Umbra runs on your own machine — the client starts it, so there is no endpoint to ping. 80 installs a week from npm. Last commit 5 Aug 2026.
Trust score for AI-generated code: scan repos, guard agent file writes, get a 0-100 score.
We read the source, 14 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
const { status, error } = spawnSync(process.execPath, [cli, ...process.argv.slice(2)], {
await fs.writeFile(path.join(workdir, dockerfileArg), rendered, 'utf8');
const dotfiles = ['.npmrc', '.nvmrc', '.eslintrc', '.prettierrc', '.gitconfig', '.cursorrules'];
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add umbra -- npx -y @elberacasa/umbra
{
"mcpServers": {
"umbra": {
"args": [
"-y",
"@elberacasa/umbra"
],
"command": "npx"
}
}
}
[mcp_servers.umbra]
command = "npx"
args = ["-y", "@elberacasa/umbra"]
{
"mcpServers": {
"umbra": {
"args": [
"-y",
"@elberacasa/umbra"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"umbra": {
"args": [
"-y",
"@elberacasa/umbra"
],
"command": "npx"
}
}
}
Analyzes codebases with tree-sitter and generates AGENTS.md files for AI coding agents.
Scan codebases for AI usage, classify risk, generate EU AI Act compliance reports.
AI visibility for ChatGPT/Perplexity/Claude — triple score (AEO+GEO+Agent) with fix code. Free.
Scans AI-generated code for invisible Unicode, Trojan Source, and supply-chain threats.
Generate QR codes for URLs, PIX, Wi-Fi, vCards, WhatsApp and more. For AI agents.
AI software engineer — writes code, opens PRs, reviews code, generates tests, and more.
Disposable microVM sandboxes for AI agents: run code, read/write files, git, preview URLs.
Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.
Answers built from our own checks of this server.