# spryloom

Publish apps from Claude Code, Codex or Cursor to your team, behind sign-in, with a database.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.1.17
- **Author:** com.spryloom
- **License:** UNLICENSED
- **npm:** spryloom
- **Source:** https://spryloom.com
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 1 day

## Security scan

- **Status:** warnings
- **Scanned:** 2026-10-09T00:19:37.391Z
- **Version scanned:** 0.1.15
- **CVEs:** none found by OSV at scan time

## Tools

13 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `sign_in` — Sign in to Spryloom, once per machine. Call when another Spryloom tool says it is not signed in. Use the email address the person gives you when you ask; never 
- `finish_sign_in` — Wait for the person to approve the sign-in from their email, then sign in. Call after sign_in, once you have told the person the code. If it says not approved y
- `publish` — Publish this app to Spryloom so the user's coworkers can use it behind company sign-in. Ask who should be able to use it before calling. A folder with only stat
- `status` — Show whether an app is running, which version it is on, and how many people use it. Use when the user asks how an app is doing, whether anyone is using it, or w
- `export` — Export an app as portable JSON containing its metadata, manifest, audience, versions, and safe audit history. Application database rows require the app’s own ex
- `logs` — Read recent output from a running app. Use when an app is behaving oddly, a user reports something not working, or you need to see why a request failed.
- `page_data` — Read the saved data of a Spryloom page that saves data: its lists, or the records in one list, as the signed-in person sees them in the page. Use when the user 
- `save_page_record` — Add a record to a list of a Spryloom page that saves data, or change or delete a record the signed-in person saved themselves. Only when the user asks for that 
- `rollback` — Return an app to an earlier version. Data is left untouched. Use when a change made things worse and the user wants the previous version back.
- `restore` — Restore an archived app. Its database and data are retained; restoring starts the last published version.
- `invite` — Invite people to use an app by email. Use after publishing, when the user names the coworkers who should have it, or asks you to share it with someone.
- `uninvite` — Remove a coworker from an app. Use when the owner asks to revoke someone's access; existing sessions end at the documented session boundary.
- `custom_domain` — Give an app a custom domain, or verify, list, or remove one. Adding returns the DNS records the user must add; verify once they are in place. Only the app owner

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"spryloom\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"spryloom\"\n      ],\n      \"env\": {\n        \"SPRYLOOM_TOKEN\": \"<YOUR_SPRYLOOM_TOKEN>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `SPRYLOOM_TOKEN` — Spryloom Token (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 1 credential (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Moderate blast radius — holds an api key; runs on your machine.
- Floor 23, ceiling 23 (tier: moderate)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/spryloom
- Install plan: https://forgeregistry.com/api/v1/packages/spryloom/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/spryloom
- HTML page: https://forgeregistry.com/registry/spryloom
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
