The official TypeScript SDK for Model Context Protocol servers and clients
This is the branch which contains v2 of the SDK (currently in development, pre-alpha). We anticipate a stable v2 release in Q3 2026 along with the updated MCP spec. Until then, v1.x remains the recommended version for production use. v1.x will continue to receive bug fixes and security updates for at least 6 months after v2 ships to give people time to upgrade. For v1 documentation, see the V1…
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
get-alertsNo description publishedThis tool published no description. Forge does not invent one.
get-forecastNo description publishedThis tool published no description. Forge does not invent one.
greetNo description publishedThis tool published no description. Forge does not invent one.
get-protocol-infoNo description publishedThis tool published no description. Forge does not invent one.
register_userNo description publishedThis tool published no description. Forge does not invent one.
create_eventNo description publishedThis tool published no description. Forge does not invent one.
update_shipping_addressNo description publishedThis tool published no description. Forge does not invent one.
payment-confirmNo description publishedThis tool published no description. Forge does not invent one.
third-party-authNo description publishedThis tool published no description. Forge does not invent one.
multi-greetNo description publishedThis tool published no description. Forge does not invent one.
get_weatherNo description publishedThis tool published no description. Forge does not invent one.
whoamiNo description publishedThis tool published no description. Forge does not invent one.
calculate-bmiNo description publishedThis tool published no description. Forge does not invent one.
list-filesNo description publishedThis tool published no description. Forge does not invent one.
fetch-dataNo description publishedThis tool published no description. Forge does not invent one.
delete-fileprivilegedNo description publishedThis tool published no description. Forge does not invent one.
process-filesNo description publishedThis tool published no description. Forge does not invent one.
summarizeNo description publishedThis tool published no description. Forge does not invent one.
collect-feedbackNo description publishedThis tool published no description. Forge does not invent one.
list-workspace-filesNo description publishedThis tool published no description. Forge does not invent one.
start-notification-streamNo description publishedThis tool published no description. Forge does not invent one.
collect-user-infoNo description publishedThis tool published no description. Forge does not invent one.
long-operationNo description publishedThis tool published no description. Forge does not invent one.
structured-toolNo description publishedThis tool published no description. Forge does not invent one.
v1-to-v2No description publishedThis tool published no description. Forge does not invent one.
pingNo description publishedThis tool published no description. Forge does not invent one.
test-with-failing-transformNo description publishedThis tool published no description. Forge does not invent one.
test-rollbackNo description publishedThis tool published no description. Forge does not invent one.
testNo description publishedThis tool published no description. Forge does not invent one.
echoNo description publishedThis tool published no description. Forge does not invent one.
main.rsNo description publishedThis tool published no description. Forge does not invent one.
lib.rsNo description publishedThis tool published no description. Forge does not invent one.
profileNo description publishedThis tool published no description. Forge does not invent one.
test-request-infoNo description publishedThis tool published no description. Forge does not invent one.
test-query-paramsNo description publishedThis tool published no description. Forge does not invent one.
close-stream-toolNo description publishedThis tool published no description. Forge does not invent one.
test-callback-toolNo description publishedThis tool published no description. Forge does not invent one.
test-old-version-toolNo description publishedThis tool published no description. Forge does not invent one.
test-no-callback-toolNo description publishedThis tool published no description. Forge does not invent one.
test-standalone-callback-toolNo description publishedThis tool published no description. Forge does not invent one.
0 of 40 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
This is the branch which contains v2 of the SDK (currently in development, pre-alpha). We anticipate a stable v2 release in Q3 2026 along with the updated MCP spec. Until then, v1.x remains the recommended version for production use. v1.x will continue to receive bug fixes and security updates for at least 6 months after v2 ships to give people time to upgrade. For v1 documentation, see the V1 API docs. For v2 API docs, see . We're temporarily restricting PRs to contributors only to manage…
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.