Skip to main content
Glama
640,719 tools. Updated 2026-10-05 09:44

"Git LFS" matching MCP tools:

  • Fast code search across any public git repo. Returns file paths, line numbers, and code snippets with context. Supports regex, boolean queries, fuzzy matching, and structural filters (declarations, usages, strings, comments). Dependency/build directories excluded by default. Searching for leaked secrets? Call code_analyze instead and read security_summary — it runs a real secret and credential scanner over the whole repository, where searching for key prefixes like "sk-", "ghp_" or "AIza" only matches the spellings you happened to think of.
    ConnectorNo auth
  • Start a schema check of a proposed schema against a variant, the same check that `rover graph check` starts. Use this for a monograph or for a whole supergraph schema; use RunSubgraphCheck for one subgraph. The check runs in the background, so this returns a workflow ID and a Studio URL, not a result. Pass the returned workflowID to GetCheckResults to read the outcome. Provide the graph ID, the variant name, and the proposed schema as SDL. Optionally provide the git branch and commit to label the run in Studio.
    ConnectorNo auth
  • Use this when the user, or the agent building the app, wants to check an app they control for exposed files and open databases before launch. A deeper security scan than check_app_security, for an app the caller controls (for example one the agent itself is building). It looks for sensitive things left publicly reachable: an environment (.env) file, an exposed .git folder, a directory listing, or a published source map. It also finds the Supabase or Firebase backend the app uses and checks what an anonymous visitor can read: tables, files, and whether anyone can sign up. It reads only, never writes, and never stores, logs or returns any key; it reports the exposed PATH, table or bucket name and a row count so the owner can see it, never a file's contents or a secret value. Because it probes an app directly, it runs only after ownership is proven: call it once to receive an inert verification token, add that token to the app (a meta tag on the home page, or a /7it-verify.txt file), then call again and the scan runs.
    ConnectorNo auth
  • Create a NEW artifact in Agent Grid; never edits an existing one. Two independent axes, easy to confuse: **type** (below) is where the files come from, and **artifactType** is what the artifact IS. artifactType defaults to app — a live web application that renders and runs at the returned URL as soon as it is ready, which is what every type below produces unless you say otherwise. Pass artifactType markdown for a readable document, or asset for a stored file: neither is a running app, so do not promise a live URL for them. Generation types (p2c/l2c/f2c) run ASYNCHRONOUSLY: this returns IMMEDIATELY with { status: 'generating', sessionId, artifactUrl, previewUrl, playgroundUrl } while the app is still being built. The preview link shows a live loading screen that swaps in the finished app. Most of the time, you need a single call to artifact-status with { sessionId, wait: true }, BEFORE you reply to the user because it blocks until the app is ready or failed, so you report a finished app rather than a promise (if it returns still 'generating', call it again). This artifact-create tool is NOT meant to be called multiple times for the same generation request. While a matching job is active, the same stable request identity may reuse that job for the team instead of creating another. The own-code types (empty/import) return immediately. **Do NOT use for:** editing an existing artifact (artifact-explore + artifact-edit, or the git flow via artifact-get_git_token); rename/visibility (artifact-update_metadata); deploying live (artifact-publish). **type:** Anima GENERATES (async — poll artifact-status): - p2c: text prompt (requires prompt; optional guidelines) - l2c: website (requires url) - f2c: Figma frames (requires fileKey + nodesId + X-Figma-Token header) YOU supply (ready immediately): - empty: empty git repo you push to (requires framework) - import: your code is the first commit; EXACTLY ONE of files (inline text, up to roughly 100 KB) or zipUploadId (binaries or larger) **framework:** only html and react exist. Required for empty; optional for import (detected from package.json) and generation types (default html). **Returns:** generation types (p2c/l2c/f2c) → { success, status: 'generating', sessionId, artifactUrl, playgroundUrl, previewUrl }; poll artifact-status for completion. Own-code types (empty/import) → sessionId, revision, artifactUrl, name, gitRemoteUrl, access, expiresAt, nextSteps (plus fileCount, skippedFiles for import), and a read-write git token in the same response — so do NOT call artifact-get_git_token after creating. playgroundUrl comes only when artifactType is app; previewUrl renders those plus markdown artifacts, while asset artifacts expose only artifactUrl. A markdown inline-files import also returns documentPreview plus documentPreviewTruncated, so the preview card can render the bounded document text without a follow-up read. `revision` is the first commit: pass it straight to artifact-edit as baseRevision if you edit without git. These are ready immediately (no 'generating' status): previewUrl renders the committed files right away for import, and the seed README for empty.
    ConnectorOAuth
  • Inspect the files of an EXISTING artifact: list them, search their text, read them, or review the commit history. Works with no shell, no git and no network access, so prefer it whenever you cannot run git. Pass the sessionId (the last path segment of a .../chat/<sessionId> URL). A canvasDraft field, when authorized, reports an uncommitted Canvas draft. Use action draft to inspect its projection overlay explicitly; ordinary reads remain committed files. Draft access requires write permission. Typical flow to change something: action "search" to find the file, action "read" for the files you will edit, then artifact-edit. Every response includes "revision", the artifact's current commit — pass it back as artifact-edit's baseRevision. Use action "read" with a "revision" to see how a file looked at an earlier commit (this is how you undo something). Assets — images, fonts, media — are readable too: action "read" answers with size, mime and oid under "asset": true whenever a file's bytes are not text, instead of content. That check is on the bytes, so it is the authority: an SVG reads as text, and a file with an unfamiliar extension may still come back as an asset. When a search comes back empty, check "notSearched": "assets" counts binary files a text query can never match, and "excluded" counts files under node_modules, dist or build — re-run with includeExcluded true to search those. A "tree" listing also maps any path artifact-edit cannot change under "unwritable". For generation or build progress use artifact-status instead; this shows the commit log, not build state.
    ConnectorOAuth
  • Registers the project if it is new, attaches whatever source you give it, and deploys it using the application's Deployment workflow. Direct applications go to Production; Staged applications go to Development. Returns the live URL, or a deployment id to poll if the build is still running. **You do not decide whether this project needs git.** Send what you have and SpringRoll works it out: • a pushed git remote → pass `repositoryUrl` (and `ref` if not the default branch) • no remote, or uncommitted work → pass `archive`, a base64 tar+gzip of the source: tar --exclude=node_modules --exclude=.next --exclude=.git --exclude='.env*' \ -czf - . | base64 -w0 • both → SpringRoll builds from git, and falls back to your files if the ref cannot be resolved (an unpushed branch, typically) • neither, on an app that already exists → redeploys its current source Upload SOURCE, not build output: SpringRoll runs the build. node_modules, .next, dist, build, out, coverage and .log files are dropped automatically and reported. Every .env file and .git/ is REFUSED outright, naming the offending path: configuration belongs in SpringRoll, not in the bundle. Upload limits are about 3 MB compressed on the wire (a platform request-body cap, not a preference), 20 MB expanded, 2000 files, 512 KB per file; a project past them should pass `repositoryUrl` instead, which SpringRoll clones directly with no size limit. Sending the same files twice is free, because bundles are addressed by content. Direct to Production skips workflow approvals but keeps production safety checks. Staged applications continue to use explicit promotion and approvals.
    ConnectorNo auth

Matching MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI agents to perform full Git operations including branching, committing, pushing, stashing, rebasing, and more, with safety features and support for advanced workflows like Git Flow and LFS.
    32 npm
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables AI agents to intelligently organize Git changes into clean, focused commits with autopilot mode or surgical line-by-line staging precision. Supports partial staging of untracked files and handles large diffs with smart truncation.
    5
    1
    MIT

Matching MCP Connectors

  • [~] PRIORITY TRIGGER: Use this tool when user mentions 'PR', 'Pull Request', 'list PRs', 'show PRs', 'active PRs', 'mes PR', 'liste des PR', 'pull requests ouverts', 'what PRs are open', 'PRs by [author]', 'PRs targeting [branch]'. NEVER call search_d365_code for PR listing requests. List Pull Requests in an Azure DevOps Git repository. If `repositoryId` is unknown, omit it and all repositories will be listed first. Filters: status (Active/Completed/Abandoned/All), author display name, target branch. Returns: PR ID, title, author, source->target branch, review status, linked work items, creation date. Use `ado_analyze_pr_impact` with a PR ID to get full D365 code impact analysis. Requires DEVOPS_ORG_URL + DEVOPS_PAT (Code: Read scope).
    ConnectorNo auth
  • Raw file/git access at the indexed commit, for cloud agents with no clone; with a clone prefer your own Read/Grep/git. Ops: - read: content of filePath, whole file or slice startLine..endLine. ifHash (a prior read's hash) returns {unchanged:true}, no content. compact:true strips blank/comment-only lines. - list: files+subdirs at path. grep: ripgrep pattern (glob/pathPrefix). tree: layout from path. stat: size/lines/language/binary for filePath. blame: authorship for filePath. diff: fromSha..toSha. Keys: {op:"read",filePath:"src/a.ts"}, {op:"grep",pattern:"foo"}, {op:"list",path:"src"}. filePath is the file, path the directory. Gated by the Source Access add-on; else source_access_required.
    ConnectorNo auth
  • Start an isolated Firecracker microVM sandbox (ready in about 1 s; Linux with Python 3.12 + pip, Node.js 22 + npm, bash, git and curl; internet egress allowed so pip/npm install and git clone work; no inbound ports, SMTP blocked). `mode`: "ephemeral" (default — billed per second, minimum 60 s, auto-deleted after `idle_timeout` s of inactivity, default 300, max lifetime `ttl` up to 24 h) or "persistent" (billed per started hour, a month costs at most 730 h minus 25%; survives host maintenance; max `ttl` 30 days). `tariff` (default small): micro 0.25 vCPU/512 MB RAM/3 GB disk $0.0165/h · small 0.5 vCPU/1 GB RAM/5 GB disk $0.033/h · standard 1 vCPU/2 GB RAM/10 GB disk $0.066/h · plus 2 vCPU/4 GB RAM/15 GB disk $0.132/h · pro 4 vCPU/8 GB RAM/20 GB disk $0.264/h · max 8 vCPU/16 GB RAM/40 GB disk $0.528/h (pick plus or bigger for heavy pip installs such as torch, builds or data work). Headless browsers (Chromium via Playwright/Puppeteer) need `standard` or bigger — micro/small do not have enough RAM. If the host is busy the call fails with 503 capacity (Retry-After) — retry or choose a smaller tariff. Charged from the same prepaid balance as VPS (no subscription). Empty balance → 402 insufficient_balance (top up with topup_balance). If the balance runs out later, persistent sandboxes are paused (memory+disk snapshot, not billed) and resume automatically after a top-up; paused snapshots are deleted after 14 days. The response has `state: "running"` and `ready: true` once you can exec (usually immediately); if it says `starting`, call get_sandbox after 1-2 s. Always kill_sandbox when done. Requires: token + balance. Typical errors: 402 insufficient_balance → topup_balance; 503 capacity → retry or smaller tariff.
    ConnectorNo auth
  • Get detailed code quality findings from a remote public git repository. Returns rule IDs, line numbers, severity, category, descriptions, and source snippets. Supports filtering by file path, severity (error, warning, info), category (security, deprecated, safety, correctness, maintainability, accessibility, modernization, performance, concurrency), and kind (security, quality) — kind=security is every security-category finding in one call, kind=quality is everything else. code_analyze.top_findings shows only the quality half; use kind=security here to see the security-category findings it leaves out. THIS IS NOT THE SECRET SCANNER. kind=security means insecure code — weak hashes, unsafe deserialization, injection-shaped patterns — and it will not find a leaked API key or private key. Leaked credentials are code_analyze.security_summary, which is a different scanner over different rules; the two sets do not overlap, so an audit wants both. Use after code_analyze to drill into specific findings. Shares the same analysis cache — no duplicate work if analyze already ran.
    ConnectorNo auth
  • Run a ClamAV malware scan on a site's container. Scans the web root (or specified path) for malware, viruses, and trojans. ClamAV is installed automatically if not present. Excludes node_modules, vendor, .git, and cache directories. May take up to 5 minutes for large sites. Requires: API key with write scope. Args: slug: Site identifier path: Directory to scan (default: /var/www/html) Returns: {"infected_files": [{"path": "/var/www/html/shell.php", "threat": "Php.Malware.Agent"}], "scanned_count": 1234, "infected_count": 1, "scan_time_s": 45.2}
    ConnectorNo auth
  • Get the MFG Calcs Provenance Manifest: the verifiable record for every branded index and ledger on the site. For each one it returns a SHA-256 of the committed artifact and of every committed public-data input it was built from, plus the generator that reproduces it and the page that renders it. Use this to VERIFY a number before quoting it: re-hash the committed artifact (integrity), re-run the named generator on the committed inputs (reproducibility), and read the git history (timestamp). Takes no arguments. The hashes prove the artifacts are intact and reproducible, not the correctness of the underlying government data. Cite the returned url.
    ConnectorNo auth
  • Publish an artifact — deploys its committed files (git HEAD; uncommitted edits are not included) to a live public URL. Works for app AND markdown artifacts; an asset artifact cannot be published (tell the user so and share its artifactUrl instead). Publishing makes the content PUBLIC to the world. It is NOT needed for sharing — the artifact is already visible at its artifactUrl to everyone who can reach it, and liveUrl is NOT an editor. Call this only when the user explicitly asked to publish/deploy; otherwise share that URL and offer publishing as a follow-up question. Requires a sessionId from a previously created artifact (via artifact-create). **What goes live:** - app: the running web application. - markdown: one document. liveUrl renders the initial file (README.md if present, else the first .md lexicographically); the raw source is at <liveUrl without the query string>/index.md (Content-Type: text/markdown) — give the user that path when they want the markdown. Other .md files are served raw at their own paths, each with a rendered .html sibling. ```mermaid fences render as diagrams; the .md keeps the fence. accTitle/accDescr label a diagram. **Modes:** - "webapp" (default): Deploys to a live URL; use it for both app and markdown artifacts. Returns { success, liveUrl, subdomain }. - "designSystem": NOT available over MCP — always fails with an enterprise contact link, whatever you pass. Do not offer it as a capability. **Returns:** { success, liveUrl, subdomain }
    Connector
    Destructive
    OAuth
  • Change the files of an EXISTING artifact and commit them, without git or a shell. Never creates a new artifact — the sessionId keeps pointing at the same one, and its playground URL does not change. If a Canvas draft exists, this refuses unless acknowledgeCanvasDraftRevision matches the draft you reviewed and the user explicitly chose to edit committed files. It does not edit, promote or discard the draft. All the changes you pass land as ONE commit: either every operation applies or none does. Read the files first with artifact-explore and pass the revision it returned as baseRevision; if someone else changed the artifact meanwhile the edit is rejected with REVISION_CONFLICT, which lists what changed so you can re-read those files and retry. Prefer op "str_replace" for edits to existing files (send the exact snippet), "write" to create a file or replace one wholesale, "delete", and "move" to rename. move does NOT rewrite imports — neither in the files that import the moved module, nor the relative imports INSIDE the moved file, which now resolve from its new folder, so read it first and add the str_replace operations that fix them. The live preview updates from the new commit immediately. To rename an artifact or change its visibility use artifact-update_metadata; for very large repositories or full git workflows (branches, history rewriting) use artifact-get_git_token.
    Connector
    Destructive
    OAuth
  • Step 1 of adding a LARGE asset (an image, font or media file) to an EXISTING artifact — anything over 256 KB, which is the most artifact-edit takes inline. Smaller files need no staging: send them to artifact-edit directly with encoding "base64". **Flow:** 1. Call this with the sessionId and the filename: it returns assetUploadId, uploadUrl and uploadFields. 2. Upload the file with an HTTP POST of multipart/form-data to uploadUrl. Send EVERY key/value of uploadFields as a form field FIRST, then the file itself LAST, in a field named "file" — S3 ignores anything sent after the file part, so the order matters. Do not add a size or Content-Length field. Success is HTTP 204 with an empty body. With curl, uploadFields {"key": "abc", "policy": "xyz"} becomes: curl -X POST <uploadUrl> -F key=abc -F policy=xyz -F file=@/path/to/your-file.png 3. Call artifact-edit with a "write" change carrying assetUploadId instead of content, and the path the file should live at. Put the code that references it in the SAME edit, so both land in one commit. **Rules:** one file per id, single use, 30 minutes to redeem it, 32 MB max — S3 rejects a larger body at step 2. Files over 10 MB are stored through Git LFS automatically: the commit carries a small pointer and .gitattributes gains the matching filter line, with no extra steps on your side. uploadFields carry the signature that authorizes the upload; treat them as a secret. If your host cannot make an HTTP request, use artifact-edit with encoding "base64" for a file that fits inline, or artifact-get_git_token to push the file with git. **Returns:** success, assetUploadId, uploadUrl, uploadFields, expiresAt, maxBytes, nextSteps.
    ConnectorOAuth
  • Use to verify a signed published probe attestation after an evidence audit. Returns L1 signature, key, time, and chain-link checks; optional L2 replay of daily heads to a Git-tag anchor; and L3 scope, which requires verify_evidence for live transport. A valid signature proves attestation integrity and scope, not upstream semantic truth or currentness. For a deep audit use search_datasets → get_evidence → verify_evidence → verify_attestation. Use it for signed-attestation integrity; do not use it for published receipt verification, a live transport comparison, or an aggregate verdict—use verify_dataset, verify_evidence, or trust_verdict instead. L2 is not run unless replay_chain is set, and a failed level reports an unsatisfied check rather than upstream semantic truth; DataPulse is read-only, requires no API key, and the edge limits clients to roughly one request per second with a small burst, so pace or retry.
    ConnectorNo auth
  • Create a Keelen account (or start agent login) — emails a 6-digit code. UNAUTHENTICATED — the only tool besides verify_email that works before a bearer key is configured. `email` is where the code is sent. Flow: signup(email) -> the user reads the 6-digit code from their inbox -> verify_email(email, code) returns a reveal-once API key, stored as this server's `Authorization: Bearer <api_key>` header in the MCP client config; reconnecting the client and calling get_onboarding_status() then continues setup. The code expires in 15 minutes; a repeat signup resends it. Response is uniform whether or not the email already has an account (enumeration-safe), so signup doubles as agent LOGIN. Rate-limited per IP and per email. The `email` must be explicitly provided and confirmed by the user in chat before this call. It is not inferred from a client profile, the logged-in account, git config, or any other ambient source; a candidate address the caller already holds is echoed back for an explicit yes first. Because this call doubles as LOGIN, a guessed address signs the user in to whatever workspace owns it, and the rest of setup then mints an API key on, and creates a project in, an account they did not choose.
    Connector
    Destructive
    No auth
  • Returns the still-unanswered SpecPilot onboarding questions of the next incomplete step, gated by the answers supplied so far - questions that do not apply to this kind of project are omitted, and options are filtered, badged or flagged the same way the SpecPilot web chat would. Stateless: send every answer collected so far on each call. Procedure: (1) Decide whether the repository already has real source code and set `isNewBuild` accordingly - it changes which onboarding analysis is generated at the end. (2) Infer what the repo already answers rather than asking: `platforms` from the dependency manifests and layout, `languageOverride`, `ideAgent` (you are the IDE - claudecode, cursor, copilot, codex, windsurf), `handle` from git config or the origin remote, `projectName` from the package manifest or folder name, and `projectDescription` from the README only if it plainly says what the project is. (3) Call this tool with what you have; answer what the repo makes obvious and ask the developer the rest, a whole step per message. Send an empty value for an optional question the developer declines, or it will be asked again; send `todoSentinel` verbatim when they do not know yet. For `projectDescription`, sending one of the returned chip labels exactly is what infers `projectCategory` and gates every later question - free prose infers nothing. Confirm any pre-seeded value rather than accepting it silently. (4) Loop until `done` is true, then call specpilot_generate_specs and follow its `nextSteps` for where each file goes.
    ConnectorNo auth
  • Register the site you are working in, and get its project id back. Pass the domain you derived from this codebase (git remote, deployed URL, site config). Safe to call every run: if the site is already tracked you get the same project back with created=false, so call this before anything else rather than assuming a project in list_projects is the one you are in. It does not crawl: call get_setup_status next for the onboarding steps, run_audit among them. Returns projectId, the normalized domain, brandName and created. Private, loopback and internal hosts are refused as invalid_request; a plan's site limit answers quota_exceeded with metric sites. Without a plan the first site gets the one free audit, and the answer says what that includes.
    ConnectorNo auth
  • Start a schema check of one proposed subgraph schema against a variant, the same check that `rover subgraph check` starts. The check runs in the background, so this returns a workflow ID and a Studio URL, not a result. Pass the returned workflowID to GetCheckResults to read the outcome. Provide the graph ID, the variant name, the subgraph name, and the proposed subgraph schema as SDL. Optionally provide the git branch and commit to label the run in Studio.
    ConnectorNo auth
  • Requests a build for the given component ids, backed by a private GitHub repo BotKelp owns and manages itself under its own org — never your account. Returns the repo's location, a short-lived single-repo-scoped clone credential, and a persistent projectid for later use with get_scaffold/get_projects/set_projects. Repeat requests for the same component combination reuse the same repo at no extra GitHub-side cost. A failed build (red ci.yml) is never charged. Payment: pay with linked BotKelp account credits (MCP OAuth 2.1 / Bearer bk_live_ at transport — never a tool argument), or omit account linkage and pay per-call in USDC via x402 (attach payment via the MCP call's _meta["x402/payment"] — no signup). maintain (default true, credit flow only) keeps this project's repeat access renewable — see ADR 0025 and set_projects. Pass site_profile: true (only your account's single profile) or a profile name to attach that named profile's documents in the same result; if incomplete, call get_siteprofile with next.arguments — there is no second unsolicited reply. delivery: "clone" (default) returns a git clone command; "inline" returns the files in the reply instead, for callers that can't run git — costs more tokens, use only when a shell isn't available. Extra pages land IN the clone (unique personal bk-* repo; shared tpl stays generic): site_profile true or a name bakes dashboard legal pages (privacy/terms/cookies) as Next.js routes; template_files true (all saved files) or [{name} | {source, dest}] pulls dashboard files or files from the connected GitHub repo.
    ConnectorNo auth