hulak — security grade CAUTION, quality 70/100

Security audit verdict: CAUTION · quality 70/100

Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by xaaha · MCP Server · ★ 95

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is hulak safe to install? View the security audit →

About hulak

Git-native API client with encrypted secrets. REST · GraphQL · OAuth Quick Start • GraphQL Explorer • Project Layout • Documentation Run one request, a whole directory, or stay interactive Hulak runs request files directly from your project. It supports concurrent directory execution. It falls back to an interactive picker when you simply run . Dedicated GraphQL Explorer Browse schemas from multiple endpoints. Search operations. Build queries interactively. Execute inline. Save generated files from the terminal. Quick Start Install Hulak ships via xaaha/tap. Homebrew 6.0+ requires explicit trust for third-party taps; without it, silently skips hulak. One-time step per machine: Other install options: Build from source with Shell completion (go ins

ai-agentsapi-clientapi-client-with-encrypted-secretsclideveloper-toolsgolanggraphql-clienthttp-clientinsomnia-alternativemcp

Quick Facts

Stars95
Forks6
LanguageGo
CategoryMCP Server
LicenseMIT
Quality Score70.0108209859523/100
Open Issues31
Last Updated2026-10-03
Created2024-02-19
Platformscli, go, mcp
Est. Tokens~17k

Compatible Skills

These tools work well together with hulak for enhanced workflows:

  • simplemind — semantic(0.33)+complementary+rare_topics+similar_pop+shared_platform (56%)

hulak alternative? Top 6 similar tools

Looking for a hulak alternative? If you're comparing hulak with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • tiger by jtaoufik · ⭐ 98

    Free, open source, git-native API client. A local-first Postman, Insomnia and Bruno alternative for macOS, Win

  • mcp-gopls by hloiseau · ⭐ 97

    Model Context Protocol (MCP) server for Go using gopls – LSP-powered analysis, tests, coverage, and tooling.

  • mcp-cli by apify · ⭐ 459

    mcpc is a CLI client for MCP. It supports persistent sessions, stdio/HTTP, OAuth 2.1, JSON output for code mod

  • AgenticGoKit by AgenticGoKit · ⭐ 179

    Open-source Agentic AI framework in Go for building, orchestrating, and deploying intelligent agents. LLM-agno

  • TaskWing by josephgoksu · ⭐ 87

    Local-first AI knowledge layer. Extract architecture, query from any AI tool via MCP. Private by architecture.

  • claude-emporium by Vvkmnn · ⭐ 82

    🏛 [UNDER CONSTRUCTION] A (roman) claude plugin marketplace

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is hulak?

hulak is Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.. It is categorized as a MCP Server with 95 GitHub stars.

What programming language is hulak written in?

hulak is primarily written in Go. It covers topics such as ai-agents, api-client, api-client-with-encrypted-secrets.

How do I install or use hulak?

You can find installation instructions and usage details in the hulak GitHub repository at github.com/xaaha/hulak. The project has 95 stars and 6 forks, indicating an active community.

What license does hulak use?

hulak is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to hulak?

The top alternatives to hulak on Agent Skills Hub include tiger, mcp-gopls, mcp-cli. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools