# pitroom

Hands bounded coding work to cheaper worker agents: verified answers, exact diffs, cost receipts.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.23.0
- **Author:** io.github.ATASTECH
- **License:** MIT
- **npm:** pitroom
- **Source:** https://github.com/ATASTECH/pitroom
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-10T07:01:35.886Z
- **Version scanned:** 0.23.0
- **CVEs:** none found by OSV at scan time

## Tools

21 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `run-report` — The report of a run: answer, receipt, verified references.
- `run-patch` — The exact diff an isolated or in-place run made.
- `research` — Find, map or explain code through a read-only worker, and verify what comes back.
- `question` — What to find out about the project.
- `implement` — A worker makes a change in an isolated copy; you review the exact diff and apply it only when it is right.
- `task` — The change to make, with the context a worker needs.
- `review` — A read-only reviewer from another model judges a commit range or the latest change.
- `range` — A commit range such as main..HEAD. Default: the latest run's change.
- `crew` — Independent tasks run in parallel as one group of workers.
- `tasks` — The tasks, one per line.
- `pitroom_run`
- `pitroom_wait` — Wait for runs that came back "still running" and return their reports.
- `pitroom_show` — A run's report (live progress while it runs); patch: the exact diff; full: the untruncated answer.
- `pitroom_info` — Reports, changing nothing. topic: runs (latest runs; running, group), history (search earlier answers before asking again; text, state, model, since, limit), st
- `pitroom_review` — A read-only reviewer (another worker by default) judges a run's change or a commit range ("main..HEAD"): findings with severities and a SPEC / QUALITY verdict.
- `pitroom_audit` — Another worker re-checks a read run's answer: AGREE, PARTIAL or DISAGREE, with the disputed claims.
- `pitroom_apply` — Land an isolated run's patch (or a group's, in order) on the working tree; checked first. A patch deleting files needs allowDelete: pass it only after checking 
- `pitroom_discard` — Drop an isolated run's private copy (the patch is kept).
- `pitroom_revert` — Undo a mode "write" run's changes (refused if the files changed since).
- `pitroom_stop` — Stop a running or queued run, or a group; cooldowns: try rate-limited models again now.
- `pitroom`

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"pitroom\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"pitroom\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: mutates data; runs on your machine.
- Floor 28, ceiling 52 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/pitroom
- Install plan: https://forgeregistry.com/api/v1/packages/pitroom/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/pitroom
- HTML page: https://forgeregistry.com/registry/pitroom
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
