
Unchore Defend
io.github.smileminov0.1.0更新於 Sep 30, 2026
Grade a site's security headers with fixes and a badge; read logs or code for the defender.
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Unchore Defend,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
Unchore Defend
Security help for the person protecting the system. Two tools, no install, works in Claude Code, Claude Desktop, any MCP client, or a plain terminal.
[Unchore Defend in 20 seconds]
July 2026: an AI agent broke out of its test sandbox and got into Hugging Face's production systems. Hugging Face counted about 17,600 attacker actions across 11 nodes over roughly 4.5 days. When the responders asked commercial frontier models to help read the logs, the requests were "blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker." They finished the forensics on an open-weight model (GLM-5.2). Sources: disclosure · technical timeline
Defend makes that switch for you: it asks Claude, then GPT, then GLM, then DeepSeek, and moves on only when one refuses.
Install
Claude Code (skills + MCP tools):
Then just ask: "check the security headers of mysite.com and fix what you can" or "read access.log — were we attacked?"
Only want the site check? /plugin install unchore-site-check@unchore installs just that (no key, no AI calls).
The site check needs no key. For defend, Claude Code asks for an OpenRouter or Unchore key when you enable the plugin (later: /plugin configure unchore-defend@unchore); it is kept in your system's secure storage.
Claude Desktop: download unchore-defend.mcpb from Releases and open it.
Any MCP client (Cursor, VS Code, Windsurf, …) — clone this repo, then add:
Terminal only: Node 22+, nothing to install.
Site check
Nine checks, weighted: HTTPS (25), HSTS (15), Content-Security-Policy (15), clickjacking protection (10), nosniff (10), Referrer-Policy (8), Permissions-Policy (5), cookie flags (7), server version hidden (5). A ≥ 90 · B ≥ 75 · C ≥ 60 · D ≥ 40.
It sends one ordinary GET to the site and nothing anywhere else. Private, local and cloud-metadata addresses are refused, every redirect is checked again, and it stops after 3 redirects, 8 seconds or 200 KB.
Put the grade in your README — the output gives you the line:
[Security headers: B (80/100) — checked with Unchore]
The badge says what was measured: response headers. It is not a full security audit.
Rather click than type? The same check runs at unchore.ai/tools/site-check.
Defend
For "we were hit — what happened?", "is this log an attack?", "what did this script do?".
- Masked before sending: phone numbers, ID/card/account numbers, e-mails, API keys, tokens and private keys. IP addresses, paths and timestamps stay — they are the evidence.
- If one AI refuses, the next answers. Some safety filters refuse even defenders. Defend asks Claude first, then GPT, GLM and DeepSeek — only when the one before refused. GLM and DeepSeek run on US hosts, and every request asks OpenRouter to route only to providers that don't collect data (
data_collection: deny). - Defensive use only. It explains an attack as far as needed to detect and stop it. The AIs are told not to write exploits or malware.
Pay for the AI one of two ways:
OPENROUTER_API_KEY— your own key; requests go straight from your machine to OpenRouter.UNCHORE_TOKEN— no AI account needed. Sign in at unchore.ai → Settings → AI → Unchore credit → New key.
--chain glm,deepseek sets the order, --own forces your OpenRouter key, --json prints machine-readable output.
Tested on real traffic
640 lines of our own production web logs (7 days, IP addresses removed): 69 real attack lines (WordPress admin probes, .git/.env fishing, scanner bots) and 571 normal lines.
No AI refused plain log triage. Claude and GPT were the most precise, so they go first. Refusals show up on harder work, like the payload analysis where Hugging Face got blocked. That is where the fallback helps.
Why this exists
Unchore is a personal AI that notices when you ask for the same thing twice and offers to do it for you from then on. These two tools are pieces of it that also work on their own.
Contributing
Issues and pull requests are welcome. Run node --test test/*.test.mjs before sending. Security problems: see SECURITY.md. What is sent where: PRIVACY.md.
MIT © 2026 Unchore
來源:README.md,提交 1920101
工具
0版本歷史
1- v0.1.0最新Sep 30, 2026

