Back to Directory/Developer Tools

io.github.flagrix-io/flagrix

Scan GitHub repos and profiles for malware before cloning — commit-pinned risk verdicts for agents

Developer ToolsJavaScriptv0.1.0

flagrix

Scan GitHub repositories and profiles for malware before you clone — from the terminal, CI, or an AI agent. The same commit-pinned verdict as the Flagrix browser extension, made callable.

npx flagrix scan https://github.com/some-org/coding-assignment
  some-org/coding-assignment @ 3f9c2a1
  HIGH RISK — Do not clone  security score 12/100
  3 files scanned · 10 dependencies · 2 issues

  CRITICAL Data exfiltration patterns detected: Keylogger Pattern
    assignment.js:14
      14  document.addEventListener("keydown", (e) => send(e.key))

Built after real fake-recruiter campaigns ("coding assignment" repos that steal wallets, SSH keys, and browser sessions) started targeting developers.

Commands

flagrix scan <url | owner/repo>   # scan a repository (--ref <branch|sha>)
flagrix scan-user <username>      # score a GitHub profile for scam signals
flagrix mcp                       # MCP server (stdio) for AI agents

Exit codes

codemeaning
0low risk
1scan failed
2medium risk — review before proceeding
3high risk — do not clone

--json (automatic when stdout is piped) emits the full result. The verdict is pinned to the scanned commit (commitSha in the JSON): every file is read at that SHA, so a push mid-scan or after the verdict can't silently invalidate it.

AI agents

claude mcp add flagrix -- npx -y flagrix mcp

Tools: scan_github_repo, scan_github_user. A Claude Code hook that gates every git clone on a scan ships in hooks/ — see docs/agent-gating.md.

Tokens & rate limits

Unauthenticated scans use GitHub's 60 req/h budget (a scan issues one request per scanned file, up to ~50). Set GITHUB_TOKEN (or FLAGRIX_GITHUB_TOKEN, or --token) to raise it to 5,000/h and to scan private repositories.

Privacy

Fully local. No telemetry, no accounts, no Flagrix backend — the only network calls go to the GitHub/npm APIs and the public detection-rules repository (signature refresh, cached 6 h, with a bundled offline snapshot).

How it works

Scanning logic lives in @flagrix/scanner-core (MIT), signatures in flagrix-detection-rules (MIT) — the same engine and rules the browser extension uses. Verdicts are risk assessments, not definitive fraud determinations; always verify through official channels.

AI Disclosure

This project leverages Claude AI for boilerplate generation, test-suite expansion, and optimization. All AI-generated code is strictly reviewed, refactored, and verified by human maintainers before merging.

License

MIT — see LICENSE.

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y flagrix

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-flagrix-io-flagrix": {
      "command": "npx",
      "args": [
        "-y",
        "flagrix"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

flagrixnpm

Compatible MCP Clients

io.github.flagrix-io/flagrix works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More