{
  "markdown": "<div align=\"center\">\n\n# 🛡️ Emfirge\n\n## Git branch for your cloud.\n\n**Give your AI a read-only map of AWS. Trace attack paths, test a security fix on a cloned graph, and see the result before touching production.**\n\n[Get started][quickstart] · [Read the docs][docs] · [Open dashboard][dashboard] · [npm][npm]\n\n[![npm](https://img.shields.io/npm/v/@emfirge/mcp?style=flat-square&color=cb3837)](https://www.npmjs.com/package/@emfirge/mcp)\n[![CI](https://img.shields.io/github/actions/workflow/status/theanshsonkar/emfirge/ci.yml?branch=main&style=flat-square&label=CI)](https://github.com/theanshsonkar/emfirge/actions/workflows/ci.yml)\n[![MCP Registry](https://img.shields.io/badge/MCP_Registry-listed-5b5bd6?style=flat-square)][registry]\n[![License](https://img.shields.io/badge/License-BUSL_1.1-2563eb?style=flat-square)][license]\n\n</div>\n\n## Your scanner finds problems. Emfirge tests the fix.\n\nMost cloud tools hand you a list and ask you to trust the recommendation. Emfirge builds a connected graph of your account, forks it in memory, applies the proposed security change, re-runs the rules, and shows what got safer—or riskier.\n\n| 🕸️ See the path | 🎯 Find the chokepoint | 🧪 Rehearse the fix | 💬 Stay in your AI |\n|---|---|---|---|\n| Internet → compute → IAM → data | Prioritize what breaks the most attack paths | No write access. No production mutation. | Claude, Cursor, Kiro, Cline, Continue, Codex |\n\n<div align=\"center\">\n\n**~20 AWS service types · 58 graph-aware rules · 17 rule families · 7 MCP tools**\n\n</div>\n\n## Start in 30 seconds\n\n```bash\nnpx @emfirge/mcp install\n```\n\nThen ask your assistant:\n\n```text\nScan my AWS account using role\narn:aws:iam::123456789012:role/EmfirgeReadOnly in us-east-1\n```\n\nNo role yet? Say **“help me set up Emfirge.”** You will get a one-click CloudFormation link for a read-only IAM role.\n\n> **Try it now with no setup:** use demo role `arn:aws:iam::194722410583:role/EmfirgeReadOnly` in `us-east-1`.\n\n**Free:** 5 scans per AWS account per day. No signup. No API key.\n\n## Ask questions your cloud can finally answer\n\n```text\nShow me the worst attack path from the internet.\nWhat is the blast radius if this instance is compromised?\nWhich resource should I fix first?\nWill closing SSH remove the path without adding new security findings?\nCheck this account against CIS AWS Foundations 1.5.\n```\n\n## One graph. Seven tools.\n\n| Tool | Answer |\n|---|---|\n| `emfirge_scan` | What does my AWS risk look like? |\n| `emfirge_get_findings` | What is wrong and how do I fix it? |\n| `emfirge_attack_paths` | How could an attacker reach my data? |\n| `emfirge_verify_fix` | What changes if I apply this security fix? |\n| `emfirge_simulate_breach` | What happens after this resource is compromised? |\n| `emfirge_check_compliance` | Which CIS AWS 1.5 or SOC 2 controls fail? |\n| `emfirge_setup_help` | How do I create the read-only role? |\n\n## Proof, not a prompt\n\n```text\nScan AWS → build graph → fork graph → apply mutation → re-run rules → show delta\n```\n\nThe score, findings, attack paths, and fix verification come from deterministic graph analysis—not an LLM guessing what might happen. Your AI explains the evidence; Emfirge produces it.\n\n## Built for trust\n\n- **Read-only AWS access** through a role you own and can revoke anytime.\n- **One-hour STS credentials** protected by an ExternalId and never stored.\n- **Local tokenization** of recognized AWS identifiers before MCP results reach your LLM in strict mode.\n- **No production changes** during scans, breach simulations, or fix verification.\n- **Source available** for the MCP, scanner engine, rules, scoring, and docs.\n\n> Emfirge proves the simulated **security** delta against your latest scan; it does not yet prove application connectivity. Some graph-derived labels may also remain visible in strict mode. See [How it works][how-it-works] and [Privacy][privacy] for the exact boundaries.\n\n## Go deeper when you are ready\n\n[Quickstart][quickstart] · [How the fork works][how-it-works] · [MCP tools][tools] · [Privacy][privacy] · [Security][security] · [Self-hosting][self-hosting] · [Contributing][contributing]\n\n---\n\n<div align=\"center\">\n\n### Stop guessing in production.\n\n**Fork the graph. Follow the path. Prove the security delta.**\n\n[Install Emfirge][quickstart] · [Star the repo][repo]\n\n</div>\n\n[repo]: https://github.com/theanshsonkar/emfirge\n[docs]: https://emfirge.cloud/docs\n[quickstart]: https://emfirge.cloud/docs/quickstart\n[dashboard]: https://app.emfirge.cloud\n[npm]: https://www.npmjs.com/package/@emfirge/mcp\n[registry]: https://registry.modelcontextprotocol.io/v0.1/servers?search=io.github.theanshsonkar/emfirge\n[license]: https://github.com/theanshsonkar/emfirge/blob/main/LICENSE\n[how-it-works]: https://emfirge.cloud/docs/how-it-works\n[tools]: https://emfirge.cloud/docs/tools\n[privacy]: https://emfirge.cloud/docs/privacy\n[security]: https://emfirge.cloud/docs/security\n[self-hosting]: https://emfirge.cloud/docs/self-host\n[contributing]: https://github.com/theanshsonkar/emfirge/blob/main/CONTRIBUTING.md\n",
  "bytes": 5030,
  "sha": "46dea1ed7a2333b9b323ee74b0ac0326e5fb9c4ac918bd65456e62a3d45c8252",
  "repo_slug": "theanshsonkar/emfirge",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_theanshsonkar_emfirge_05b87c9f/readme"
}