
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
gmtrenchor-mcp
Advanced tools
Arc launch intelligence with a published track record: a token's first hour frozen before the chain prunes it, who deployed it and what else they launched, what a scanner called and what became of it. MCP tools; the record is free and the rest settle per
GMTRENCHOR measures what is normally invisible on Arc and Hyperliquid, keeps it, and publishes its own scoreboard, failures included.
Start with track_record. It is free, it states the lift of this scanner
against pools it never called, and it shows the score bands that do not
separate and the theses our research engine has refuted. A signal service that
will not publish its own failures is asking to be taken on trust.
token_microstructure for the first hour: buyers,
concentration, the price at ten, thirty and sixty minutes. Arc's public nodes
prune the swap tape within days, so this window cannot be fetched from
anywhere at any price once it has passed. Ours was written down while it
existed.deployer_history.market_context, and carry_persistence
if you are sizing a funding trade rather than reading one.open_calls, against track_record.| Tool | What it answers | |
|---|---|---|
track_record | What this scanner called and what became of it, with the lift, the bands that fail, and what the lab has refuted. | free |
open_calls | Every call open on Arc now, with what was known when it was opened. | 3¢ |
token_microstructure | One token's first hour, frozen before the chain forgot it. | 5¢ |
deployer_history | What one address has launched and what became of it. | 5¢ |
market_context | Hyperliquid now against the same hour a day ago. | 1¢ |
carry_persistence | How long funding spreads have actually lasted. | 5¢ |
No tool here gives advice. Each answers a question about the past with the denominator beside it. A rate over eleven observations and a rate over eleven thousand read the same in prose, so every answer states which it is.
{ "mcpServers": { "gmtrenchor": { "command": "npx", "args": ["-y", "gmtrenchor-mcp"] } } }
With nothing else set the free tool works and the paid ones say what they need.
| Variable | What |
|---|---|
PAY_WALLET_KEY | The agent's own key. Read from its own environment, used only to sign the payment authorisation locally, never sent anywhere. |
PAY_CHAIN | Where that wallet's USDC is: arc (default), base, arbitrum or hyperEvm. The payment need not be on the chain the data is about. |
PAY_MAX_USDC_PER_CALL | The most one call may cost. Default 0.05, which admits every tool here. The owner sets this. A price above it is refused before anything is signed. |
Payment is USDC over x402 through Circle Gateway, gas-free for the buyer.
You are never charged for an answer that was not produced. The service verifies the payment, produces the answer, and only then settles.
Audited on 18 September 2026 with Circle's own client and a real signature from
an unfunded wallet: on every route and on all four chains Circle verified the
signature, the answer was produced, and settlement was refused for one reason
only, insufficient_balance, with the answer withheld.
The data sets are bought once at a URL rather than through a tool, because a tool that hands a model nineteen dollars of gzip is a bill and not an answer: every closed call with its outcome at https://gmtrenchor.memeogatchi.workers.dev/x402/calls/closed, and one frozen day of every Arc launch at https://gmtrenchor.memeogatchi.workers.dev/x402/panel?day=YYYY-MM-DD, listed free at https://gmtrenchor.memeogatchi.workers.dev/panel/days.
Read provenance in the closed-call set before you parse it. Arc rows are
complete, because we read that chain ourselves block by block. Rows from the
other chain we scan carry the claim, its time, the score and the reasons but not
the prices: those observations came from a third party whose terms forbid
redistributing or deriving from them, so the columns are null and each row names
which. The rows are kept rather than dropped — a record showing only the chain
where the scanner looks good would not be a record.
FAQs
Arc launch intelligence with a published track record: a token's first hour frozen before the chain prunes it, who deployed it and what else they launched, what a scanner called and what became of it. MCP tools; the record is free and the rest settle per
We found that gmtrenchor-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.