Hares — MCP security scanner runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 10 Aug 2026.
Multi-layer security scanner for MCP servers and agent skills (injection, exfiltration)
We read the source, 13 h ago · rules 99ea952c379d
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
/(^|[\s;&|(`])(sudo|doas|pkexec)\s|osascript\s+-e\s+.*with\s+administrator\s+privileges|-Verb\s+RunAs|\brunas\s+\/user:/i;
GITHUB_TOKEN: "ghp_9dK2mR7xQ4pL8vN1sT6wZ3yB5cV0nA8fJ2ug",
{ re: /(^|[/\\])\.git-credentials$/, store: "git" },
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
raw = await read(path.join(dir, name));
spawnSync("docker", ["rm", "-f", "-v", name], { stdio: "ignore", windowsHide: true, timeout: SANDBOX_TEARDOWN_MS });
const _KEY_FILES = new Set(["id_rsa", "id_dsa", "id_ecdsa", "id_ed25519", ".netrc", ".pgpass"]);
"pastebin.com",
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add hares -- npx -y @alihashim313/hares
{
"mcpServers": {
"hares": {
"args": [
"-y",
"@alihashim313/hares"
],
"command": "npx"
}
}
}
[mcp_servers.hares]
command = "npx"
args = ["-y", "@alihashim313/hares"]
{
"mcpServers": {
"hares": {
"args": [
"-y",
"@alihashim313/hares"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"hares": {
"args": [
"-y",
"@alihashim313/hares"
],
"command": "npx"
}
}
}
Security scanner for AI agent skills and MCP servers
Security scanner for MCP servers - detects tool poisoning and injection
Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
Scan for prompt injection, secrets, PII, and vet MCP servers before installation
Security firewall for AI agents — scans MCP calls for injection, secrets, and risks.
Multi-agent LLM security layer detecting prompt injection and jailbreaks.
Security scanner for MCP servers. SSRF, path traversal, injection, auth, secrets. Grade A-F.
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Answers built from our own checks of this server.