Finds the leaked tokens in a .har capture, scores every third party by how much damage it could do, and writes a redacted copy safe to attach to a ticket. Local only, no network calls.
npm · fingerprint de15f0deae1ac7fb34318238 · repository · RSS
Nothing, since tracking began. That is the good outcome, and it is what most servers look like.
If you run this server, put the proxy in front of it. It pins these exact fingerprints on first connect and stops the session if they move.
npx --yes mcp-pin@0.1.0 -- <your har-forensics-mcp command>Or subscribe to this page's RSS feed to be told when it changes.
The badge states one fact about time and nothing else. It never claims a server is safe.
[](https://mcp-pin.gautamkhosla.com/servers/951d474e43a05d76.html)