Flare runs on your own machine — the client starts it, so there is no endpoint to ping. 106 installs a week from npm.
Scan a running app or repo for leaked secrets, exposed routes and open RLS, and verify live keys
Today is the operative word: we check Flare every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add security -- npx -y flarehq-mcp
{
"mcpServers": {
"security": {
"args": [
"-y",
"flarehq-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.security]
command = "npx"
args = ["-y", "flarehq-mcp"]
{
"mcpServers": {
"security": {
"args": [
"-y",
"flarehq-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"security": {
"args": [
"-y",
"flarehq-mcp"
],
"command": "npx"
}
}
}
Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.
Security scanning for websites, public repositories, and Open CLAW skills.
Secure MCP runtime server for scanning and autofixing code issues
Detects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.
Evidence-backed verification for citations, URLs, packages, repos, and cases -- for agents.
Remote MCP server for OFAC screening, EDD memos, exposure forecasts, queues, and reports.
Encrypted store for API keys and database URLs your code needs. Use them without reading them.
Scan GitHub repos and profiles for malware before cloning — commit-pinned risk verdicts for agents
Answers built from our own checks of this server.