Terms of Service
Reading note. These Terms govern use of the ForgeRift plugins (
local-terminal-mcp,vps-control-mcp) and the forgerift.io website. The underlying source code is separately licensed under the MIT License in each repository. Schedule A (the End User License Agreement) covers how you may use the plugin software. Schedule B sets product-specific terms.
1. Acceptance
By downloading, installing, accessing, or using any ForgeRift plugin, any software distributed by ForgeRift, or the forgerift.io website (together, the "Services"), you agree to these Terms of Service ("Terms"), Schedule A (EULA), Schedule B (Product Terms), and the ForgeRift Privacy Policy, each as amended from time to time. If you do not agree, do not use the Services.
If you are using the Services on behalf of an organization, you represent that you have authority to bind that organization to these Terms, and "you" means both you and that organization.
2. Definitions
- "Plugin" means a Claude Code or Claude Desktop plugin distributed by ForgeRift, including
local-terminal-mcpandvps-control-mcp, any successor versions, and any related documentation. - "Marketplace" means the Anthropic Software Directory or any other third-party plugin distribution surface from which the Plugins may be obtained.
- "Your Systems" means the computers, virtual machines, servers, and networks on which you install or point the Plugins, and any accounts, credentials, or data stored on them.
- "Consumer" means a natural person acting outside of a trade, business, craft, or profession, where that status gives rise to mandatory rights under applicable law (e.g., EU Directive 2011/83/EU).
- "Documentation" means the README, CHANGELOG, COMMANDS, SECURITY, and TROUBLESHOOTING files published in each Plugin's repository and the content on forgerift.io.
- "Subscription" means a paid recurring billing arrangement (Individual or Bundle) governed by Section 6.
- "Gated Operation" means an operation that the Plugin will not execute until the user has reviewed a plain-language description of the specific action, its target, and its potential consequences, and provided explicit per-invocation confirmation. A prior confirmation for the same operation type does not carry forward to subsequent invocations.
3. Eligibility
Age requirement. You must be at least 18 years old to use the Services. If you are between 13 and 17 years old, you may use the Services only with the consent of a parent or legal guardian who agrees to these Terms on your behalf. The Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you are aware that a child under 13 has created an account, please notify us at [email protected] and we will delete the account.
Jurisdiction. You must not be a national or resident of a country subject to comprehensive U.S. economic sanctions (currently Cuba, Iran, North Korea, Syria, or the Crimea, Donetsk People's Republic, or Luhansk People's Republic regions of Ukraine), and you must not be listed on any U.S. Government restricted-party list (including the OFAC SDN List, the BIS Entity List, or the State Department Debarment List). See also Section 18 (Export Controls).
4. The Services
4.1 Description. ForgeRift distributes Plugins that extend Claude (a product of Anthropic PBC) with structured tools for operating local workstations and remote Linux servers. ForgeRift LLC is an independent third-party developer and is not affiliated with, endorsed by, or sponsored by Anthropic PBC. The Plugins run on Your Systems or on infrastructure you control. ForgeRift does not host your Plugin instances, does not hold your credentials, and does not initiate network connections to Your Systems. The Plugin makes one outbound call from Your Systems to ForgeRift's license-validation endpoint at startup to verify your active subscription, and (only if you supply an optional Anthropic API key) per-invocation outbound calls to Anthropic's API for AI-assisted safety classification — see Schedule B.1 and the Privacy Policy §2.1 for detail. Always install Plugins directly from official ForgeRift repositories at github.com/ForgeRift or through the official Anthropic Marketplace listing. Verify release integrity using checksums published in each GitHub release.
4.2 Service Level. The Services are provided on a best-effort basis. ForgeRift does not currently offer an uptime guarantee. We target high availability but do not commit to any specific service level, uptime percentage, or response time. Your sole remedy for service unavailability is to stop using the Services. Any future paid-tier SLA, if offered, will be published in a separate Service Level Agreement document at that time.
4.3 Changes. We may add, modify, remove, or version Plugins. We will publish changes in each Plugin's CHANGELOG and will give reasonable notice of changes that materially reduce functionality. For paid subscribers, we will give at least thirty (30) days' advance notice before removing material features.
5. Account and Credentials
5.1 Account responsibility. Some Services require an account tied to a verifiable email address. You are responsible for all activity under your account, for keeping your credentials confidential, and for notifying us promptly at [email protected] if you suspect unauthorized use.
5.2 Data Processing Agreement. If you are a business customer established in the European Economic Area (EEA) or the United Kingdom and require a Data Processing Agreement (DPA) in connection with ForgeRift's processing of your account and billing data as part of the Subscription service, you may request one by emailing [email protected]. We will provide a DPA within a reasonable time. The DPA governs ForgeRift's role as a processor of your account and billing data to the extent applicable.
6. Fees, Subscriptions, and Billing
6.1 Trial Period
ForgeRift does not offer a permanent free tier. All paid Subscriptions include a 14-day free trial. See Section 6.3 for full trial terms including payment method requirements and trial-to-paid conversion.
6.2 Paid Subscription Tiers
ForgeRift offers the following paid Subscription plans:
| Plan | Monthly | Annual | Savings |
|---|---|---|---|
| Individual (single plugin) | $14.99 / month | $149.00 / year | ~17% |
| Bundle (both plugins) | $19.99 / month | $199.00 / year | ~17% |
Prices are in U.S. dollars and are exclusive of applicable taxes (see Section 6.7).
6.3 Free Trial
New paid Subscribers receive a 14-day free trial beginning on the date of Subscription activation. A valid payment method is required at sign-up; the card is not charged during the trial period (a temporary $0 or $1 authorization hold may appear and is automatically released by your card issuer).
Important — cancel before the trial ends or your card will be charged. If you do not cancel before the end of your 14-day free trial, your Subscription automatically converts to a paid plan on day 15 and your payment method is charged in full at the then-applicable rate for your plan and billing cadence (monthly or annual). The first charge corresponds to the first paid period that begins on day 15.
No refunds after the trial ends. Subscriptions are non-refundable after the 14-day trial converts to paid status. Cancelling on day 16 or later will not produce a refund of the day-15 charge or any subsequent charge; cancellation simply prevents the next renewal. The only exceptions are billing errors clearly attributable to ForgeRift (per Section 6.5), prorated convenience-termination refunds initiated by ForgeRift (per Section 14.2 / 14.5), and any mandatory statutory refund right that applies in your jurisdiction (Section 6.5, Consumer statutory rights paragraph).
You may cancel at any time before the trial ends by emailing [email protected] from the email address you used at sign-up, or (when the Stripe Customer Portal is enabled) through the self-service portal linked from your receipt. Cancellation during the trial takes effect immediately, you will owe nothing, and the Plugin will validate normally for the remainder of the trial day on which you cancelled.
You acknowledge this trial-conversion behavior at the point of purchase. The Stripe checkout page displays "14-day free trial, then $X.XX/month" or equivalent for your selected plan; clicking "Subscribe" / "Pay" affirms your understanding of automatic conversion to paid status on day 15 in accordance with this Section.
6.4 Auto-Renewal; Cancellation; Downgrade
AUTO-RENEWAL NOTICE (REQUIRED DISCLOSURE -- EU CONSUMER DIRECTIVE 2019/2161): Your Subscription automatically renews at the end of each billing period (monthly or annual) at the then-current price for your plan unless you cancel before the renewal date. ForgeRift will attempt in good faith to send an email reminder at least 3 days before the end of your 14-day free trial, at least 7 days before each monthly renewal charge, and at least 14 days before each annual renewal charge. Delivery failures attributable to the recipient's mail provider, address changes not communicated to ForgeRift, or third-party service-provider outages do not constitute a breach of these Terms, and your cancellation rights are not contingent on receipt of a reminder. To prevent renewal, you must cancel at least 24 hours before your current billing period ends.
Cancellation timing. You may cancel your Subscription at any time through your account settings or by emailing [email protected]. Cancellations take effect at the end of your current billing period -- you retain access to paid features through the period you have already paid for. You will not be charged for subsequent periods.
Downgrade timing. If you downgrade from Bundle to Individual, the downgrade takes effect at the start of your next billing period. You retain access to your current plan's features through the end of the billing period in which you request the downgrade.
6.5 Refunds
General. Except as expressly stated in these Terms or required by applicable law, all fees are non-refundable. This includes fees paid for any portion of a billing period you do not use.
Annual subscriptions. Annual Subscriptions that are cancelled mid-term are not prorated. You will retain access through the end of the annual period you have paid for, but no partial refund will be issued for the unused months.
Trial period. If you cancel during the 14-day free trial, you owe nothing. No refunds are issued after the trial period ends.
Consumer statutory rights. If you are a Consumer in the European Union or the United Kingdom, you may have a statutory 14-day right of withdrawal from a digital content subscription. However, by commencing use of the Services during the withdrawal period, you expressly consent to immediate performance and acknowledge that you lose your right of withdrawal upon commencing use. This acknowledgment is presented as a separate, explicit confirmation step at the point of purchase during checkout — if you do not provide that confirmation, immediate performance will not begin and your right of withdrawal is preserved for the 14-day period. This paragraph does not limit other mandatory statutory refund rights you may have under applicable law.
ForgeRift billing errors. If you are charged incorrectly due to an error on ForgeRift's part — including duplicate charges, charges after a timely cancellation, or charges at an incorrect rate — contact [email protected] with the subject "Billing Error" within 60 days of the charge. ForgeRift will investigate and, where the error is confirmed, refund the incorrect amount within 10 business days. Section 6.6 (chargebacks) does not apply to amounts confirmed as ForgeRift billing errors.
Exceptions. ForgeRift may issue additional refunds at its sole discretion in extraordinary circumstances. Contact [email protected] with subject "Refund Request."
6.6 Chargebacks and Fraudulent Disputes
If you initiate a chargeback, payment dispute, or reversal through your bank or card issuer without first contacting ForgeRift at [email protected] and giving us a reasonable opportunity to resolve the issue (at minimum 5 business days), your account may be suspended pending review upon notice of the chargeback or dispute. You may dispute the suspension within 10 business days of the date ForgeRift sends the suspension notice to your registered email address, by emailing [email protected] with subject "Chargeback Dispute" — ForgeRift will review and respond within 5 business days. ForgeRift may recover documented direct costs incurred as a direct result of an unjustified dispute. This Section 6.6 does not limit your right to dispute a genuinely fraudulent charge that you did not authorize, and does not affect any rights Consumers have under applicable law to seek remedies through their card issuer or bank.
6.7 Taxes
Fees are exclusive of taxes. You are responsible for any sales, use, VAT, GST, digital services tax, or similar tax properly assessed on the Services, except for taxes on ForgeRift's net income. If ForgeRift is required to collect tax on your behalf, it will be added to your invoice.
6.8 Founder Cohort
Founder Cohort pricing is available until the earlier of (a) the 100th paid Subscriber signing up or (b) 3 months after the date this plugin first becomes available for purchase on the Anthropic marketplace — the Founder Cohort window closes 3 months after the date this plugin first becomes available for purchase on the Anthropic marketplace ("Founder Cohort Window"). Founder Cohort rates are: Individual plan at $9.99/month; Bundle plan at $14.99/month. Founder Cohort pricing is offered on monthly billing only; annual billing is not available at the Founder Cohort rate. Selecting or switching to an annual plan at any point converts the subscription to standard pricing and permanently forfeits the Founder Cohort rate lock. Accidental annual-plan switch: A Founder Cohort Member who inadvertently selects annual billing may contact [email protected] within seven (7) calendar days of the switch to revert to the Founder monthly rate; ForgeRift will refund the annual charge on a prorated basis less any days of service used at the annual rate, and restore the Founder rate lock. Founder Cohort Members who maintain an active paid Subscription at the end of the Founder Cohort Window lock in their Founder Cohort rate for as long as the Subscription remains Continuously Active (defined below). Founder Cohort pricing is not transferable, lapses permanently if the Subscription is voluntarily cancelled and then reactivated — the Founder rate cannot be reinstated after such a lapse. Involuntary suspensions arising from payment-method failure that are fully cured within thirty (30) days of the initial suspension event do not count as a lapse for Founder Cohort purposes. ForgeRift may verify Founder Cohort eligibility through subscription records. Rate protection: Once a Subscriber has locked in the Founder Cohort rate, ForgeRift will not increase that rate and will not retire the Founder Cohort tier for any Continuously Active Founder Cohort Member. This protection applies solely to the Founder Cohort monthly rate and does not limit ForgeRift's ability to change standard pricing for new or non-Founder subscribers.
"Continuously Active" means the Subscription is in paid, good-standing status with: (i) no voluntary cancellation; (ii) no plan switch to annual billing other than one reverted within the 7-day accidental-switch grace period described above; and (iii) no involuntary suspension lasting more than thirty (30) days. A Subscription that converts from the 14-day free trial directly to a paid plan without interruption is considered Continuously Active from the trial start date.
6.9 Honor-System Entitlement
Subscription tier access relies on good-faith use: ForgeRift trusts subscribers to use the tier they have subscribed to. Intentionally misrepresenting your Subscription tier (for example, subscribing to Individual while claiming Bundle entitlements) is a violation of these Terms and may result in account suspension.
6.10 Grace Period
If your payment method fails, ForgeRift will retry the charge and send payment failure notices. You will have a 7-day grace period during which paid features remain active. If payment is not collected within the grace period, your Subscription will be suspended. Support will be limited to billing remediation during the grace period.
7. Acceptable Use
You agree not to:
- Use the Services in violation of law, Anthropic's Usage Policy, or the terms of any Marketplace from which you obtained the Plugin.
- Use the Services to attack, compromise, monitor, or disrupt any system or network you are not authorized to operate, to conduct port scanning or vulnerability probing of networks you do not own, to participate in distributed denial-of-service attacks, or to exfiltrate data you are not authorized to access.
- Attempt to defeat, bypass, or disable the Plugins' security classifications (for example, the RED/AMBER/GREEN authorization model), sensitive-file guards, request timeouts, or audit logging.
- Reverse engineer, decompile, or disassemble the Services except to the extent applicable law expressly permits.
- Use the Services to infringe any person's intellectual property, privacy, publicity, or contractual rights.
- Use the Services to generate, distribute, or facilitate malware, ransomware, spyware, credential stuffing, illegal surveillance, or content that is unlawful under applicable law.
- Use the Services for cryptocurrency mining on any system without the explicit written consent of the system owner.
- Deploy AI techniques designed to subliminally manipulate users' behavior without their awareness, to exploit psychological vulnerabilities, or to employ deceptive or coercive persuasion techniques that circumvent rational agency.
- Use the Services for biometric categorization of individuals based on sensitive characteristics (including race, political opinions, religion, health status, or sexual orientation), for social scoring systems that rate individuals' trustworthiness or social behavior, or for inferring emotions in workplace or educational settings, where prohibited by applicable law including the EU AI Act (Regulation 2024/1689).
- Remove or alter attribution, copyright notices, or license text in the Plugin source.
- Resell the Services or redistribute them to third parties for commercial gain, without a separate written agreement with ForgeRift. Use of the Services within your own organization for internal commercial projects is permitted.
Security researchers who discover potential vulnerabilities in the Services are encouraged to report them through the channels described in each Plugin's SECURITY.md file. ForgeRift will not pursue legal claims under these Terms against researchers who report issues in good faith through those channels, without causing undue harm, and without publicly disclosing before ForgeRift has had a reasonable opportunity to remediate.
8. Your Responsibilities for Your Systems
You acknowledge:
- The Plugins execute commands against Your Systems. You are responsible for the state, contents, and continued operation of Your Systems, including backups, access controls, patching, and monitoring.
- The Plugins are a layered defense, not an absolute guarantee. Security classifications, allowlists, request timeouts, and audit logging reduce the blast radius of AI-driven tool calls; they cannot eliminate all risk.
- Command authorization operates on two levels: (a) Explicit authorization -- commands you approve directly through the Plugin interface (e.g., AMBER-tier re-invocations of
run_commandin local-terminal-mcp;run_approved_commandand deploy jobs in vps-control-mcp). You bear full responsibility for explicitly authorized commands and their consequences. (b) Autonomous execution within configured scope -- commands the AI selects and executes within the permission tier you have configured. You bear responsibility for your scope and permission configuration choices; ForgeRift bears responsibility that the Plugin's classification system performed as documented. Operations in the Hard-Blocked categories defined below cannot be executed under either authorization path. - You must monitor and supervise all AI-assisted operations at all times. Do not leave the Services running unattended while connected to production systems, credential stores, or any system where unintended commands would be unacceptable. ForgeRift is not liable for any damage resulting from unattended or unsupervised use of the Services.
- You will review the behavioral transparency documentation published with each Plugin before relying on the Services for sensitive operations.
Hard-Blocked Operations. The following categories of operations are technically blocked by the Plugins and cannot be executed through automated means under any circumstances -- not by Claude's autonomous judgment, not by any user approval through the Plugin interface, and not by any Subscription tier or configuration option. When a request falls into one of these categories, the Plugin returns a non-bypassable error message identifying the blocked category, explaining why automation is disallowed, and providing the recommended manual steps for the user to execute outside the Plugin.
| Category | Representative examples (not exhaustive) |
|---|---|
| Recursive or bulk file deletion | rm -rf, find ... -delete, shred, wipe, bulk unlink operations |
| Destructive git history rewrite | git push --force, git push -f, any push operation that rewrites remote branch history |
| Database destruction | DROP DATABASE, DROP TABLE, TRUNCATE TABLE, DELETE without a WHERE clause scoped to a specific subset of rows |
| Disk-level write operations | mkfs, fdisk, dd with zero- or random-source input, disk format or repartition commands |
| System power-state operations | shutdown, Restart-Computer, Stop-Computer, poweroff, halt, telinit [06], systemctl poweroff/halt/reboot |
| Credential and key material destruction | Deletion or bulk overwrite of .ssh/, .aws/, .gcloud/, .azure/ credential directories, private key files, or certificate stores |
| OS-level permission destruction | chmod -R 000 on non-ephemeral paths, chown -R on root or home directories, deletion of active system user accounts |
This table covers the seven principal hard-block categories. The complete set of 140+ hard-blocked patterns across 27 categories — including outbound network exfiltration (curl, wget, ssh, scp, Invoke-WebRequest), arbitrary code execution (Invoke-Expression, -EncodedCommand, bash -c), package manager commands (choco install/remove, winget install), scheduled task and service creation (schtasks, sc create), privilege escalation (runas, sudo), and registry destruction — is documented in the Plugin's COMMANDS.md file, which is incorporated into the Documentation defined in Section 2. ForgeRift may extend the list in future Plugin releases; additions will be documented in each Plugin's CHANGELOG. This technical block cannot be waived, configured away, or overridden by any means -- including Subscription tier, configuration files, or command-line flags.
WARNING -- SIGNIFICANT OPERATIONS: The Services can execute commands with significant or lasting effects, including deploying code to production servers and modifying system configurations. You are solely responsible for maintaining current backups of Your Systems and for verifying commands before authorization. Do not use the Services on systems where unintended production changes would be unacceptable unless independent backup and recovery procedures are in place. Operations with the highest irreversibility risk -- including recursive file deletion, force-push, and database destruction -- are hard-blocked at the Plugin level and cannot be initiated through the Services under any circumstances (see Hard-Blocked Operations above).
Gated Operations. Certain operations that are reversible in principle but carry elevated risk -- including production deployments and system configuration changes -- require explicit per-invocation user confirmation before the Plugin will execute them. When the Plugin identifies a Gated Operation, it presents a plain-language description of the action, its target, and the potential consequences, and requires the user to affirmatively confirm before proceeding. The mechanism by which confirmation is surfaced differs by Plugin: in local-terminal-mcp, AMBER-tier confirmation operates as a workflow convention (the dry_run parameter defaults to true; re-invoking with dry_run=false after review is the recommended flow -- this is not a server-side per-invocation gate, as further described in Schedule B.1); in vps-control-mcp, confirmation is enforced per invocation at the deploy-pipeline level. By confirming a Gated Operation, you represent that you understand the action, have reviewed the target and consequences, and accept full responsibility for the outcome. A confirmation that was induced by misleading AI output does not transfer responsibility from you to ForgeRift -- you retain responsibility for reviewing the described action before confirming.
8.A Your acknowledgments — the AI behavior layer is not under ForgeRift's control
Read this section carefully. By using the Services you affirmatively acknowledge each of the following.
- The Plugins direct Claude (Anthropic PBC) and Cowork (Anthropic PBC) to execute actions on Your Systems. Claude and Cowork are independent products owned and operated by Anthropic PBC. ForgeRift LLC does not own, operate, train, control, or direct Claude or Cowork in any respect. ForgeRift does not control which commands Claude generates, when Claude generates them, how Claude interprets your instructions, or whether Claude follows the Plugin's behavioral safety guidance. The Plugin's role is limited to validating, classifying, gating, auditing, and (where permitted by tier) executing commands the AI selects. Anthropic's behavior, model updates, policy changes, and outages are outside ForgeRift's control.
- You are responsible for what you authorize. Every AMBER-tier or otherwise gated operation requires your affirmative confirmation. By confirming, you represent that you have read the plain-language description of the action and the system it targets, that you understand the consequences, and that you accept full responsibility for the outcome. A confirmation that was induced or recommended by AI output does not transfer responsibility from you to ForgeRift. You retain the duty to review the described action before confirming, and you agree that any damages resulting from a command you confirmed are your responsibility, not ForgeRift's.
- You are responsible for your scope and permission configuration. The Plugin offers configurable scopes (which directories may be read, which PM2 processes may be restarted, whether an Anthropic API key is provided to enable Layer 2/3 AI safety review, etc.). Setting these scopes too broadly is your decision and your risk. ForgeRift bears responsibility that the Plugin's classification system performs as documented; ForgeRift does not bear responsibility for damages arising from a scope you chose to configure.
- You are responsible for backups, monitoring, and recovery. The Plugins are a layered defense; they reduce blast radius but do not eliminate risk. Maintaining current backups, monitoring system state, and having independent recovery procedures are your responsibility regardless of how you use the Services.
- You are responsible for your own credentials, secrets, and operational hygiene. If you paste API keys, passwords, or other secrets into your conversation with Claude, those values become part of the conversation context Anthropic processes and may appear in command arguments, AI safety classification calls, or Plugin audit logs. Do not paste production secrets into AI conversations. ForgeRift is not responsible for the consequences of secrets you placed into conversation context.
- You are responsible for unsupervised use. Do not leave the Services running unattended while connected to production systems, credential stores, or any system where unintended commands would be unacceptable. ForgeRift is not liable for any damage resulting from unattended or unsupervised use of the Services.
- You are responsible for compliance with Anthropic's Usage Policy and Marketplace terms. Your use of Claude is independently governed by Anthropic's terms; nothing in these Terms grants any rights or warranties with respect to Anthropic's services. If Anthropic changes its policies, the Plugins may need to change too; ForgeRift will make reasonable efforts to keep the Plugins compatible but does not warrant continuous compatibility.
- Behavioral transparency, not operational control. ForgeRift publishes detailed Documentation describing what the Plugin enforces (the static deny list, allowlist validators, sensitive-file guards, audit logging, and tier classifications). That Documentation is the limit of ForgeRift's behavioral commitment. The Plugin enforces what it documents; the Plugin does not warrant outcomes that depend on AI judgment, third-party platforms, or user choices.
Nothing in this Section limits any mandatory consumer-protection rights you may have under applicable law. Sections 11 (Disclaimers), 12 (Limitation of Liability), and 13 (Indemnification) apply with full force, subject to those mandatory rights.
9. Third-Party Services
The Services interoperate with third-party platforms including Anthropic (Claude), GitHub (source hosting), payment processors (Stripe), email providers (Resend), Supabase (subscription database), and Let's Encrypt / sslip.io (TLS issuance for vps-control-mcp). ForgeRift is not responsible for third-party services, outages, or changes in their terms. Your use of a third-party platform is governed by that platform's terms.
10. Intellectual Property
10.1 ForgeRift IP. ForgeRift retains all right, title, and interest in the Services, except for rights expressly granted to you in these Terms and Schedule A. The ForgeRift name, the forgerift.io domain, and our logos are our trademarks; no license to our trademarks is granted by these Terms.
10.2 Source license. The Plugin source code is distributed under the MIT License (see each repository's LICENSE file). The MIT License governs your rights in the source code. Schedule A governs your use of pre-built Plugin binaries, installers, updates, documentation, and ForgeRift-provided services associated with the Plugins.
10.3 Feedback. If you send us suggestions or feedback, you grant us a non-exclusive, royalty-free, perpetual, irrevocable, worldwide license to use it without restriction. We welcome it.
11. Disclaimers
11.1 As is. To the maximum extent permitted by law, the Services are provided "as is" and "as available," without warranties of any kind, whether express, implied, statutory, or otherwise, including implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement.
11.2 No warranty of fit for sensitive operations. The Plugins operate by directing Claude, an AI system, to execute commands on Your Systems. AI systems follow instructions probabilistically -- Claude may not always follow the Plugin's behavioral safety instructions, may issue commands outside the intended scope, or may be induced by unexpected inputs to behave outside its configured parameters. The Plugin's RED/AMBER/GREEN classification system reduces but does not eliminate this risk. ForgeRift does not warrant that Claude will always follow the Plugin's behavioral instructions, that the Plugin will prevent every unsafe command, or that the Services will be uninterrupted or error-free. You acknowledge this disclosure and the behavioral transparency documentation published with each Plugin. Operations in the Hard-Blocked categories defined in Section 8 are technically impossible through the Plugin regardless of AI instruction, user configuration, or Subscription tier -- the Plugin returns a non-bypassable error and directs you to execute those actions manually outside the Plugin.
11.3 Consumers. If you are a Consumer and applicable law grants you statutory warranties or remedies that cannot be disclaimed, the disclaimers in this Section 11 apply only to the maximum extent permitted. Nothing in these Terms limits a Consumer's mandatory statutory rights.
12. Limitation of Liability
12.1 Cap. To the maximum extent permitted by law, ForgeRift's total aggregate liability arising out of or relating to these Terms or the Services, under any theory, will not exceed the greater of (a) the amount you paid ForgeRift for the Services in the twelve (12) months preceding the first event giving rise to the claim, or (b) one hundred U.S. dollars (USD $100).
12.2 Excluded damages. ForgeRift will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, data, or goodwill, even if advised of the possibility of such damages.
12.3 Infrastructure costs. ForgeRift is not liable for VPS hosting fees, cloud computing costs, bandwidth charges, storage fees, or any other third-party infrastructure expenses you incur through your use of the Services, regardless of whether those costs result from commands executed by the AI within your configured parameters or from commands you explicitly authorized.
12.4 Consumers. Nothing in this Section 12 limits liability for (a) death or personal injury caused by ForgeRift's negligence, (b) fraud or fraudulent misrepresentation, or (c) any other liability that cannot be limited or excluded under applicable law. For Consumers ordinarily resident in the United Kingdom or the European Union, Sections 12.1 and 12.2 apply only to the extent permitted by the Consumer Rights Act 2015 (UK) or equivalent mandatory consumer-protection law in your country of residence. Where applicable mandatory law renders any limitation in this Section 12 unfair or unenforceable, that limitation does not apply to you and you retain all rights available under that law.
13. Indemnification
You will defend, indemnify, and hold harmless ForgeRift, its members, employees, and contractors from and against any third-party claim, demand, loss, or expense (including reasonable attorneys' fees) arising out of or related to (a) your breach of these Terms, (b) your violation of law or third-party rights, or (c) your use of the Services in or against any system you were not authorized to operate. This Section 13 does not apply to Consumers.
14. Term and Termination
14.1 Term. These Terms apply from the first time you use the Services and continue until terminated.
14.2 Termination for convenience. You may stop using the Services at any time. You may uninstall the Plugins through Claude Desktop's Extensions settings (no terminal or scripts required). ForgeRift may terminate your access to any non-free Service for convenience with thirty (30) days' notice. If ForgeRift terminates a paid Subscription for its own convenience, we will refund the prorated unused portion of any prepaid annual fees for the remaining period after the termination date. Upon any Subscription cancellation or termination, ForgeRift will deactivate all license keys associated with your account within 24 hours. If you subscribe to vps-control-mcp, you are additionally responsible for revoking bearer tokens and removing sslip.io DNS entries per the vps-control uninstall guide; ForgeRift will deactivate OAuth client registrations for vps-control within 24 hours of termination.
14.3 Termination for cause. Either party may terminate these Terms immediately if the other party materially breaches them and fails to cure within thirty (30) days of written notice. ForgeRift may suspend or terminate your access immediately if your use threatens the security or integrity of the Services or violates Section 7. Except in cases of active and ongoing security threat or AUP violation, ForgeRift will provide at least 24 hours' written notice before suspending a paid account and will work in good faith to resolve the underlying issue. Chargeback abuse under Section 6.6 constitutes grounds for immediate suspension pending review per the process in Section 6.6. Suspended users retain the right to contact [email protected] to dispute the suspension. ForgeRift reserves the right to preserve and disclose account information to law enforcement authorities where required by law or in response to valid legal process, and will cooperate with investigations into criminal misuse of the Services.
14.4 Effect of termination. Sections 6 (outstanding payment obligations and accrued refund rights), 10 (IP), 11 (Disclaimers), 12 (Liability), 13 (Indemnification), 14.2 (prorated-refund obligation arising from for-convenience termination), 14.5 (service discontinuation obligations where applicable), 16 (Governing Law), 17 (Disputes), 18 (Export Controls and Sanctions), and 19 (Miscellaneous) survive termination. The MIT License in each repository continues to govern the source code you obtained before termination.
14.5 Service discontinuation and Marketplace delisting. This Section governs permanent product discontinuation or marketplace delisting affecting all Subscribers and is in addition to (not a replacement for) the per-subscriber for-convenience termination process in Section 14.2. If ForgeRift permanently discontinues a Plugin or the Plugin is removed from the Anthropic Marketplace (whether by ForgeRift's choice or by Anthropic's action), ForgeRift will: (a) provide at least thirty (30) days' advance written notice to active Subscribers where practicable; (b) refund the prorated unused portion of any prepaid annual fees for the period after the discontinuation date; and (c) maintain the license validation server in operational status for at least the full duration of any annual billing period already paid. For monthly Subscribers, access continues through the end of the last paid billing period. ForgeRift's total liability in a discontinuation event is limited to the refund of prepaid fees described in this Section.
15. Changes to the Terms
We may update these Terms from time to time. We will publish the updated Terms at forgerift.io/terms and revise the "Last updated" date. For material changes -- including changes to pricing, supported platforms, feature availability, or acceptable use restrictions -- we will give at least thirty (30) days' advance notice through the Services or by email. Your continued use of the Services after an update takes effect means you accept the updated Terms. If you do not accept, stop using the Services.
16. Governing Law
These Terms are governed by the laws of the State of Wisconsin, U.S.A., without regard to its conflict-of-laws rules. The U.N. Convention on Contracts for the International Sale of Goods does not apply.
If you are a Consumer ordinarily resident in the European Union or the United Kingdom, this choice of law does not deprive you of the protection of mandatory consumer-protection laws of your country of residence.
17. Disputes
17.1 Informal resolution first. Before initiating arbitration or filing any claim, you agree to contact us at [email protected] and attempt to resolve the dispute informally for at least thirty (30) days. Most concerns can be resolved quickly this way. The 30-day period begins when you send written notice of your claim to [email protected].
17.2 Binding individual arbitration. If informal resolution under Section 17.1 does not resolve the dispute within thirty (30) days, either party may initiate binding arbitration. All disputes arising out of or relating to these Terms or the Services -- except those that qualify under Section 17.4 (Small Claims) -- shall be resolved by final and binding individual arbitration administered by the American Arbitration Association ("AAA") under its then-current Commercial Arbitration Rules. The arbitration will be conducted in Milwaukee County, Wisconsin, unless the parties agree otherwise in writing. The arbitrator shall apply Wisconsin substantive law and shall have authority to grant any relief that a court could grant. The arbitrator's award shall be in writing and may be entered as a judgment in any court of competent jurisdiction. The party initiating arbitration pays the AAA filing fee; all other arbitration costs are allocated per AAA rules.
17.3 Class action waiver. All disputes must be arbitrated or litigated on an individual basis only. Neither party may bring or participate in any class, collective, consolidated, or representative action or proceeding before any arbitrator or court. The arbitrator has no authority to consolidate claims or to conduct class or representative proceedings. If this class action waiver is found unenforceable with respect to any particular dispute, that dispute shall proceed in court under Section 17.6 rather than in arbitration.
17.4 Small claims. Either party may bring qualifying claims in small-claims court in the jurisdiction where the claimant resides, without first going through informal resolution or arbitration.
17.5 Limitations period. Any claim or action arising out of or relating to these Terms or the Services must be commenced within one (1) year after the cause of action arose, regardless of any statute of limitations to the contrary. Claims not filed within this period are permanently barred.
17.6 Courts (fallback). If Section 17.2 is found invalid, inapplicable, or unenforceable in a particular dispute, or for any dispute excluded from arbitration, that dispute shall be brought exclusively in the state or federal courts located in Milwaukee County, Wisconsin, and each party irrevocably consents to the personal jurisdiction of those courts.
17.7 Consumer carve-out. Sections 17.2 (arbitration) and 17.3 (class action waiver) do not apply to a Consumer exercising mandatory rights that cannot be waived under applicable law. EU Consumers may also use the European Commission's Online Dispute Resolution platform at https://ec.europa.eu/consumers/odr. If you are a Consumer ordinarily resident in the EU or the United Kingdom, these provisions do not deprive you of the right to bring or defend proceedings in the courts of your country of residence where required by applicable law.
18. Export Controls and Sanctions
The Services are subject to U.S. export control laws and regulations, including the Export Administration Regulations (EAR) administered by the U.S. Bureau of Industry and Security (BIS) and economic sanctions administered by the U.S. Office of Foreign Assets Control (OFAC).
You represent and warrant that:
- You are not located in, and are not a national or resident of, any country or territory subject to a comprehensive U.S. embargo as determined by OFAC from time to time (currently Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk People's Republic, and Luhansk People's Republic regions of Ukraine);
- You are not named on, and are not owned or controlled by any entity named on, any U.S. Government restricted-party list, including the OFAC Specially Designated Nationals List, the BIS Entity List, the BIS Denied Persons List, or the U.S. State Department Debarment List;
- You will not use the Services, directly or indirectly, in violation of any applicable export control law, regulation, or license restriction; and
- You will not export, re-export, or transfer the Services or any direct product thereof to any prohibited destination, person, or entity without obtaining any required authorization from the applicable U.S. government agency.
ForgeRift reserves the right to refuse, suspend, or terminate Services to any user or jurisdiction where required by applicable law or regulation.
19. Miscellaneous
19.1 Entire agreement. These Terms, Schedule A, Schedule B, and the Privacy Policy are the entire agreement between you and ForgeRift concerning the Services and supersede any prior agreements on the same subject.
19.2 Severability. If any provision of these Terms is held unenforceable, the remaining provisions remain in effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable while preserving the parties' intent.
19.3 No waiver. A failure or delay in enforcing any provision is not a waiver of that provision.
19.4 Assignment. You may not assign these Terms without our prior written consent. ForgeRift may assign these Terms in connection with a merger, acquisition, or sale of substantially all of its assets.
19.5 Force majeure. Neither party is liable for failure to perform due to causes beyond its reasonable control, including acts of God, war, terrorism, labor disturbance, internet or utility outages, and governmental action.
19.6 Relationship of the parties. The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship.
19.7 Notices. Notices to ForgeRift go to [email protected]. Notices to you may be sent to the email associated with your account, posted on forgerift.io, or delivered in-product.
19.8 Headings. Section headings are for convenience and do not affect interpretation.
19.9 Electronic communications (E-SIGN Act). By using the Services, you consent to receive from ForgeRift all communications required by law in electronic form, including these Terms, the Privacy Policy, purchase receipts, renewal notices, and other required disclosures. You agree that electronic communications satisfy any requirement that such communications be "in writing." You may request a paper copy of any electronic communication by emailing [email protected]; ForgeRift may charge a reasonable administrative fee for paper delivery. You may withdraw this consent at any time, but doing so may limit ForgeRift's ability to provide certain Services.
Schedule A -- End User License Agreement (EULA)
This EULA governs your use of the Plugins as distributed by ForgeRift. It is incorporated into the Terms by reference.
A.1 License grant
Subject to these Terms, ForgeRift grants you a non-exclusive, non-transferable, revocable license to install, run, and use each Plugin on systems you own or control, solely for your own internal purposes (personal or business). The Plugin source code is separately licensed under the MIT License as set forth in each repository's LICENSE file.
A.2 Permissions and Restrictions
You may fork the Plugin repositories, publish modified versions under a different name, and use them for personal or internal organizational purposes in accordance with the MIT License terms in each repository.
You will not:
- Use the Plugin to provide a commercial managed service to third parties (e.g., running the Plugin as part of a hosted service you resell) without a separate written agreement with ForgeRift. This does not restrict use within a single organization, including its subsidiaries and affiliates.
- Modify or remove security classifications (RED/AMBER/GREEN), allowlists, sensitive-file guards, request timeouts, audit logging, or behavioral directives, and then redistribute the modified Plugin under the ForgeRift name or trademarks.
- Represent a modified fork as an official ForgeRift Plugin.
A.3 Updates
ForgeRift may issue updates, patches, and new versions. You are encouraged to run current versions. ForgeRift treats security vulnerabilities as high priority; critical vulnerabilities will be patched and announced via SECURITY.md and notified to subscribers by email as promptly as practicable. ForgeRift targets patch release within 72 hours for vulnerabilities scoring CVSS 9.0 or above, and within 30 days for vulnerabilities scoring CVSS 7.0--8.9, subject to third-party dependencies and factors outside ForgeRift's reasonable control. You are responsible for updating to patched versions promptly upon notification. ForgeRift is not obligated to maintain backwards compatibility for experimental features documented as such in the CHANGELOG at the time of that version's release.
A.4 Reservation of rights
All rights not expressly granted are reserved to ForgeRift.
A.5 Source code
The Plugin source code is licensed separately under the MIT License. Nothing in this EULA restricts your rights under the MIT License with respect to source code you obtain from the public repository.
A.6 Regulated industries
The Plugins are not designed, certified, or intended to comply with industry-specific regulatory requirements, including but not limited to HIPAA (healthcare), FISMA (federal information systems), GLBA (financial services), PCI-DSS (payment card data), or FERPA (education records). You are solely responsible for determining whether the Plugins are appropriate for use in any regulated environment and for ensuring your own compliance with applicable regulations.
A.7 Third-party platform dependency
The Plugins depend on third-party platforms outside ForgeRift's control, including the Claude AI platform (Anthropic PBC), the Model Context Protocol (MCP) specification, and the Anthropic Marketplace. ForgeRift is not liable for any interruption, degradation, or incompatibility resulting from changes to those platforms, including API changes, policy updates, MCP protocol revisions, or Marketplace rule changes. ForgeRift will make reasonable efforts to maintain compatibility with current versions of these platforms but makes no guarantee of compatibility with future versions.
Schedule B -- Product-Specific Terms
B.1 local-terminal-mcp
- Windows 10/11 only — macOS and Linux are not currently supported. Runs on your local workstation and accesses your local filesystem, git repositories, npm projects, and system information through structured tools that enforce sensitive-file guards and per-tool validation. Arbitrary shell commands additionally pass through a three-tier security classifier (RED/AMBER/GREEN).
- You acknowledge the sensitive-file guards (including .env, SSH keys, .pem/.key/.pfx certificates, Windows credential stores, cloud credentials (.aws, .gcloud, .azure), browser login data, kubeconfig, and other credential and secret files documented in SECURITY.md) and agree not to attempt to disable or circumvent them.
- Command execution via the
run_commandtool is subject to a dry-run-first policy:dry_run=trueis the default for everyrun_commandinvocation regardless of security tier. For AMBER-tier commands, the recommended workflow is to preview withdry_run=true, present the warning to the user, and re-invoke withdry_run=falseonly after confirmation; this is a workflow convention enforced by Claude's behavior, not a server-side two-call gate. This policy is fully described in the README distributed with each Plugin release. - Each tool invocation is subject to a per-tool wall-clock timeout: 30 seconds for
run_commandandrun_git_command; 60 seconds forrun_npm_command(npm operations legitimately require more time). If a spawned child process does not complete within its timeout, it receives a kill signal and the tool call returns an error. Long-running commands (for example,npm auditon a project with thousands of dependencies orgit log --allon a very large repository) may fail as a result. You are responsible for structuring commands to complete within this limit or running them directly in your own terminal. - Audit logs are written to
logs/audit.logwithin the extension's install directory (managed by Claude Desktop). Whenaudit.logreaches 10 MB it is renamed toaudit.log.old, overwriting any prior backup; maximum on-disk storage is approximately 20 MB at any time. Audit logs never leave your machine; you may delete them at any time. ForgeRift does not receive telemetry, command output, file contents, or usage data from local-terminal-mcp. The plugin sends your license key to ForgeRift's subscription service (hosted on Supabase) at startup solely to verify your active subscription. If the license validation endpoint is unreachable at startup (network outage, server maintenance), the plugin fails closed — it exits immediately with an error and provides no tools until successfully restarted. There is no offline grace period. See the Privacy Policy at forgerift.io/privacy.html for full details. - Optional Anthropic API key: If you supply an Anthropic API key in Claude Desktop's extension configuration, the command text and user-provided justification for every
run_commandinvocation (not only AMBER-tier commands) are sent to Anthropic's API for AI-assisted safety classification before execution. A high-risk classification result may independently block execution. This is opt-in; without an API key, the AI classification layers are skipped entirely and AMBER commands fall back to the manual dry-run-and-confirm flow described above. Each classification call consumes API tokens billed to your Anthropic account at Anthropic's rates. This data flow is between you and Anthropic; ForgeRift does not receive this data. See the Privacy Policy at forgerift.io/privacy.html §2.1 for full details.
B.2 vps-control-mcp
- Runs on a Linux VPS you already operate. ForgeRift does not host your VPS and does not have network access to it.
- You are responsible for providing OAuth 2.0 client credentials or a bearer token at setup time, for managing TLS (the bundled setup.sh wires Let's Encrypt via sslip.io on your behalf, but you retain control of the certificate), for the allowlist of PM2 processes and readable file paths, and for the integrity of the VPS itself.
- The deploy pipeline is a Gated Operation. Each invocation presents a plain-language summary of the target repository, branch, and PM2 process before execution, and requires your explicit confirmation. You retain full responsibility for any deployment you confirm.
- Audit logs are stored on your VPS. ForgeRift does not receive telemetry, command output, or file contents from vps-control-mcp. License key validation works differently from local-terminal-mcp: vps-control-mcp validates each incoming MCP request against either Supabase (in marketplace billing mode, looking up the bearer token in the
customerstable for plan-based access control) or a single configured bearer token (in self-hosted / dev mode). It does not compute a machine fingerprint, does not POST topayments.forgerift.io/validate, and does not register a per-machine activation. Per-machine activation parity with local-terminal-mcp is on the post-marketplace roadmap. See the Privacy Policy at forgerift.io/privacy.html — Section 2.1.1 for details.
Contact
ForgeRift LLC
5821 W Mineral St, West Allis, WI 53214, U.S.A.
(Principal office and registered agent address)
Email: [email protected]
Website: https://forgerift.io
Security: [email protected] (or GitHub Security Advisory on each repository)
ForgeRift provides support via email only — no phone support is offered.
End of Terms of Service.