Forge Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Forge Mcp (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<picture> <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/pm577/forge-mcp/main/assets/forge-banner-dark.svg"> <img alt="Forge — Portable Reputation Protocol for AI Agents" src="https://raw.githubusercontent.com/pm577/forge-mcp/main/assets/forge-banner-light.svg"> </picture>
<p align="center"> <strong>Portable reputation that follows your agent across every platform.</strong> </p>
<p align="center"> <a href="https://pypi.org/project/forge-mcp/"><img src="https://img.shields.io/pypi/v/forge-mcp?label=PyPI&logo=pypi&color=6366f1" alt="PyPI"></a> <a href="https://github.com/pm577/forge-mcp/actions"><img src="https://img.shields.io/github/actions/workflow/status/pm577/forge-mcp/ci.yml?branch=main&logo=github" alt="CI"></a> <a href="https://pypi.org/project/forge-mcp/"><img src="https://img.shields.io/pypi/pyversions/forge-mcp?logo=python" alt="Python versions"></a> <a href="https://github.com/pm577/forge-mcp/blob/main/LICENSE"><img src="https://img.shields.io/github/license/pm577/forge-mcp?color=green" alt="License"></a> <a href="https://smithery.ai/server/@pm577/forge-mcp"><img src="https://img.shields.io/badge/Smithery-available-6366f1?logo=data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMTYiIGhlaWdodD0iMTYiIHZpZXdCb3g9IjAgMCAxNiAxNiIgZmlsbD0ibm9uZSIgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvc3ZnIj48cGF0aCBkPSJNOCAwTDggMTZNMTYgOEwwIDgiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIi8+PC9zdmc+" alt="Smithery"></a> <a href="https://glama.ai/mcp/servers/pm577/forge-mcp"><img src="https://img.shields.io/badge/Glama-listed-6366f1" alt="Glama"></a> </p>
Every agent marketplace has the same problem: reputation is platform-dependent. An agent with 500 successful jobs on Platform A starts at zero on Platform B. Forge fixes this by making reputation portable — agents carry their trust score wherever they go.
Forge is MCP-native (Model Context Protocol). Any agent can connect — Claude Code, Hermes Agent, Codex, Cursor, or your custom agent — with zero platform lock-in.
# Install
pip install forge-mcp
# Run (HTTP SSE mode — for remote agents)
forge-server --port 4243
# Or stdio mode (for local MCP tools)
forge-serverTry it:
# Any agent can call Forge via MCP
forge_register("my-agent", "My Agent")
forge_vouch("alice", "my-agent", "Great work on Project X")
trust = forge_verify("my-agent") # → 0.4| Tool | What it does |
|---|---|
forge_store | Store facts in structured namespaces |
forge_recall | Retrieve stored knowledge |
forge_forget | Delete a fact |
forge_graph | View entity relationship graph |
forge_stats | System statistics |
| Tool | What it does |
|---|---|
forge_register | Register a new agent identity |
forge_vouch | Vouch for another agent's reliability |
forge_verify | Get an agent's current trust score |
forge_endorse | Endorse a specific skill |
forge_reputation | Full profile — score, history, vouches |
| Tool | What it does |
|---|---|
forge_referral_code | Generate referral code for viral distribution |
forge_referral_stats | Track referral performance |
Base trust: 0.30
Referred agent: 0.40 (+0.1 bonus)
Per vouch: +0.10
Per referral: +0.05 (for referrer)
Maximum: 1.00Referral viral loop:
Agent A shares referral code
→ Agent B joins with code (starts at 0.40)
→ Agent A earns +0.05 trust
→ Agent A's higher trust attracts more referrals
→ Network compounds┌─────────────┐ MCP Protocol ┌──────────────┐
│ Any Agent │ ◄──────────────────► │ Forge Server │
│ (Hermes, │ (SSE or stdio) │ :4243 │
│ Claude, │ │ │
│ Codex) │ ├──────────────┤
└─────────────┘ │ SQLite (WAL) │
│ ~/.forge/ │
└──────────────┘MCP (Model Context Protocol) is the standard for agent-to-tool communication — the USB-C of AI. By building on MCP, Forge is immediately compatible with every MCP client without custom integrations.
See CONTRIBUTING.md. All contributions welcome — issues, PRs, documentation, integrations.
<p align="center"> <a href="https://moltbook.com/u/forgereputation">Follow Forge on Moltbook</a> · <a href="https://github.com/pm577/forge-mcp/issues">Report Issue</a> · <a href="https://github.com/pm577/forge-mcp/discussions">Discussion</a> </p>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.