cf-mcp-traffic

cf-mcp-traffic

Exposes Cloudflare HTTP traffic and firewall analytics to Claude Code via MCP tools, including a deterministic suspicion scorer.

Category
访问服务器

README

cf-mcp-traffic

A local stdio MCP server that exposes Cloudflare HTTP traffic and firewall analytics to Claude Code. Query traffic by 20+ dimensions, drill into individual actors, and score suspicion against a documented rulebook. Includes a deterministic scorer so it can run without Claude. Local-only, not deployed.

What it exposes

Four MCP tools plus a helper:

  • list_known_domains — the zones configured in your domains.json
  • traffic_summary — aggregated bucket counts from httpRequestsAdaptiveGroups, grouped by up to 3 of ~20 dimensions (ASN, path, IP, JA4, country, status, bot_score_bucket, time_hour, etc.)
  • firewall_events — same shape but on WAF / rate-limit / bot-management / custom-rule actions, with rule descriptions
  • requests_for — sampled per-request drilldown, filtered by IP / JA4 / ASN / path / UA / status
  • score_actor — runs the deterministic scorer against a pre-aggregated ActorSignals bundle

The scoring logic lives in src/lib/scoring.ts. It's a pure function — no I/O, no globals, importable from any TS runtime.

Prerequisites

Setup

1. Clone and install

git clone git@github.com:Greta221/cf-mcp-traffic.git
cd cf-mcp-traffic
bun install

2. Create your data directory

The server reads all account-specific config from a local directory pointed at by the CF_MCP_TRAFFIC_DATA_DIR env var. Nothing account-specific ships with the code.

mkdir -p ~/.cf-mcp-traffic-data

Populate two files inside it:

.env — your credentials:

CF_API_TOKEN=your_token_here
CF_ACCOUNT_ID=your_account_id_here

domains.json — a flat map from domain name to its Cloudflare zone tag:

{
  "example.com": "your_zone_tag_here",
  "another-example.com": "another_zone_tag"
}

Zone tags come from the Cloudflare dashboard: Zone overview → API → Zone ID.

3. Wire it into Claude Code

Add the server to ~/.claude.json (or the project-local .mcp.json):

{
  "mcpServers": {
    "cf-traffic": {
      "type": "stdio",
      "command": "bun",
      "args": ["run", "/absolute/path/to/cf-mcp-traffic/src/index.ts"],
      "env": {
        "CF_MCP_TRAFFIC_DATA_DIR": "/absolute/path/to/your/.cf-mcp-traffic-data"
      }
    }
  }
}

Restart Claude Code. The cf-traffic server should appear in /mcp.

Optional: watch list, trust list, site patterns

Two markdown files and one JSON, all in your data directory. Only needed if you use the /triage-traffic runbook (see below) or the score_actor tool with trust penalties.

  • watch-list.md — actors observed misbehaving but not severe enough to block. Log the actor, the reason, and the trigger for revisiting.
  • trust-list.md — known-good sources (payment webhooks, internal infra, verified crawlers). Membership drives negative penalties on scored actors.
  • site-patterns.json — your account's API hosts, application URL patterns, sensitive POST endpoints. Drives several signals. Expected keys:
{
  "api_hosts": ["api.example.com"],
  "api_path_prefixes": ["/api/", "/v1/"],
  "html_paths": ["/", "/profile"],
  "asset_path_prefixes": ["/static/", "/assets/"],
  "asset_file_extensions": [".css", ".js", ".png"],
  "sensitive_post_paths": ["/login", "/checkout/pay"]
}

None of these files are required to boot the server. Signals that depend on missing files simply don't fire.

Running the scorer without Claude

The scorer is a pure function. Import and call it:

import { scoreActor } from "./src/lib/scoring";
import type { ActorSignals } from "./src/lib/types";

const input: ActorSignals = {
  identifier_type: "ip",
  identifier: "1.2.3.4",
  // ...populate the remaining fields from your own aggregations
};

const result = scoreActor(input);
console.log(result.score, result.reasons);

Signal names, weights, and thresholds are in src/lib/constants.ts. Input and output types are in src/lib/types.ts.

The scoring rulebook

The scoring policy (how signals fire, what they mean, how trust penalties work, worked examples) lives at .claude/commands/triage-traffic.md. It's a slash command Claude Code reads — you can invoke it with /triage-traffic inside Claude, or read it as documentation for the scoring model.

The rulebook and the code are kept in sync: rulebook signal names match the SIGNAL constants in src/lib/constants.ts.

Development

bun run test       # vitest, single run
bun run test:watch
bun run check      # biome lint + format check

Design notes

  • Stdio MCP server, not a Worker. Runs locally on demand when Claude invokes a tool.
  • requests_for returns sampled data (~1% on busy zones). Never use it for path or host counts — always use traffic_summary aggregations for those.
  • The score_actor tool takes a pre-computed ActorSignals object. Aggregating the signals from raw traffic queries is the caller's job (Claude does this in-session by reading the rulebook and calling the query tools).

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选
mcp-server-qdrant

mcp-server-qdrant

这个仓库展示了如何为向量搜索引擎 Qdrant 创建一个 MCP (Managed Control Plane) 服务器的示例。

官方
精选
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选