
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
agentforge-mcp
Advanced tools
MCP server for AgentForge — turn rough requests into tool-tuned, quality-checked prompts for AI coding agents.
Stop re-explaining what you want to your AI coding agent.
Hand it one rough sentence — get back a structured, tool-tuned prompt
it can execute in one pass.

agentforge-mcp is the Model Context Protocol
server for AgentForge. One tool, one job: turn
a vague request into a sharp one.
You know the loop: you ask your coding agent for something, it misreads the half you didn't spell out, you correct it, it breaks something else, you re-explain. The fix isn't a smarter agent — it's a sharper prompt.
AgentForge does the prompt engineering for you. Give it
"add a dark mode toggle that persists" and it:
Harness engineering is having a moment — but prompt engineering matters more in the coding-agent era, not less. Tested across 1,000+ real coding cases, projects with AgentForge in the loop reached a deployable state 147% faster.
No install — it runs through npx.
1. Get an API key. Sign in at agentforge.sciscale.org, open API keys, and create one. The key is shown once — copy it.
2. Add it to your agent.
Claude Code:
claude mcp add agentforge --env AGENTFORGE_API_KEY=af_your_key -- npx -y agentforge-mcp
Cursor / Windsurf / Claude Desktop — add to your MCP config
(~/.cursor/mcp.json, ~/.codeium/windsurf/mcp_config.json, etc.):
{
"mcpServers": {
"agentforge": {
"command": "npx",
"args": ["-y", "agentforge-mcp"],
"env": { "AGENTFORGE_API_KEY": "af_your_key" }
}
}
}
3. Use it. Ask your agent naturally — "refine this with AgentForge, then build it: add a dark mode toggle that persists."
agentforge_refine_prompt| Argument | Default | |
|---|---|---|
request | — | Your task in plain language (1–4000 chars). Rough is fine. |
target_tool | claude-code | claude-code, codex, cursor, aider, continue, windsurf, kimi, generic |
style | plan-first | plan-first, direct-edit, explore-first |
Returns the refined prompt, plus its Quality Engine score and your remaining daily usage.
| Free | Pro | |
|---|---|---|
| Refinements | 3 / day | Unlimited |
| Quality Engine | scored across 12 dimensions | scored + auto-refined until it passes ≥ 90 |
Don't want to wire up an MCP server at all? The same engine — same Quality Engine, same per-account Pro — runs right in your browser at agentforge.sciscale.org. No install, no key, no config.
Paste a request, pick your target tool, copy the prompt — generation history and advanced modes included:

agentforge-mcp is a thin client — no engine logic ships in this package. Your
request goes to the AgentForge API, the hosted engine does the extraction,
formatting, and quality-checking, and the prompt comes back. The engine keeps
improving without you ever updating this package.
| Variable | Default | |
|---|---|---|
AGENTFORGE_API_KEY | — | Required. Your API key. |
AGENTFORGE_API_URL | https://agentforge.sciscale.org/api/v1/refine | Override the endpoint (rarely needed). |
npm install
npm run build # tsc -> dist/
node dist/index.js # runs on stdio
MIT — see LICENSE.
agentforge-mcp is part of AgentForge — a SciScale studio product.
FAQs
MCP server for AgentForge — turn rough requests into tool-tuned, quality-checked prompts for AI coding agents.
The npm package agentforge-mcp receives a total of 19 weekly downloads. As such, agentforge-mcp popularity was classified as not popular.
We found that agentforge-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.