New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@flarewatch/mcp

Package Overview
Dependencies
Maintainers
1
Versions
6
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@flarewatch/mcp

stdio→HTTPS bridge for the FlareWatch MCP server. Lets stdio-only MCP clients (Claude Desktop, Cursor, etc.) attach via `npx @flarewatch/mcp`.

Source
npmnpm
Version
0.1.2
Version published
Weekly downloads
27
12.5%
Maintainers
1
Weekly downloads
 
Created
Source

@flarewatch/mcp

stdio→HTTPS bridge for the FlareWatch MCP server.

Lets stdio-only MCP clients (Claude Desktop, Cursor, Continue) reach the remote endpoint at https://mcp.flarewatch.io/api/mcp without each client having to implement the Streamable HTTP transport.

Install / use

No install needed — npx will fetch on demand:

npx -y @flarewatch/mcp

Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "flarewatch": {
      "command": "npx",
      "args": ["-y", "@flarewatch/mcp"]
    }
  }
}

Restart Claude Desktop. The 13 FlareWatch tools (validators, FTSO providers, scoring methodology, agent transparency, etc.) become available in every conversation.

Cursor

Cursor supports Streamable HTTP natively — you don't need this bridge. Configure directly:

{
  "url": "https://mcp.flarewatch.io/api/mcp"
}

Continue.dev

{
  "experimental": {
    "modelContextProtocolServers": [
      {
        "transport": { "type": "stdio", "command": "npx", "args": ["-y", "@flarewatch/mcp"] }
      }
    ]
  }
}

Environment overrides

VariableDefaultPurpose
FLAREWATCH_MCP_URLhttps://mcp.flarewatch.io/api/mcpEndpoint to forward to. Useful for preview deploys or local dev.
FLAREWATCH_MCP_TIMEOUT_MS30000Per-request HTTP timeout in ms.

What this bridge does NOT do

It's intentionally dumb. ~150 LoC. The server is the single source of truth for:

  • Tool definitions
  • Resource content
  • Rate limiting
  • Quarantine / honeypot / classifier walls
  • Response signing

The bridge just forwards JSON-RPC frames between stdio and HTTPS. No caching, no retries, no fallback. If the remote endpoint is down, the bridge surfaces the upstream error rather than attempting recovery.

Verification

Every tool response carries a verification_signature HMAC. To verify a citation came from this server, call the verify_response tool with the cited payload + signature.

Keywords

mcp

FAQs

Package last updated on 02 Jun 2026

Related posts