Flagrix runs on your own machine — the client starts it, so there is no endpoint to ping. 53 installs a week from npm. Last commit 13 Jul 2026.
Scan GitHub repos and profiles for malware before cloning — commit-pinned risk verdicts for agents
We read the source, 20 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
"pattern": "(?:fs\\.read|readFileSync|readFile)\\s*\\([^)]*(?:\\.ssh|\\.aws|\\.gnupg|\\.docker|id_rsa|credentials)",
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add flagrix -- npx -y flagrix
{
"mcpServers": {
"flagrix": {
"args": [
"-y",
"flagrix"
],
"command": "npx"
}
}
}
[mcp_servers.flagrix]
command = "npx"
args = ["-y", "flagrix"]
{
"mcpServers": {
"flagrix": {
"args": [
"-y",
"flagrix"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"flagrix": {
"args": [
"-y",
"flagrix"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
GITHUB_TOKEN (Optional GitHub token — raises API rate limits and enables private-repo scans).
The author declared them in the registry entry; get the values from the project itself.
GitHub for AI agents — repos, files, code search, issues, PRs, commits. Read-only default.
Scans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it.
Read-only, commit-pinned repository context for coding agents.
GitHub repo maintainability verdicts—maintained, slowing, at-risk, abandoned—via MCP.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Every Agent Skill installed for any coding agent, plus GitHub skill repos, as MCP tools/resources.
PQC scanner for GitHub repos and smart contracts. Detects quantum-vulnerable ECDSA/RSA.
MCP server for GitHub repo health, commit summaries, issue triage, and RAG Q&A.
Answers built from our own checks of this server.