ai.helixar/mcp

MCPcommunitylive
v0.0.1ai.helixarUnknownUpdated 5mo agoGitHub

Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.

Agentic-AI security tools for Claude, exposed as a remote MCP server. Status: Live at . Two tools available remotely (Streamable HTTP); a third runs locally over stdio. Public, no-auth in v1 — OAuth lands with Phase 8. Tool | What it does | | Scan an MCP server (URL or raw manifest JSON) against Sentinel detection rules. Returns risk score, findings, and a Claude-generated security brief. Quick…

Endpoint healthlive
checked 1h ago · 31ms · auth required
100% of the last 6 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
5mo agoLast update
Package
Authorai.helixar
LicenseUnknown
Version0.0.1
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: run `forge publish` from the repo to claim ownership
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface35 tools · 3 privileged
Security scan✓ CleanvHEAD · 3mo agoHow well does this scan work?
EvalsNone
IndexedJun 13, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

35 tools · 3 privileged
Statically extracted from the published packagevHEAD · 3mo ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

helixar_inspect_mcpNo description published

This tool published no description. Forge does not invent one.

helixar_hdp_validateNo description published

This tool published no description. Forge does not invent one.

helixar_releaseguardNo description published

This tool published no description. Forge does not invent one.

search_inboxNo description published

This tool published no description. Forge does not invent one.

delete_repositoryprivilegedNo description published

This tool published no description. Forge does not invent one.

export_all_usersNo description published

This tool published no description. Forge does not invent one.

lookup_customerNo description published

This tool published no description. Forge does not invent one.

do_thingNo description published

This tool published no description. Forge does not invent one.

drop_databaseprivilegedNo description published

This tool published no description. Forge does not invent one.

fetchNo description published

This tool published no description. Forge does not invent one.

pingNo description published

This tool published no description. Forge does not invent one.

sendNo description published

This tool published no description. Forge does not invent one.

list_usersNo description published

This tool published no description. Forge does not invent one.

run_queryNo description published

This tool published no description. Forge does not invent one.

renderNo description published

This tool published no description. Forge does not invent one.

bundleNo description published

This tool published no description. Forge does not invent one.

run_codeNo description published

This tool published no description. Forge does not invent one.

http_getNo description published

This tool published no description. Forge does not invent one.

admin_reset_passwordsNo description published

This tool published no description. Forge does not invent one.

notifyNo description published

This tool published no description. Forge does not invent one.

read_fileNo description published

This tool published no description. Forge does not invent one.

get_configNo description published

This tool published no description. Forge does not invent one.

ok_toolNo description published

This tool published no description. Forge does not invent one.

searchNo description published

This tool published no description. Forge does not invent one.

device_controlNo description published

This tool published no description. Forge does not invent one.

state_machine_stepNo description published

This tool published no description. Forge does not invent one.

chain_stepNo description published

This tool published no description. Forge does not invent one.

describe_password_policyNo description published

This tool published no description. Forge does not invent one.

check_complexityNo description published

This tool published no description. Forge does not invent one.

rotation_statusNo description published

This tool published no description. Forge does not invent one.

noopNo description published

This tool published no description. Forge does not invent one.

delete_accountprivilegedNo description published

This tool published no description. Forge does not invent one.

export_all_messagesNo description published

This tool published no description. Forge does not invent one.

delegate_to_subagentNo description published

This tool published no description. Forge does not invent one.

chain_callNo description published

This tool published no description. Forge does not invent one.

0 of 35 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Agentic-AI security tools for Claude, exposed as a remote MCP server. Status: Live at . Two tools available remotely (Streamable HTTP); a third runs locally over stdio. Public, no-auth in v1 — OAuth lands with Phase 8. Tool | What it does | ** | Scan an MCP server (URL or raw manifest JSON) against Sentinel detection rules. Returns risk score, findings, and a Claude-generated security brief. Quick mode is free + authless (top 8 rules). Deep mode runs all 26 rules with an API key. | | Validate…

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.

Topics

Related in security