audit_lockfile
2 registry entries were observed exposing a tool named audit_lockfile — none of them flagged as a privileged capability.
Every row is point-in-time scan output, dated below. Forge has an observed tool surface for 8,491 of 26,663 scannable entries (32%) — an entry that has not been scanned cannot appear here, so absence from this list is not evidence that an entry does not expose this tool.
- MCP serverobserved · static extractionCatch AI-hallucinated (slopsquatted) npm imports in generated code BEFORE npm install. Scans a code block, flags imports of packages that do
- MCP serverobserved · static extractionAudit a package-lock.json for supply-chain attacks BEFORE npm install. Cross-checks every resolved dependency against the live npm registry: