Swetrix analytics: projects and project details. Needs API key.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
list_projectsAll Swetrix projects with ids and domains.All Swetrix projects with ids and domains.
No input schema was published for this tool.
get_projectOne Swetrix project with settings and stats summary.One Swetrix project with settings and stats summary.
No input schema was published for this tool.
campaign_parametersAudit the utm_ parameters on a list of URLs, computed locally: which campaigns, sources and mediums they name and how often, how many URLs are untagged or only partly tagged, whether term and content are missing, and the case or stray-parameter mistakes that split one channel across two rows in a r…Audit the utm_ parameters on a list of URLs, computed locally: which campaigns, sources and mediums they name and how often, how many URLs are untagged or only partly tagged, whether term and content are missing, and the case or stray-parameter mistakes that split one channel across two rows in a r…
No input schema was published for this tool.
sdk_release_feedThe published swetrix tracker package on npm: latest version, how many versions exist, days since the last publish, the median, shortest and longest gap between releases, its dependency count, last week's download count, the most recent versions by date, and the project's newest GitHub release tags…The published swetrix tracker package on npm: latest version, how many versions exist, days since the last publish, the median, shortest and longest gap between releases, its dependency count, last week's download count, the most recent versions by date, and the project's newest GitHub release tags…
No input schema was published for this tool.
ecosystem_auditThe project's shape from GitHub: licence, age, days since the last push, stars, forks, watchers and open issues, the language mix as a share of bytes, contributors ranked by commits with the top contributor's share, and an explicit judgement on the bus factor and on whether a single language domina…The project's shape from GitHub: licence, age, days since the last push, stars, forks, watchers and open issues, the language mix as a share of bytes, contributors ranked by commits with the top contributor's share, and an explicit judgement on the bus factor and on whether a single language domina…
No input schema was published for this tool.
5 of 5 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Swetrix analytics: projects and project details. Needs API key.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
The crawl stopped at the depth-4 limit. Anything below that level was never resolved.
The crawl stopped at the 60-package limit. The rest of the tree was never resolved.
36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)
54 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.
+42 more not listed. The counts by reason above cover all of them.
Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.