flagrix

flagrix

Enables AI agents to scan GitHub repositories and user profiles for malware signals before cloning, providing risk verdicts pinned to specific commits.

Category
Visit Server

README

flagrix

Scan GitHub repositories and profiles for malware before you clone — from the terminal, CI, or an AI agent. The same commit-pinned verdict as the Flagrix browser extension, made callable.

npx flagrix scan https://github.com/some-org/coding-assignment
  some-org/coding-assignment @ 3f9c2a1
  HIGH RISK — Do not clone  security score 12/100
  3 files scanned · 10 dependencies · 2 issues

  CRITICAL Data exfiltration patterns detected: Keylogger Pattern
    assignment.js:14
      14  document.addEventListener("keydown", (e) => send(e.key))

Built after real fake-recruiter campaigns ("coding assignment" repos that steal wallets, SSH keys, and browser sessions) started targeting developers.

Commands

flagrix scan <url | owner/repo>   # scan a repository (--ref <branch|sha>)
flagrix scan-user <username>      # score a GitHub profile for scam signals
flagrix mcp                       # MCP server (stdio) for AI agents

Exit codes

code meaning
0 low risk
1 scan failed
2 medium risk — review before proceeding
3 high risk — do not clone

--json (automatic when stdout is piped) emits the full result. The verdict is pinned to the scanned commit (commitSha in the JSON): every file is read at that SHA, so a push mid-scan or after the verdict can't silently invalidate it.

AI agents

claude mcp add flagrix -- npx -y flagrix mcp

Tools: scan_github_repo, scan_github_user. A Claude Code hook that gates every git clone on a scan ships in hooks/ — see docs/agent-gating.md.

Tokens & rate limits

Unauthenticated scans use GitHub's 60 req/h budget (a scan issues one request per scanned file, up to ~50). Set GITHUB_TOKEN (or FLAGRIX_GITHUB_TOKEN, or --token) to raise it to 5,000/h and to scan private repositories.

Privacy

Fully local. No telemetry, no accounts, no Flagrix backend — the only network calls go to the GitHub/npm APIs and the public detection-rules repository (signature refresh, cached 6 h, with a bundled offline snapshot).

How it works

Scanning logic lives in @flagrix/scanner-core (MIT), signatures in flagrix-detection-rules (MIT) — the same engine and rules the browser extension uses. Verdicts are risk assessments, not definitive fraud determinations; always verify through official channels.

AI Disclosure

This project leverages Claude AI for boilerplate generation, test-suite expansion, and optimization. All AI-generated code is strictly reviewed, refactored, and verified by human maintainers before merging.

License

MIT — see LICENSE.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured