forge-mcp
A production-grade, LLM-agnostic local development engine over MCP, providing structured code intelligence and shared language server processes for AI coding agents.
README
forge-mcp
A production-grade, LLM-agnostic local development engine over the Model Context Protocol. One resident daemon. Any MCP client. Shared warm language servers, structural code intelligence, fingerprint caching, event-driven invalidation, and a self-healing supervisor — built so an AI coding agent gets compiler-grade answers without burning context, crashing tools, or leaking memory.
WIP personal tool. Successor to my
nav-mcp; runs in parallel during migration. Design hardened across five iterations of research + devil's-advocate review against 2025–2026 MCP spec revisions, SDK issue history, and field-reported failure classes.
What it is
A single long-lived daemon on 127.0.0.1 speaking MCP Streamable HTTP, plus a tiny stdio proxy any MCP host launches as a "local server." The proxy auto-starts the daemon, authenticates with a per-boot bearer token, and bridges stdio ↔ HTTP. Result: OpenCode, Claude Desktop, Claude Code, Cursor — all sharing one engine: one set of warm LSP processes per (project root, language), one cache, one security policy.
OpenCode ──stdio──┐
Claude Desktop ───┤── stdio-proxy ──HTTP+token──▶ forge-mcp daemon (127.0.0.1)
Cursor ──http─────┘ (auto-starts daemon, ├─ dispatch core (15 modes)
embedded fallback) ├─ warm LSP pool, (root,lang)-keyed
├─ supervisor (restart → circuit-break)
├─ fingerprint cache (LRU+TTL, 64MB)
├─ native fs-watcher invalidation
└─ 6 flat tools
Why
AI coding agents fail in three repeatable ways: blind text I/O (re-reading whole files, grepping names, no type-level truth), fragile tooling (a crashed language server becomes an error-retry loop), and duplicated heavyweight state (every host spawning its own 300–700 MB tsserver). forge-mcp answers each: real LSP (definitions, references, diagnostics, semantic rename) with an AST/structural layer on top; a never-throw contract where every failure degrades down a fidelity ladder (LSP → tree-sitter → ctags → regex) inside a structured envelope while a supervisor restarts crashed servers; and one shared warm server per project+language across all clients.
Tool surface
| Tool | Modes / behavior | Safety |
|---|---|---|
read |
tree · outline · symbols · read · peek · search · glob · def · refs · hover · diagnostics · wsymbol | read-only |
edit |
edit · write · rename · action — fingerprint stale-guard, per-path mutex, all-or-nothing workspace edits | destructive, guarded |
ast_grep |
structural search/rewrite — in-process @ast-grep/napi for TS/JS, CLI for other langs, ripgrep floor; apply=true gates mutation and writes only through the guarded writer |
dry-run default |
git_view |
read-only git inspection; mutating subcommands refused with hints | read-only |
test_run |
check · fix · last-failed; cancellation-aware; failures-only output | fix = mutating |
dep_audit |
lockfile-driven CVE scan; offline-safe; declares network calls | read-only, networked |
Every response is a NavEnvelope — ok, engine (which fidelity rung answered), notes, pagination anchors, fingerprints — with cache/recovery fields emitted only when something noteworthy happened (token-lean by design).
Core guarantees
- Never-throw — the transport never sees an exception; agents always get a usable, attributed answer or a clean refusal.
- Self-healing — restart budget (3/5 min, exponential backoff) → circuit-breaker → fallback chain → half-open recovery. Daemon itself is crash-only: all state reconstructible; a daemon crash costs each client at most one failed call.
- Memory-bounded by construction — byte-accounted LRU cache (64 MB, 2 MB/entry, strict TTLs, errors never cached), LSP pool LRU + idle reap, refcounted didOpen/didClose, session sweep triad, child-process registry with kill-sweeps, capped child heaps. Validated by a <15 % RSS soak gate.
- Fresh by events, correct by fingerprints — a native filesystem watcher evicts caches within ~100 ms of external edits, but correctness never depends on it: mtime-keyed fingerprints remain the authority, and the watcher degrades to stat-based invalidation if it dies.
- Concurrency-correct — shared LSP processes with session-scoped views; diagnostics fan out to all waiters; cross-client writes serialized by per-path mutex and rejected on stale fingerprints.
- Windows-correct — cmd-shim command-injection gate, EPERM/EBUSY rename backoff (Defender locks), pipe-backpressure draining, detached daemon spawn done right.
- Secure by default —
127.0.0.1bind, per-boot bearer token (stored only in%LOCALAPPDATA%, never in the repo), Origin validation/DNS-rebinding 403, canonical+symlink-resolved path jail,.env*guard, per-client tool profiles, exact-pinned deps.
Layout
Code lives in this repo. Runtime state (daemon.json + token, boot.lock, logs/) lives in %LOCALAPPDATA%\forge-mcp\ — by construction, secrets can't be committed. forge.example.json documents config; the live forge.json is gitignored.
Status
Pre-implementation: design docs + reference_files/ (nav-mcp port source) only. Build proceeds through gated milestones M0–M7 defined in implementation_plan.md — each with verify gates, fallback behavior, and rollback. Agents working in this repo: read AGENTS.md first.
| Doc | Purpose |
|---|---|
implementation_plan.md |
Source of truth: M0–M7 with run/verify/on_fail |
AGENTS.md |
Constraints, port gotchas, envelope contract, flags |
RUNBOOK.md |
Ops & recovery (lands at M7) |
test/ |
Permanent bun test regression suite (lands progressively) |
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。