
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
@clarxai/mcp
Advanced tools
Clarx MCP server — score agent manifests, validate clarx-manifest.json, generate CI workflows, and (with a Clarx token) pull scan findings and remediation prompts into your IDE.
Clarx MCP server — score agent manifests (CLAUDE.md / AGENTS.md), validate clarx-manifest.json, and generate Clarx CI workflows directly from your coding agent (Cursor, Claude Code, Codex, Claude Desktop, Grok Build, …).
No account required. The core tools run entirely on your machine with the same rules as the Clarx manifest studio.
Recommended: set shared env once if you use hosted Clarx tools across multiple IDEs:
export CLARX_MCP_TOKEN="clarx_..."
export CLARX_API_URL="https://api.clarx.ai"
Add to your MCP client config (e.g. .cursor/mcp.json, claude_desktop_config.json):
{
"mcpServers": {
"clarx": {
"command": "npx",
"args": ["-y", "@clarxai/mcp@latest"]
}
}
}
Claude Code:
claude mcp add clarx -- npx -y @clarxai/mcp@latest
Codex:
codex mcp add clarx -- npx -y @clarxai/mcp@latest
If a GUI app does not inherit your shell env, use an inline env block in that client instead.
| Tool | What it does | Requires |
|---|---|---|
analyze_manifest | Score a CLAUDE.md / AGENTS.md (0–100, pillar scores, findings with line numbers) | — |
analyze_clarx_manifest | Validate clarx-manifest.json against the engine schema | — |
get_ci_workflow | Generate a GitHub Actions workflow that gates PRs on the Clarx score | — |
suggest_manifest_fix | AI-write one manifest section to close a finding | CLARX_MCP_TOKEN (hosted) or ANTHROPIC_API_KEY (BYOK) |
generate_manifest_draft | AI-draft a full manifest from your README | CLARX_MCP_TOKEN (hosted) or ANTHROPIC_API_KEY (BYOK) |
With CLARX_MCP_TOKEN, manifest AI runs on Clarx's servers (Pro: unlimited; Free: 10/mo). ANTHROPIC_API_KEY is an optional BYOK fallback.
analyze_manifest scores are manifest quality estimates — the same rules the manifest studio uses. They are not comparable to Clarx repo AI-readiness scores, which come from a full engine scan.
Create an API token in your Clarx Cloud org settings and set it as CLARX_MCP_TOKEN to unlock hosted manifest AI and scan data:
| Tool | What it does |
|---|---|
suggest_manifest_fix | Hosted AI section writes (included in token; uses manifest:ai scope) |
generate_manifest_draft | Hosted full manifest draft from README |
list_repos | Repositories the token can access, with latest AI-readiness scores |
get_scan | Latest scan summary, or full drill-down by scan_id |
list_findings | Findings + recommended actions from the latest scan (compact by default) |
get_remediation_prompt | The structured fix prompt behind "Copy AI prompt" — feed it straight to your agent (format: brief for the shorter fix brief, combine_all for everything at once) |
"env": {
"CLARX_MCP_TOKEN": "clarx_…"
}
Tokens are org-scoped with scoped permissions; the API enforces plan limits server-side.
FAQs
Clarx MCP server — score agent manifests, validate clarx-manifest.json, generate CI workflows, and (with a Clarx token) pull scan findings and remediation prompts into your IDE.
The npm package @clarxai/mcp receives a total of 121 weekly downloads. As such, @clarxai/mcp popularity was classified as not popular.
We found that @clarxai/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.