_runtime b
- `save_fleet_template` — Save a named fleet template (set of agent specs) for reuse. Names: lowercase letters, numbers, dashes, underscores.
- `list_fleet_templates` — List all saved fleet templates, sorted by name.
- `spawn_from_template` — Return a fleet spec from a saved template, ready to pass to spawn_fleet.
- `ask_peer` — Open a bounded, two-agent Discussion: sends the root question and (optionally) explicitly reserves one peer attempt, then waits until the conversation deadline 
- `wake_agent`
- `reply_discussion`
- `get_discussion`
- `record_work_receipt`
- `get_work_receipt`

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"meshfleet\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"meshfleet\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs commands; runs on your machine.
- Floor 45, ceiling 73 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/meshfleet
- Install plan: https://forgeregistry.com/api/v1/packages/meshfleet/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/meshfleet
- HTML page: https://forgeregistry.com/registry/meshfleet
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
