Back to Browse

Forge MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server + tools for the Forge E-- generative-music authoring loop (compile / run / commit).

About

MCP server + tools for the Forge E-- generative-music authoring loop (compile / run / commit).

Security Report

4.2
Use Caution4.2High Risk

forge-mcp is a well-structured MCP server with appropriate authentication via Bearer token forwarding to a backend service (forge-transpile). The codebase demonstrates solid path-traversal defense and input validation. However, there are several moderate-severity concerns: subprocess calls in vault_fs.py lack comprehensive error handling and input sanitization (git commands), the Bearer token fallback mechanism creates a dev-only auth bypass risk if accidentally left in production, and token storage in environment variables without explicit warnings about secure practices. Permissions align reasonably with the server's purpose (file I/O for vaults, network access for forge-transpile API), but the subprocess execution introduces additional attack surface. Supply chain analysis found 6 known vulnerabilities in dependencies (0 critical, 5 high severity). Package verification found 1 issue.

4 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

subprocess

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Base URL of the forge-transpile service. Provides /catalog, /compile, /run, /resolve-slot endpoints backing the read/author tools.Optional

Environment variable: FORGE_TRANSPILE_URL

Local vault directory used by forge_read_notes_in_vault + forge_commit_recipe. Must exist and be writable.Optional

Environment variable: FORGE_VAULT_PATH

Bearer token forwarded to forge-transpile. Rotate by updating FORGE_TRANSPILE_SECRET on the upstream service and re-setting this. Dev fallback only when clients don't set Authorization on each request.Required

Environment variable: FORGE_MCP_BEARER

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-frmoded-forge-mcp": {
      "env": {
        "FORGE_MCP_BEARER": "your-forge-mcp-bearer-here",
        "FORGE_VAULT_PATH": "your-forge-vault-path-here",
        "FORGE_TRANSPILE_URL": "your-forge-transpile-url-here"
      },
      "args": [
        "forge-recipe-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

forge-mcp

Author, compile, run, and commit generative-music E-- Recipes directly from any MCP-capable agent (Claude Desktop, Cursor, …). forge-mcp exposes the Forge E-- library note catalog + vault as an MCP server and closes the authoring loop end-to-end: the agent picks a chip from the catalog, drafts a Recipe, verifies it parses, runs it in a sandbox, previews the artifact, and commits the finished Recipe to a vault note. All 6 tools ship today.

[library note catalog] → [compile] → [run] → [commit] → [vault note with recipe_version bump]

Install into Claude Code

Fastest path — Claude Code spawns forge-mcp as a stdio subprocess. Full walkthrough at docs/claude-code-install.md.

# 1. Install from PyPI (https://pypi.org/project/forge-recipe-mcp/)
pip install forge-recipe-mcp

# 2. Fetch your Bearer once and export
export FORGE_MCP_BEARER=$(jq -r '.transpileServiceToken' \
  ~/forge-vaults/bluh/.obsidian/plugins/forge-client-obsidian/data.json)

# 3. Register with Claude Code
claude mcp add forge-mcp \
  -e FORGE_MCP_BEARER=$FORGE_MCP_BEARER \
  -e FORGE_TRANSPILE_URL=https://forge.thecodingarena.com \
  -e FORGE_VAULT_PATH=$HOME/forge-vaults/bluh \
  -e FORGE_MCP_TRANSPORT=stdio \
  -- forge-mcp

# 4. Start Claude Code and ask "list the notes in my forge music library."

Install (other clients)

Full walkthrough (Claude Desktop config, forge-transpile Bearer acquisition, verification smoke, troubleshooting): docs/install.md.

Quick paths:

# From source (pip + editable install for development)
pip install -e ".[dev]"
python -m forge_mcp.server

# Docker
docker build -t forge-mcp:latest .
docker run --rm -p 8765:8765 \
    -e FORGE_TRANSPILE_URL=https://forge.thecodingarena.com \
    -e FORGE_VAULT_PATH=/path/to/your/vault \
    forge-mcp:latest

Environment:

  • FORGE_TRANSPILE_URL — base URL of the forge-transpile service. Default: http://localhost:8000.
  • FORGE_VAULT_PATH — local vault directory for forge_read_notes_in_vault + forge_commit_recipe. Default: ~/forge-vaults/bluh.
  • FORGE_MCP_HOST — host to bind. Default: 0.0.0.0.
  • FORGE_MCP_PORT — port to bind. Default: 8765.
  • FORGE_MCP_BEARERdev fallback only. Per-request Bearer extraction is the primary path (CW-MCP-1-B); this env var only fires when the incoming request has no Authorization header. Do NOT set in production.

Claude Desktop config

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "forge-mcp": {
      "url": "http://localhost:8765/mcp",
      "headers": {
        "Authorization": "Bearer <your-forge-transpile-token>"
      }
    }
  }
}

Get your Bearer:

jq -r '.transpileServiceToken' \
    ~/forge-vaults/bluh/.obsidian/plugins/forge-client-obsidian/data.json

Tools

Read (no side effects):

  • forge_read_note_catalog({domain?}) — list Forge library notes; every entry carries the E-- signature the agent needs to Call it.
  • forge_read_notes_in_vault({filter?}) — list vault notes with a has_recipe + recipe_version summary. Backed by a local filesystem walk (CW-MCP-2-E).

Author (deterministic — no LLM, no vault write):

  • forge_compile_recipe({source}) — Recipe → Python. Returns compiled source + unresolved slot count, OR a structured parse error with line/column (per drain CW-recipe-parser-line-info).
  • forge_run_recipe({source, domains?}) — compile + execute in a resource-limited server sandbox. Returns a short preview + a run_id; artifacts (MusicXML / MIDI / PNGs) accessible via the forge-artifact:// resource.
  • forge_get_run_result({run_id}) — fetch full stdout/stderr + artifact manifest of a previous run. 7-day TTL, per-Bearer isolation.

Commit:

  • forge_commit_recipe({source, note_id, expected_version?}) — persist Recipe to a vault note (facet-scoped — Description + Python + frontmatter survive byte-for-byte). Bumps recipe_version in the note's frontmatter. Optimistic-concurrency via expected_version; version-conflict returns isError:true with expected + current numbers.

Resources

  • forge-note:///{domain}/{name} — library note content.
  • forge-artifact:///{run_id}/{artifact_name} — on-demand binary fetch for run artifacts. Text mimes return via text; binaries via base64 blob.
  • forge-recipe:///{note_id}/v{n} — Recipe body at a specific recipe_version (git-tracked vaults only; returns "history unavailable" text otherwise).

Auth

forge-mcp does NOT validate tokens itself — forge-transpile is the source of truth (guarded by FORGE_TRANSPILE_SECRET). Each request's Authorization: Bearer <token> header is forwarded verbatim; a 401 or 403 from forge-transpile surfaces as isError: true with an actionable message the agent can read (drain CW-MCP-1-B).

Rotation is zero-downtime on the forge-mcp side: change FORGE_TRANSPILE_SECRET on forge-transpile, update your MCP client's header, done. Old tokens fail on the next request with a clean rejection message.

Related repos

  • forge — the E-- parser + transpiler + core music library. forge-mcp vendors a snapshot of forge/recipe/ per the CW-MCP-2-A architecture; drift is caught by scripts/check-recipe-drift.sh in the forge-transpile repo.
  • forge-transpile — the FastAPI service exposing /compile / /run / /catalog etc. that forge-mcp's tools proxy for the transpile + sandboxed-run paths. Vault reads + commits are LOCAL and don't hit forge-transpile.
  • forge-client-obsidian — the Obsidian plugin end of the same authoring loop. forge-mcp writes to the SAME vault the plugin reads/renders; both share the note-file format.

Reviews

No reviews yet

Be the first to review this server!