🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@emfirge/mcp

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@emfirge/mcp

Git branch for your cloud. Understand AWS risk, prioritize what matters, and prove fixes before touching production. Read-only by design.

latest
Source
npmnpm
Version
0.2.1
Version published
Maintainers
1
Created
Source

🛡️ Emfirge

Privacy-first AWS security, inside your AI.

Trace attack paths from the internet to your sensitive data, calculate blast radius, and prove fixes before you apply them — without your resource IDs ever reaching the LLM.

Website · Source · MCP Registry · Privacy · Report an issue

npm MCP Registry License: BUSL 1.1 node

Your AI can read your code, but it can't see your cloud. Emfirge fixes that. It scans your live AWS account, builds a graph of every resource and how they connect, then lets your assistant walk attack paths, simulate breaches, and verify fixes — all from a conversation.

The AI never guesses. Emfirge clones your infrastructure graph, applies the change, and re-runs 58 deterministic rules. Your assistant reads back what the engine proved.

🕸️ Graph-basedMaps every AWS resource and relationship — not isolated resource linting like Checkov/tfsec.
🎯 Attack pathsWeighted-Dijkstra routes from the internet to your data, ranked by exploit difficulty, not hop count.
💥 Blast radiusSee exactly what an attacker reaches once they land on a resource.
🔒 Privacy-firstResource IDs are tokenized on your machine before anything reaches the LLM. The mapping never leaves.
Proven fixesClone the graph → apply the change → re-run every rule → diff. A real simulation, not a hunch.
📋 ComplianceCIS AWS Foundations 1.5 + SOC 2, per-control pass/fail, mapped to MITRE ATT&CK.

Install (30 seconds)

npx @emfirge/mcp install

Auto-detects and wires up Claude Desktop, Cursor, Kiro, Cline, Continue, and Codex CLI, then asks you to pick a privacy mode. Restart your client and just ask:

"Scan my AWS account, role arn:aws:iam::123456789012:role/EmfirgeReadOnly, region us-east-1"

No role yet? Say "help me set up Emfirge" — your assistant hands you a one-click CloudFormation deploy link for a read-only IAM role.

Free. 5 scans/day per AWS account. No signup. No API keys.

Try it with zero setup

Use the demo ARN — fake infrastructure, the real engine:

arn:aws:iam::194722410583:role/EmfirgeReadOnly    region: us-east-1

"Scan with arn:aws:iam::194722410583:role/EmfirgeReadOnly in us-east-1"

Want a visual graph instead? emfirge.cloud — same engine, browser UI, free during beta.

What your AI gets

ToolWhat it does
emfirge_setup_helpReturns a clickable CloudFormation deploy link (for first-time setup).
emfirge_scanScan an AWS account — returns risk score, finding counts, and an analysis_id.
emfirge_get_findingsFull findings list for a scan, filterable by severity.
emfirge_attack_pathsAttack paths from the internet to internal resources, plus chokepoints.
emfirge_verify_fixSimulate a fix and see the real score delta — no changes to your AWS.
emfirge_check_complianceCIS AWS Foundations / SOC 2 per-control status.
emfirge_simulate_breachFull kill-chain walkthrough — attack stages, blast radius, follow-up moves.

All seven tools are deterministic on the backend — no LLM calls inside the MCP path. Your host LLM (Claude / Cursor / etc.) is the only AI in the loop, and in strict mode it only ever sees tokenized data.

Privacy by default

In strict mode (the default), every AWS identifier is tokenized locally before it reaches your LLM:

What the LLM sees:    "SG_001 has SSH open → reaches S3_001"
What's on your disk:  SG_001 = sg-0a1b2c3d
                      S3_001 = acme-customer-pii

The mapping lives at ~/.emfirge/tokens.json and is never sent to Emfirge, Anthropic, or anyone. When you say "fix SG_001", the MCP resolves the real ID locally, calls the backend, and re-tokenizes the response.

ModeWhat's tokenizedBest for
strict (default)Every AWS ID — ARNs, EC2/SG/IAM/S3, IPs, account IDs, bucket namesBanks, healthcare, regulated industries
balancedARNs, EC2/SG/EIP/IAM IDs, IPs, account IDs. Subnets/VPCs/volumes raw.Most users
offNothing — raw IDs go to the LLMPersonal accounts, demo, debugging
npx @emfirge/mcp privacy strict|balanced|off   # change mode across every wired client
npx @emfirge/mcp privacy                        # show current mode

Honest note: tokenization sits between the MCP and the LLM. The Emfirge backend does receive real IDs — it has to, to call AWS. It stores them for 90 days, then auto-deletes. Full details in PRIVACY.md. Wipe everything anytime with npx @emfirge/mcp purge --role-arn <ARN>.

How it works

┌──────────────┐   role ARN    ┌──────────────┐  read-only   ┌─────┐
│ Your machine │──────────────▶│ emfirge.cloud│─────────────▶│ AWS │
│  (MCP host)  │               │   (scanner)  │  STS, 1 hr   └─────┘
└──────┬───────┘               └──────┬───────┘
       │ tokenized IDs                │ findings + graph
       ▼                              ▼
┌──────────────┐               ┌──────────────┐
│  Your LLM    │               │ Postgres + S3│
│ (Claude/etc) │               │  (90-day TTL)│
└──────────────┘               └──────────────┘
  • You ask your AI to scan. The MCP calls the backend with your read-only role ARN.
  • The backend assumes the role (1-hour STS token, ExternalId-scoped), maps ~20 AWS services, builds the graph, runs the rules, and returns findings.
  • The MCP tokenizes every resource ID locally, then hands the safe version to your LLM.
  • Your assistant reasons over it — attack paths, fixes, compliance — and you never leave the chat.

Under the hood

  • Weighted Dijkstra attack paths — edges weighted by exploit difficulty (0 = metadata, 1 = trivial network reach, 3 = needs a shell). A 5-hop trivial path ranks more dangerous than a 2-hop credential theft.
  • Brandes' betweenness centrality — finds chokepoint nodes where hardening one resource kills the most attack paths at once.
  • Deterministic fix simulator — graph mutation + full rule re-run, no LLM in the verification path. Proof, not a guess.
  • 58 graph-aware rules across 17 families with context-aware severity — SSH-open behind an ALB drops Critical → Low; public S3 with CloudFront drops Critical → Low.
  • Deterministic 0–100 score — higher is safer, normalized by account size, across four dimensions (security, availability, cost, disaster recovery). No LLM in the scoring path.
  • 9 toxic-combo patterns — multi-signal pairs like public RDS + no CloudTrail that are safe on their own but dangerous together.

Coverage: EC2, Lambda, ECS, S3, EBS, RDS, IAM, Secrets Manager, KMS, VPC, Security Groups, WAF, CloudFront, SNS, CloudTrail, GuardDuty, CloudWatch, AWS Config, Budgets — ~20 service types across 17 rule families.

Manual configuration

If auto-install doesn't work, add this to your client's MCP config:

{
  "mcpServers": {
    "emfirge": {
      "command": "npx",
      "args": ["-y", "@emfirge/mcp"],
      "env": { "EMFIRGE_PRIVACY": "strict" }
    }
  }
}

Config file locations:

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.json (Mac), %APPDATA%\Claude\claude_desktop_config.json (Windows)
  • Cursor~/.cursor/mcp.json
  • Kiro~/.kiro/settings/mcp.json
  • Cline~/Library/Application Support/Cline/cline_mcp_settings.json
  • Continue~/.continue/config.json

MCP requires a desktop AI client (stdio transport). Web Claude / ChatGPT / Gemini don't support MCP yet — use emfirge.cloud for those.

CLI

npx @emfirge/mcp install                         # auto-wire to all detected clients
npx @emfirge/mcp install --privacy=balanced      # non-interactive: skip the prompt
npx @emfirge/mcp uninstall                        # remove from all clients
npx @emfirge/mcp status                           # show what's wired up + privacy mode
npx @emfirge/mcp privacy <strict|balanced|off>    # change privacy mode everywhere
npx @emfirge/mcp tokens                           # list local token mappings
npx @emfirge/mcp purge --role-arn <ARN>           # delete all your scan data

Environment variables

VariableDefaultPurpose
EMFIRGE_BASE_URLhttps://emfirge.cloud/apiBackend URL — override to point at a self-hosted backend
EMFIRGE_PRIVACYstrictstrict, balanced, or off
EMFIRGE_TRUSTED_ACCOUNT_ID282027772803AWS account ID to trust in the IAM role (for setup_help)
EMFIRGE_EXTERNAL_IDaws-risk-agentExternalId for STS assume-role

Security model

  • Read-only IAM role — zero write permissions.
  • ExternalId — prevents confused-deputy attacks.
  • Scoped trust — only Emfirge's AWS account can assume the role.
  • STS temporary credentials — expire in 1 hour, never stored.
  • Instant revoke — delete the CloudFormation stack and all access is gone.

License

BUSL 1.1 — free for non-production and small production use (up to $1M ARR or 100 employees). Auto-converts to Apache 2.0 in 2030.

See your cloud the way an attacker does — from inside your AI.

Website · Source · MCP Registry

Keywords

mcp

FAQs

Package last updated on 16 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts