MCPLow riskUnclaimed
demipass
Credential custody for agents: use secrets blind (ssh/http/smtp/git/db), never in context.
dustforge.comdustforge.com/demipass
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-09-29/server.schema.json",
"name": "com.dustforge/demipass",
"description": "Credential custody for agents: use secrets blind (ssh/http/smtp/git/db), never in context.",
"repository": {
"url": "https://github.com/bildow/demipass",
"source": "github"
},
"version": "2.5.0",
"websiteUrl": "https://dustforge.com",
"packages": [
{
"registryType": "npm",
"identifier": "demipass",
"version": "2.5.0",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Dustforge JWT bearer token. Self-onboard at https://dustforge.com/.well-known/silicon or mint via the 2FA email flow.",
"isRequired": true,
"isSecret": true,
"name": "DEMIPASS_TOKEN"
},
{
"description": "API base URL (default https://api.dustforge.com)",
"name": "DEMIPASS_URL"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
nodeInstalls—
npm:demipass@2.5.0Runs install scripts—None
NetworkNoneNone
Needs credentials
DEMIPASS_TOKENDEMIPASS_TOKENOutside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #12.5.0latestOct 7, 2026
demipassOpen in Codeg