LiveMerged local public and synthetic contributor toolingPlannedRemote, private, and production operation

The Open Forge

Useful tools without hidden authority.

Forge retrieves, validates, and generates bounded evidence. People and accepted domain processes decide what that evidence means.

Forge is one local MCP application for contributors and agents working with allowlisted public repository records and explicitly synthetic data. Its ten server-owned tools are versioned, bounded, source-linked, non-mutating, provider-independent, and non-authoritative.

Forge is not the product database, a private Chronicle service, a House of Keys service, a general shell, a repository-writing agent, a provider gateway, a remote MCP service, or a production sandbox.

Exactly ten tools

Every tool has a visible job and denial.

Runtime registry revision 4 exposes no hidden general-purpose tool. Each identity is server-owned and checked against its accepted scope, source, limits, provenance, and non-authority requirements.

Lore, content, quests, architecture, and decisions

Source-linked search and deterministic validation over allowlisted public repository material.

forge.search.lore

Search frozen and governed lore with provenance.

Cannot accept canon or invent story authority.

forge.validate.content

Validate public content records against accepted schemas.

A passing result does not approve publication or canon.

forge.inspect.quest-schema

Inspect the public quest contract and its required fields.

Cannot create eligibility, completion, progression, or reward authority.

forge.validate.quest

Run deterministic validation over a public or synthetic quest draft.

Cannot complete a quest, grant rewards, or publish gameplay.

forge.search.architecture

Search public architecture records with conservative authority labels.

Proposed or historical material cannot be promoted to accepted truth.

forge.search.decision

Search accepted, proposed, superseded, and unresolved decisions.

Cannot close, accept, supersede, or amend a decision.

Standards, mapping drafts, and connector fixtures

Provider-neutral public standards evidence and explicitly synthetic connector examples.

forge.search.public-standards

Search allowlisted public standards references with provenance.

Cannot prove completeness, certification, semantic equivalence, endorsement, or provider preference.

forge.validate.mapping-draft

Validate a revisioned public or synthetic mapping draft.

Cannot approve a mapping, certify interoperability, select a provider, or prove production readiness.

forge.search.synthetic-connector-fixtures

Search explicitly synthetic, credential-free connector fixtures.

Cannot access production endpoints, private negotiations, proprietary mappings, or personal data.

Deterministic synthetic generation

Bounded generation for quest and mapping-draft examples using fixed synthetic time and immediate validation.

forge.generate.synthetic-data

Generate deterministic public synthetic cases from a hashed seed and validate every artifact.

Does not prove de-identification, representativeness, clinical realism, statistical validity, model-training fitness, or publication fitness.

LiveAccepted local implementation boundary

The runtime is deliberately narrow.

  • One local application at apps/mcp-forge using newline-delimited UTF-8 stdio and MCP protocol revision 2025-11-25.
  • Exactly ten server-owned tool identities through runtime registry revision 4 and execution contract revision 1.
  • Nine server-owned source roots with exact allowlists, traversal rejection, symlink isolation, bounded reads, repository-relative locators, and SHA-256 provenance.
  • One active call per tool identity with bounded input, scans, results, serialized output, timeout, cancellation, and materialization.
  • No shell, subprocess, network client, socket, VM, worker thread, dynamic import, code evaluation, repository write, provider call, credential path, or private-data path.

Receipts and errors

Evidence without leaking protected state.

A receipt records a bounded invocation. It cannot turn tool output into canon, architecture approval, permission, Chronicle truth, mapping approval, clinical authority, production readiness, or institutional legitimacy.

  • Every scoped success and stable scoped failure includes forge.invocation-receipt.v1.
  • Stable public-safe failures use forge.error.v1.
  • Receipts and errors omit raw input, host paths, environment values, internal traces, credentials, protected source material, and wall-clock timestamps.
  • Receipts prove only the bounded local invocation and evidence they describe; they do not prove production isolation, safety, approval, or authority.
PlannedOpen production and specialist gates

Local success does not imply production safety.

  • No production deployment, remote MCP endpoint, authentication, tenancy, private Chronicle tool, House of Keys tool, provider access, connector runtime, or repository mutation.
  • No production process isolation, CPU or heap enforcement, distributed quota, rate limiting, monitoring, incident response, backup, recovery, or deletion verification.
  • No representative security, reliability, performance, cost, accessibility, usability, contributor-benefit, clinical, statistical, or publication evidence.
  • Nineteen specialist holdpoints and eighteen unresolved-work records remain open; Sprint 7 acceptance closed none of them.

MCP is optional

Contributors do not need Forge to participate.

The repository, issue tracker, documentation, tests, and ordinary pull request process remain the primary governed contribution path. Forge assists with bounded public evidence; it does not control participation or replace human review.