This is a Linux OS hardening tool. Take a fresh install and immediately harden the heck out of it using just your favourite LLM agent and natural language prompts. "Make my system secure" or "Do a full security audit of my system."
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.DEFENSE_MCP_ALLOWED_DIRS— "": "/tmp,/home,/var/log"DEFENSE_MCP_ALLOWED_TOOLSDEFENSE_MCP_AUTO_INSTALL— false node build/index.jsDEFENSE_MCP_BACKUP_DIRDEFENSE_MCP_BACKUP_ENABLED— true Auto-backup before system changesDEFENSE_MCP_CHANGELOG_PATHDEFENSE_MCP_COMMAND_TIMEOUTDEFENSE_MCP_DRY_RUN— "": "true",DEFENSE_MCP_LOG_FILEDEFENSE_MCP_LOG_LEVEL— info Log verbosity (debug/info/warn/error)DEFENSE_MCP_LOG_MAX_FILESDEFENSE_MCP_LOG_MAX_SIZEDEFENSE_MCP_MAX_OUTPUT_SIZEDEFENSE_MCP_NETWORK_TIMEOUTDEFENSE_MCP_POLICY_DIRDEFENSE_MCP_PREFLIGHT— true Enable pre-flight dependency checksDEFENSE_MCP_PREFLIGHT_BANNERS— true Show pre-flight status in tool outputDEFENSE_MCP_PROTECTED_PATHSDEFENSE_MCP_QUARANTINE_DIRDEFENSE_MCP_RATE_LIMIT_GLOBALDEFENSE_MCP_RATE_LIMIT_PER_TOOLDEFENSE_MCP_RATE_LIMIT_WINDOWDEFENSE_MCP_READ_ONLYDEFENSE_MCP_REDACT_OUTPUTDEFENSE_MCP_REQUIRE_CONFIRMATION— true Require confirmation for destructive actionsDEFENSE_MCP_RUNTIME_PATH_VERIFYDEFENSE_MCP_SUDO_TIMEOUTDEFENSE_MCP_THIRD_PARTY_INSTALL— Requires explicit =true to enableDEFENSE_MCP_TIMEOUT_DEFAULTDEFENSE_MCP_TIMEOUT_LYNISDEFENSE_MCP_TIMEOUT_NMAPDISPLAYLOGNAMEMCP_API_KEYMCP_PORT— 3100 HTTP server port (when MCP_TRANSPORT=http)MCP_TRANSPORT— stdio Transport mode: stdio or httpSSH_CONNECTIONSSH_TTYSUDO_ASKPASSWAYLAND_DISPLAY[](https://m8ven.ai/mcp/bottobot-defense-mcp-server-odpyzn)