Hibp MCP server
A Model Context Protocol (MCP) server for the Have I Been Pwned (HIBP) API
B83/100grade B
Adoption
Growing
5 stars47 downloads/wk
Reviews
Write oneNobody has reviewed Hibp yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Hibp tools (3)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
HIBP-BreachesTool to query breached accounts and breaches from the Have I Been Pwned API
HIBP-PastesTool to query pastes containing account data from the Have I Been Pwned API
HIBP-PwnedPasswordsTool to check if a password has been exposed in data breaches using the Pwned Passwords API
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
no findings
- Code scan4 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitystatic API keys via environment variables6/15
- Maintenancelast push 13 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 83/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Install directly
Runs npx -y @darrenjrobinson/hibp-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add hibp -- npx -y @darrenjrobinson/hibp-mcp
Hibp: common questions
- Is Hibp MCP server safe?
- Mostly: it is graded B (83/100). Read the Hibp safety report
- How do I install Hibp?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Hibp need an API key?
- Yes. The registry entry asks for
HIBP_API_KEY. - Is Hibp maintained?
- The last commit was 14 days ago (2026-09-07). The latest release is v1.0.4.