Unchore Defend runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 3 Oct 2026.
Grade a site's security headers with fixes and a badge; read logs or code for the defender.
We read the source, 5 d ago · rules ccca72095570
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
const p = spawn(process.execPath, args, { env: process.env, stdio: ["pipe", "pipe", "pipe"] });
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Reads security headers and CSP line by line in your config file and names the lines that silently do
Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Bridge Claude with Google's Antigravity CLI (agy) for code review and second opinions
Find candidate customs tariff codes for a product and read the import duty on a code.
45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
Local LLM does Claude's bulk work: reads logs and files, researches the web, writes test-gated code.
Bridge Codex and other MCP clients with Anthropic Claude Code CLI for read-only second opinions
Answers built from our own checks of this server.