git clone https://github.com/aryanspv/har-forensics-mcp my-project && cd my-projectTemplates overview
# har-forensics-mcp
Audit a `.har` capture from inside your editor. Third-party blast radius, leaked
credentials, JWT forensics, CSP generation, and redaction — as MCP tools.
Reads a file from local disk, computes, writes to stdout. **It makes no network
calls**, which is the point: a real capture holds live session cookies,
`Authorization` headers, and sometimes card numbers.
Works with anything that speaks MCP over stdio — Cursor, Claude Code, Windsurf,
Zed, VS Code Copilot.
## Setup
**Claude Code:**
```bash
claude mcp add har-forensics -- npx -y har-forensics-mcp
```
**Cursor** — `.cursor/mcp.json` in the project, or `~/.cursor/mcp.json` globally:
```json
{
"mcpServers": {
"har-forensics": {
"command": "npx",
"args": ["-y", "har-forensics-mcp"]
}
}
}
```
**Windsurf / Zed / VS Code Copilot** take the same `command` + `args` shape in
their own MCP config files.
Restart the editor, then point a tool at a capture:
> Run `analyze_har` on `~/Downloads/checkout.har`
Requires Node 20+. Nothing else — no clone, no build, no API key, no account.
## Tools
| Tool | Answers |
| --- | --- |
| `analyze_har` | "What's in this capture?" — triage overview, one verdict per check. **Start here.** |
| `har_brief` | The full audit as redacted markdown. The artifact to quote or paste. |
| `har_findings` | Findings, filterable by severity. |
| `har_vendors` | Every third party, scored 0–100 by blast radius, with an HTTP Archive scrutiny tier. |
| `har_csp` | A starter Content-Security-Policy synthesized from observed traffic. |
| `har_hunt` | Query requests — `is:thirdparty`, `status:404`, `type:script`, `host:…`. |
| `sanitize_har` | Write a `.redacted.har` safe to attach to a ticket. |
## Three properties it inherits from the web app
**No network.** The analyzers contain no `fetch`, and this transport does not add
one. That invariant is the product — Cloudflare shipped a DLP profile in March
2026 that detects HAR files in HTTP traffic and lets admins block the upload
outright, because unsanitized HARs are a known credential-exfiltration path.
**Summaries, never dumps.** Every tool returns a rendered conclusion, not raw
entries. The captures this exists for run to tens of thousands of entries and
hundreds of megabytes; handing an agent the entry list would blow its context and
make it slower at a job the analyzers already did.
**Redacted by default.** `har_brief` and `har_findings` route through the same
redactor the browser export uses, built from a single shared secret-pattern
table. An agent reading a capture in an editor is *more* likely to paste a
finding into a chat window than a human with a download folder.
## What it will not do
- **Overwrite anything.** `sanitize_har` refuses to write over an existing target
or the original capture.
- **Read a file above 512 MB.** Guarded rather than left to OOM.
- **Judge time against your clock.** A HAR is a historical artifact, so token
expiry is measured against each entry's `startedDateTime`. Comparing to `now`
marks every token in a week-old capture as expired and buries the one that was
genuinely dead when the browser sent it.
## Reading the code
This package ships one file, `dist/server.js`. It is deliberately not
minified — the build treats it as something a human debugging an editor
integration will read far more often than something a machine will parse for
size — so it is the same code a build would produce, already built. There is
no separate source repository to clone; the shipped file is the artifact to
audit.
## License
MIT. Bundled vendor data is generated from
[`third-party-web`](https://github.com/patrickhulce/third-party-web) — MIT,
Copyright (c) 2017 Patrick Hulce, derived from HTTP Archive.
What people ask about har-forensics-mcp
What is aryanspv/har-forensics-mcp?
+
aryanspv/har-forensics-mcp is templates for the Claude AI ecosystem with 1 GitHub stars.
How do I install har-forensics-mcp?
+
You can install har-forensics-mcp by cloning the repository (https://github.com/aryanspv/har-forensics-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is aryanspv/har-forensics-mcp safe to use?
+
aryanspv/har-forensics-mcp has not been audited yet by our security agent. Review the original repository on GitHub before using it in production.
Who maintains aryanspv/har-forensics-mcp?
+
aryanspv/har-forensics-mcp is maintained by aryanspv. The last recorded GitHub activity is from today, with 0 open issues.
Are there alternatives to har-forensics-mcp?
+
Yes. On ClaudeWave you can browse similar templates at /categories/templates, sorted by popularity or recent activity.
Deploy har-forensics-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/aryanspv-har-forensics-mcp)<a href="https://claudewave.com/repo/aryanspv-har-forensics-mcp"><img src="https://claudewave.com/api/badge/aryanspv-har-forensics-mcp" alt="Featured on ClaudeWave: aryanspv/har-forensics-mcp" width="320" height="64" /></a>More Templates
CLI tool for configuring and monitoring Claude Code
AWS AI Stack – A ready-to-use, full-stack boilerplate project for building serverless AI applications on AWS
Scaffold production-ready full-stack apps in TypeScript, Rust, Python, Go, and Java with a visual builder and CLI. Choose your frontend, backend, database, auth, AI, payments, and DevOps integrations, all wired together.
From Claude Artifact to deployable React app — in seconds!
CLAUDE.md best practices
A complete operating system for Claude that prevents context loss and makes multi-session work reliable