explain_finding
11 registry entries were observed exposing a tool named explain_finding — none of them flagged as a privileged capability.
Spelled explain_finding, explain-finding in the wild — all one tool for the purposes of this page.
Every row is point-in-time scan output, dated below. Forge has an observed tool surface for 8,470 of 26,658 scannable entries (32%) — an entry that has not been scanned cannot appear here, so absence from this list is not evidence that an entry does not expose this tool.
- @quantakrypto/mcpverifiedMCP serverobserved · static extractionScan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.
- calllint-mcpverifiedMCP serverobserved · static extractionStatic preflight safety gate for MCP servers — scan configs before you run them. Never executes.
- io.github.KevinRabun/judgesverifiedMCP serverobserved · static extraction45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
- MCP serverobserved · static extractionPre-launch safety check for AI-built apps (Lovable, Bolt, Replit, Cursor, v0). Scans your GitHub Actions + CI hygiene locally. Source code a
- MCP serverobserved · static extractionMCP server for CertScore public website risk-signal workflows.
- MCP serverobserved · static extractionCodebase health MCP: dead code, cycles, coupling, architectural drift.
- MCP serverobserved · static extraction120-module QA gate. Give Claude eyes (screenshots), ears (Sentry errors), and hands (verify fixes).
- MCP serverobserved · static extractionMCP server for static security analysis of Android source code
- MCP serverobserved · static extractionAutonomous UX and a11y audit, fix, and verify loop. 38 tools, framework-aware patches.
- MCP serverobserved · static extractionMulti-layer security scanner for MCP servers and agent skills (injection, exfiltration)
- MCP serverobserved · static extractionScans AI-generated code for invisible Unicode, Trojan Source, and supply-chain threats.