Serveur MCP

HALLUX

dev.blvkware/hallux
Outils développeur Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Verifies package, module, DOI, install command, and dependency manifest identifiers, and can monitor identifiers for later status changes.

hallux_check
Check identifiers
Does this identifier actually exist? Call before acting on any name you recalled rather than read: a package to install, a module to import, a DOI to cite. Returns one of: exists, deprecated, absent, phantom, squat, unknown. exists - proceed deprecated - proceed, but use `successor` absent - not in the registry. Do not proceed phantom - does not exist AND models repeatedly invent it. Do not proceed squat - was invented by models, then registered by someone. Treat as hostile unknown - could not verify. Never treat this as permission Live namespaces: cite.doi, pkg.crates, pkg.go, pkg.maven, pkg.npm, pkg.nuget, pkg.pypi. An unsupported namespace returns `unknown`, never an error, so it is safe to ask.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['identifiers'], 'properties': {'identifiers': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value'], 'properties': {'value': {'type': 'string', 'description': 'The identifier exactly as written, e.g. requests, @types/node, github.com/spf13/cobra, 10.1038/nature12373.'}, 'namespace': {'enum': ['cite.doi', 'pkg.crates', 'pkg.go', 'pkg.maven', 'pkg.npm', 'pkg.nuget', 'pkg.pypi'], 'type': 'string', 'description': 'Where the identifier lives: pkg.npm, pkg.pypi, pkg.crates, pkg.go, pkg.maven or pkg.nuget for a package, cite.doi for a DOI.'}}}, 'maxItems': 100, 'description': 'Up to 100 identifiers.'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', 'required': ['decision', 'safeToProceed', 'results'], 'properties': {'blocked': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'The absent, phantom and squat results.'}, 'checked': {'type': 'integer', 'minimum': 0, 'description': 'How many identifiers were checked.'}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'Every result, in input order.'}, 'decision': {'enum': ['PROCEED', 'REVIEW', 'BLOCK', 'NOTHING_TO_CHECK'], 'type': 'string', 'description': 'BLOCK: do not proceed. REVIEW: something could not be verified. PROCEED: every identifier exists. NOTHING_TO_CHECK: no identifier was recognised.'}, 'unverified': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'The unknown results.'}, 'safeToProceed': {'type': 'boolean', 'description': 'False whenever anything was blocked.'}}}
hallux_check_command
Check an install command before running it
Call this BEFORE running any command that installs a dependency: npm, yarn, pnpm, bun, pip, uv, poetry, pipx, cargo, go get, dotnet add package, nuget. Language models invent plausible package names that have never existed, and attackers register those names because they can predict them. Installing one runs attacker code. You cannot tell the difference by looking at the name, which is why this check exists. Pass the command exactly as you intend to run it. The identifiers are extracted for you. If the result says BLOCK, do not run the command. Use the `successor` if one is given, otherwise tell the user what was found and stop.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['command'], 'properties': {'command': {'type': 'string', 'description': 'The shell command, verbatim. Example: pip install requests requests-oauth2-helper'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', 'required': ['decision', 'safeToProceed', 'results'], 'properties': {'blocked': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'The absent, phantom and squat results.'}, 'checked': {'type': 'integer', 'minimum': 0, 'description': 'How many identifiers were checked.'}, 'command': {'type': 'string', 'description': 'The command as received.'}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'Every result, in input order.'}, 'decision': {'enum': ['PROCEED', 'REVIEW', 'BLOCK', 'NOTHING_TO_CHECK'], 'type': 'string', 'description': 'BLOCK: do not proceed. REVIEW: something could not be verified. PROCEED: every identifier exists. NOTHING_TO_CHECK: no identifier was recognised.'}, 'unverified': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'The unknown results.'}, 'safeToProceed': {'type': 'boolean', 'description': 'False whenever anything was blocked.'}, 'identifiersFound': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value'], 'properties': {'value': {'type': 'string'}, 'namespace': {'type': 'string'}}}, 'description': 'The identifiers read off the command.'}}}
hallux_check_manifest
Check a dependency file
Call this after writing or editing a dependency file, and before committing it. Supported: package.json, requirements.txt, pyproject.toml, Cargo.toml, go.mod. Checks every dependency in one pass, including dev and optional groups, which is where an invented name usually arrives.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['filename', 'content'], 'properties': {'content': {'type': 'string', 'description': 'The file contents.'}, 'filename': {'type': 'string', 'description': 'The file name, e.g. package.json. Path is ignored; only the name is used to pick a parser.'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', 'required': ['decision', 'safeToProceed', 'results'], 'properties': {'blocked': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'The absent, phantom and squat results.'}, 'checked': {'type': 'integer', 'minimum': 0, 'description': 'How many identifiers were checked.'}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'Every result, in input order.'}, 'decision': {'enum': ['PROCEED', 'REVIEW', 'BLOCK', 'NOTHING_TO_CHECK'], 'type': 'string', 'description': 'BLOCK: do not proceed. REVIEW: something could not be verified. PROCEED: every identifier exists. NOTHING_TO_CHECK: no identifier was recognised.'}, 'filename': {'type': 'string', 'description': 'The file name as received.'}, 'unverified': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'verdict', 'confidence'], 'properties': {'value': {'type': 'string', 'description': 'The identifier checked.'}, 'reason': {'type': 'string', 'description': 'Why the verdict is unknown.'}, 'verdict': {'enum': ['exists', 'deprecated', 'absent', 'phantom', 'squat', 'unknown'], 'type': 'string', 'description': 'exists and deprecated may proceed; absent, phantom and squat must not; unknown is never permission.'}, 'evidence': {'type': 'object', 'description': 'What the verdict rests on: registry status and time, attestations, model families, nearest existing names.'}, 'namespace': {'type': 'string', 'description': 'The namespace checked.'}, 'successor': {'type': 'string', 'description': 'The name to use instead, when one is known.'}, 'confidence': {'type': 'number', 'maximum': 1, 'minimum': 0}, 'recommendation': {'type': 'string', 'description': 'What to do next.'}}}, 'description': 'The unknown results.'}, 'safeToProceed': {'type': 'boolean', 'description': 'False whenever anything was blocked.'}}}
hallux_watch
Be told if a name turns hostile later
Register identifiers for notification when their verdict changes. The transition that matters is phantom to squat: a name models invent that somebody then registers. Use this for a dependency that came back `absent` or `phantom` and that the user intends to use anyway, or for a set of dependencies worth monitoring. Delivered by signed webhook to a URL you supply.
Accès externe
Schéma d’entrée
{'type': 'object', 'required': ['identifiers', 'callbackUrl'], 'properties': {'callbackUrl': {'type': 'string', 'description': 'An https URL to POST transitions to.'}, 'identifiers': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value'], 'properties': {'value': {'type': 'string', 'description': 'The identifier exactly as written, e.g. requests, @types/node, github.com/spf13/cobra, 10.1038/nature12373.'}, 'namespace': {'enum': ['cite.doi', 'pkg.crates', 'pkg.go', 'pkg.maven', 'pkg.npm', 'pkg.nuget', 'pkg.pypi'], 'type': 'string', 'description': 'Where the identifier lives: pkg.npm, pkg.pypi, pkg.crates, pkg.go, pkg.maven or pkg.nuget for a package, cite.doi for a DOI.'}}}, 'maxItems': 100, 'description': 'Up to 100 identifiers to watch, typically ones that came back absent or phantom.'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', 'required': ['decision', 'registered'], 'properties': {'event': {'type': 'string'}, 'decision': {'enum': ['WATCHING'], 'type': 'string'}, 'signature': {'type': 'object', 'properties': {'format': {'type': 'string'}, 'header': {'type': 'string'}}}, 'registered': {'type': 'array', 'items': {'type': 'object', 'required': ['namespace', 'value', 'watched'], 'properties': {'value': {'type': 'string'}, 'reason': {'type': 'string'}, 'watchId': {'type': 'string'}, 'watched': {'type': 'boolean'}, 'namespace': {'type': 'string'}, 'signingSecret': {'type': 'string', 'description': 'Verifies the webhook signature.'}}}}, 'transitionOfInterest': {'type': 'string'}}}
Ajouté
hallux_watch
24 September 2026 02:40
Ajouté
hallux_check_manifest
24 September 2026 02:40
Ajouté
hallux_check
24 September 2026 02:40
Ajouté
hallux_check_command
24 September 2026 02:40

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…