
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@clarxai/mcp
Advanced tools
Clarx MCP server — score agent manifests, validate clarx-manifest.json, and generate CI workflows from your IDE. Set CLARX_MCP_TOKEN to unlock hosted scan data (coming soon).
Clarx MCP server — score agent manifests (CLAUDE.md / AGENTS.md), validate clarx-manifest.json, and generate Clarx CI workflows directly from your coding agent (Cursor, Claude Code, Claude Desktop, Windsurf, …).
No account required. The core tools run entirely on your machine with the same rules as the Clarx manifest studio.
Add to your MCP client config (e.g. .cursor/mcp.json, claude_desktop_config.json):
{
"mcpServers": {
"clarx": {
"command": "npx",
"args": ["-y", "@clarxai/mcp@latest"]
}
}
}
Claude Code:
claude mcp add clarx -- npx -y @clarxai/mcp@latest
| Tool | What it does | Requires |
|---|---|---|
analyze_manifest | Score a CLAUDE.md / AGENTS.md (0–100, pillar scores, findings with line numbers) | — |
analyze_clarx_manifest | Validate clarx-manifest.json against the engine schema | — |
get_ci_workflow | Generate a GitHub Actions workflow that gates PRs on the Clarx score | — |
suggest_manifest_fix | AI-write one manifest section to close a finding | ANTHROPIC_API_KEY |
generate_manifest_draft | AI-draft a full manifest from your README | ANTHROPIC_API_KEY |
The AI tools are bring-your-own-key: set ANTHROPIC_API_KEY in the server env and they register automatically; without it they stay out of your agent's context.
analyze_manifest scores are manifest quality estimates — the same rules the manifest studio uses. They are not comparable to Clarx repo AI-readiness scores, which come from a full engine scan.
Setting CLARX_MCP_TOKEN will unlock hosted tools — scan results, findings, and remediation prompts from your Clarx Cloud dashboard. Not available in this version.
FAQs
Clarx MCP server — score agent manifests, validate clarx-manifest.json, generate CI workflows, and (with a Clarx token) pull scan findings and remediation prompts into your IDE.
The npm package @clarxai/mcp receives a total of 121 weekly downloads. As such, @clarxai/mcp popularity was classified as not popular.
We found that @clarxai/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.