ForgeBridge
Provides Git integration for inspecting repository state, reading Git data, and supporting reviewed Git workflows such as push with permission gating.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ForgeBridgeShow me the current Git status and recent changes in my project."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ForgeBridge
Status: public alpha / beta testing. ForgeBridge is available for early real-world testing, but it is not a stable production release yet. Commands, MCP schemas, configuration, and behavior may change between alpha/beta versions. The project will continue to receive updates, fixes, UX improvements, and new capabilities.
ForgeBridge is a local, permissioned MCP agent for development work on a computer the user owns and
explicitly authorizes. It is designed for filesystem editing, interactive terminals, durable jobs,
Git workflows, and semantic browser testing from compatible AI clients. For model-driven
development, ForgeBridge exposes semantic project inspection, Git reads, and reviewed validation
operations so routine work does not require arbitrary shell commands. Start with project_inspect
to learn the project stack, Git state, host OS, and shell in one bounded call. See
the model-first workflow.
This repository is under active development toward v0.1 and should be treated as test/beta software. Current status and verified limitations are tracked in the implementation plan. Issues and feedback are welcome; future releases will continue improving stability, onboarding, remote/multi-device UX, and tool coverage.
Quick start
The public alpha package name is forgebridge; the installed command stays forgebridge. Once the
first npm release is live:
npm install --global forgebridge@next
forgebridge init --root /path/to/your/project
forgebridge doctor
forgebridge browser install
forgebridge serve --transport stdioMCP clients that launch stdio servers can run ForgeBridge without a global install:
npx -y forgebridge@next serve --transport stdioForgeBridge is also prepared for discovery through the official MCP Registry as
io.github.t1ktakdev/forgebridge. Browser automation needs a reviewed Chromium/Chrome/Edge
installation; Windows UI Automation remains opt-in. See
installation and packaging for platform-specific setup.
Related MCP server: Coding Tools MCP
Design
ForgeBridge keeps privileged enforcement on the workstation:
every action is checked by a deny-first permission engine;
paths are restricted to canonical allowed roots;
write approvals are bound to the exact action and expire;
terminal and job output is bounded and paginated;
browser sessions are isolated by default;
the default BACKGROUND execution profile forces headless browsers and defers focus-changing desktop actions;
attempted and completed actions are written to a redacted, hash-chained audit log.
For ChatGPT web, the preferred v0.1 transport is OpenAI Secure MCP Tunnel, which creates an outbound HTTPS path without publishing a port on the workstation. Local MCP clients can use stdio directly.
See:
Development
Requirements: Node.js 22 or newer, pnpm 11, Git, and Windows 10/11 for native validation.
pnpm install
pnpm check
pnpm build
node dist/cli.js init --root C:\src\my-project
node dist/cli.js serve --transport stdioTrusted local development
For a repository you explicitly trust, ForgeBridge can remove repeat approval prompts for reviewed repository-defined validation while keeping the same canonical root boundary and hard-deny rules:
forgebridge project trust C:\src\my-projectThis creates a per-project FULL profile with autonomy: trusted-local. It is intentionally local
configuration: repository files cannot enable it. Reviewed project_check plans can then run
without a fresh approval, while destructive commands, Git push, elevation, persistence, secret
access, consequential browser/Windows submissions, and anything outside the configured root remain
gated or denied. Revert with forgebridge project set PATH --mode balanced --autonomy standard or
remove the project profile with forgebridge project remove PATH.
Local installation
ForgeBridge is packaged as an npm-compatible tarball because node-pty is a native dependency and
Playwright browser binaries are platform-specific. Nothing is published by the release scripts.
pnpm run package:artifact
pnpm run package:validate
.\scripts\install-windows.ps1 -PackagePath .\release\forgebridge-0.1.0-alpha.3.tgz -InstallChromiumThe artifact includes a CycloneDX SBOM and a SHA-256 checksum. Validation installs the actual tarball in a disposable prefix and exercises the installed CLI, MCP stdio, filesystem, terminal, and headless browser paths. See installation and upgrade instructions.
Optional Windows autostart is available after installation through
configure-autostart-windows.ps1. It creates a current-user scheduled
task only after explicit local configuration and stores the least-privilege tunnel runtime key with
Windows DPAPI; the default installer still creates no startup entry.
Optional Windows UI Automation is disabled by default. Set windowsUiAutomation.enabled to true
in the local config to expose bounded semantic Windows element trees and control-pattern actions. It
requires an unlocked interactive desktop and never bypasses cross-user or elevation boundaries.
Focus-changing actions are durably deferred in BACKGROUND and GAMING profiles and require local
approval plus an explicit switch to NORMAL.
The agent never installs auto-start or a background service implicitly. Do not expose its local HTTP endpoint to a network interface.
Before any public alpha, complete the remaining external gates listed in the release-readiness audit, including a separate clean Windows VM run, artifact signing, and an independent security review. Live Secure MCP Tunnel/ChatGPT validation has already passed for the recorded Windows configuration.
Security
ForgeBridge is powerful by design. An approved arbitrary shell has the authority of the OS account running the agent. For containment, use a dedicated low-privilege account, Windows Sandbox/VM, or another OS-enforced isolation boundary. Read SECURITY.md before using the agent on sensitive systems.
License
Apache License 2.0. See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Develop, manage, and debug Railway projects, services, and deployments from within agents.
Hosted runtime for persistent agent teams, durable workflows, memory, schedules, and goals.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Build, deploy, and sell AI agents for local-service businesses - from your IDE.
Related MCP Servers
- FlicenseNot gradedqualityAmaintenanceEnables AI agents to develop within a local project workspace by reading and modifying files, running commands and tests, checking Git state, and persisting progress as history sessions that can be restored in later conversations.-
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to turn local projects into persistent workspaces, providing file editing, command execution, Git integration, and cross-session history management.-
- AlicenseNot gradedqualityBmaintenanceEnables AI clients to safely read, search, understand, and edit local project code and files, with Git inspection, code indexing, and controlled command execution within permissioned workspaces.5 npm6MIT
- AlicenseNot gradedqualityAmaintenanceEnables AI clients to securely inspect and edit approved code, use semantic code intelligence, run builds/tests, supervise bounded processes, inspect Git, and execute owner-approved SSH commands on engineering workstations.1Apache 2.0