Unicode Security MCP runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 9 Aug 2026.
Local first MCP checks for Unicode confusables, mixed scripts, invisible controls, and...
Today is the operative word: we check Unicode Security MCP every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add unicode-security-mcp -- npx -y unicode-security-mcp
{
"mcpServers": {
"unicode-security-mcp": {
"args": [
"-y",
"unicode-security-mcp"
],
"command": "npx"
}
}
}
[mcp_servers.unicode-security-mcp]
command = "npx"
args = ["-y", "unicode-security-mcp"]
{
"mcpServers": {
"unicode-security-mcp": {
"args": [
"-y",
"unicode-security-mcp"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"unicode-security-mcp": {
"args": [
"-y",
"unicode-security-mcp"
],
"command": "npx"
}
}
}
Local-first MCP security scanner and CLI for AI-generated applications.
Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs
Static compliance-controls checker for UK Online Safety Act & ICO Children's Code. CLI + MCP.
Local-first secret scanning, rotation, vault, and audit-log tools for AI agents.
Domain security & privacy checker as an MCP server. 17 live checks, 0-100 score, local-first.
Static MCP, source-code and injection-indicator checks with redacted signed receipts.
Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.
Secure MCP runtime server for scanning and autofixing code issues
Answers built from our own checks of this server.