har-forensics-mcp

Finds the leaked tokens in a .har capture, scores every third party by how much damage it could do, and writes a redacted copy safe to attach to a ticket. Local only, no network calls.

npm · fingerprint de15f0deae1ac7fb34318238 · repository · RSS

13tools
1recorded versions
13htracked
tracking started

What changed

Nothing, since tracking began. That is the good outcome, and it is what most servers look like.

Current tools

Show all 13 tool fingerprints
analyze_har
037e961d4bf93204
find_captures
679457c401856fb1
har_brief
8414d16baa32a749
har_csp
5b3d942cdddea426
har_curl
ac4b6fbaf803dc8f
har_diff
8c8f7253746898a1
har_entry
fd3be4e00349176e
har_findings
5f7db8ff8616c726
har_hunt
d4711337c481305a
har_perf
61afe11d11ee273a
har_provenance
78c455e6da8957d5
har_vendors
aa3bffe9c3e165c2
sanitize_har
ead5f6b70a78b3d3

Watch this server yourself

If you run this server, put the proxy in front of it. It pins these exact fingerprints on first connect and stops the session if they move.

npx --yes mcp-pin@0.1.0 -- <your har-forensics-mcp command>

Or subscribe to this page's RSS feed to be told when it changes.

Badge

mcp-pin status badge for har-forensics-mcp

The badge states one fact about time and nothing else. It never claims a server is safe.

[![mcp-pin](https://mcp-pin.gautamkhosla.com/badge/951d474e43a05d76.svg)](https://mcp-pin.gautamkhosla.com/servers/951d474e43a05d76.html)