Agentβ™₯︎Age
Catalog

io.github.aryanspv/har-forensics-mcp

Official

by aryanspv

Audit a .har capture: third-party risk, leaked credentials, JWT checks, redaction. No network calls.

This MCP server audits a .har (HTTP Archive) capture to assess security concerns. It focuses on third-party risk evaluation, detection of leaked credentials, checks related to JWTs, and guidance for redaction. The server performs these analyses without making any network calls.

πŸ› οΈ Key Features

  • Audit .har capture files
  • Third-party risk assessment
  • Leaked credential detection
  • JWT checks
  • Redaction support
  • No network calls

πŸš€ Use Cases

  • Review captured browser/network traffic for sensitive data exposure
  • Validate JWT-related findings in HAR exports
  • Screen HAR files for third-party involvement and associated risk
  • Prepare data for safe sharing via redaction

⚑ Developer Benefits

  • Works offline (no network calls)
  • Provides deterministic analysis of a provided .har capture
  • Covers credential, JWT, and redaction-related audit needs in one workflow

⚠️ Limitations

  • Limited to analyzing .har captures (per provided description)
  • Does not perform network-based verification (explicitly β€œNo network calls”)
io.github.aryanspv/har-forensics-mcp - agentage MCP Catalog