@mtford/httap
npm
v0.9.0
Published by @mtford — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
Terminal HTTP interception toolkit
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 7 = 93. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`dist/cli/tui/utils/clipboard.js:4`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; /** * Copy text to the system clipboard. * Uses pbcopy on macOS, xclip on Linu
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/cli/tui/utils/clipboard.js
In the server's implementation (`dist/cli/tui/utils/open-external.js:9`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; const TEMP_DIR_NAME = "httap-exports"; /** * Get the platform-specific command
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/cli/tui/utils/open-external.js
In the server's implementation (`dist/cli/tui/utils/terminal-size.js:2`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: spawnSync } from "node:child_process"; function isPositiveInteger(value) { return typeof value === "number" && Numb
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/cli/tui/utils/terminal-size.js
In the server's implementation (`dist/shared/browser.js:10`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ecFileSync } from "node:child_process"; // ── Constants ────────────────────────────────────────────────────────────────
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/shared/browser.js
In the server's implementation (`dist/shared/daemon.js:3`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; import { fileURLToPath } from "node:url"; import { getHttapPaths, readDaemonPid,
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/shared/daemon.js
In the server's implementation (`dist/shared/process-name.js:5`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ecFileSync } from "node:child_process"; import * as path from "node:path"; const PROCESS_NAME_TIMEOUT_MS = 1000; /** *
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/shared/process-name.js
Untrusted-input tools ([httap_list_requests, httap_get_request]) co-exist with external-action tools ([httap_list_requests, httap_get_request, httap_count_requests, httap_clear_requests, httap_replay_request, httap_save_request, httap_unsave_request]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [httap_list_requests, httap_get_request] → sinks [httap_list_requests, httap_get_request, httap_count_requests, httap_clear_requests, httap_replay_req
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow httap_list_requests → httap_list_requests
In the server's implementation (`dist/daemon/interceptor-loader.js:123`): Loading a module chosen at runtime (from a variable) can pull in and run attacker-influenced code paths. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: const mod = await jiti.import(filePath); const { interceptors: extracted, errors } = extractInterceptor
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/daemon/interceptor-loader.js
In the server's implementation (`dist/overrides/node.js:51`): Loading a module chosen at runtime (from a variable) can pull in and run attacker-influenced code paths. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: " var mod = require(modName);", " var origRequest = mod.request;", " mod.request =
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/overrides/node.js
Each tool and what it can reach — statically extracted from the published source.
httap_get_requestingests untrusted inputnetwork egresshttap_list_requestsingests untrusted inputnetwork egresshttap_clear_requestsnetwork egresshttap_count_requestsnetwork egresshttap_replay_requestnetwork egresshttap_save_requestnetwork egresshttap_unsave_requestnetwork egresshttap_delete_interceptorno sensitive capabilityhttap_get_interceptor_eventsno sensitive capabilityhttap_get_statusno sensitive capabilityhttap_list_interceptorsno sensitive capabilityhttap_list_sessionsno sensitive capabilityhttap_query_jsonno sensitive capabilityhttap_reload_interceptorsno sensitive capabilityhttap_search_bodiesno sensitive capabilityhttap_write_interceptorno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.9.0 latest |
A 93/100 | 9 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @mtford/httap --online
Model Context Protocol (MCP) server that integrates AgentQL data extraction capabilities.
Screenshot any URL or HTML as PNG/JPEG/WebP from your AI agent. Full-page, clean, no install.
MCP server for aria51 accessibility scanner
Bridge any browser web app to Claude Code via MCP
Browserbase’s official MCP server: cloud headless browsers for agents, with sessions and screenshots.
MCP server for AI web browser automation using Browserbase and Stagehand