Think inside your AI world.
A security advisory, against the version you pinned
A vulnerability feed is loud by design: hundreds of advisories a week, across thousands of packages you will never run. What you actually need is the one that lands on a version you pinned, at a severity you decided was worth an interruption — and that is a line the feed cannot hold, because the line is yours.
Read the GitHub Advisory Database through Unl and the whole public stream arrives measured against the criterion you ratified — so instead of reading the whole stream, you get the single advisory that crosses a dependency you pinned at a severity you set, with the reason it crosses. The one, not the thousand.
What the GitHub Advisory Database publishes
The GitHub Advisory Database is a genuine public good, and there is a lot of it:
- Hundreds of new advisories a week across npm, PyPI, Maven, Go and more
- Every severity, from a low-risk dev-dependency note to a critical remote-execution flaw
- Thousands of packages, almost none of which are in your build
- No idea which of your pinned versions it bears on — that context is not in the feed
The line the feed can't hold
Say you pinned a library at a specific version for a reason, and ratified the line that makes an advisory worth your attention: only a critical or high-severity advisory, on a dependency I have actually pinned, interrupts me — everything below that waits for the scheduled upgrade. That severity floor is a decision you made; it is not a column the feed models.
The reason the line is yours is the whole point. A feed can filter by severity; it cannot know which versions you pinned, or that you pinned them deliberately, or that a moderate advisory on an unpinned transitive dependency is noise to you and a critical one on the version you froze is not.
The frame judges the data it is given; it does not verify the source’s accuracy.
The one that crosses
So when a critical advisory lands on the exact version you pinned, it crosses — and nothing else does. Through Unl the answer arrives as a verdict: the version you pinned now carries a critical advisory, above the severity floor you set, so this one is worth the interruption; the other ninety this week were not. Same public feed; a decision instead of a digest.
You didn't ask — it was already there
You did not ask for it. The criterion was already ratified, so the next time you open Claude on that repository the crossing is already in the window — read against your severity line, with the reason it cleared it — rather than waiting for you to remember to scan the advisories. You author the line once; the read applies it every time the world moves.
The answer comes back measured against what you already decided, and why.
The lane is live and open to this tool today: one box, paste anything. If it speaks MCP, Unl can reach it. Readings arrive unprompted, the data beside the criterion; Unl is a courier, not a warehouse, and keeps only your keys and the frame.
Read further
Questions people ask
How is this different from a vulnerability alert or a Dependabot feed?
An alert fires on the source's rule — a severity threshold someone else set, over every package it watches. This fires on YOUR rule: the severity floor you ratified, applied only to versions you actually pinned, with the reasoning attached. The feed shows you the thousand; the measured read shows you the one that crosses a line you drew, and why.
Do I get pinged the moment an advisory lands?
The capability is that the crossing arrives measured against your criterion the next time you are working — it is already in the window, read against your line, rather than a stream you monitor. A scheduled push is a separate delivery; what the read guarantees is that when the crossing surfaces, it surfaces as a verdict against your position, not as one more feed item.
Does Unl change anything in my repository or the advisory feed?
Unl reads through the GitHub Advisory Database, and can write back on your explicit gesture — it never acts as a side effect of a read. The advisory feed is a public GET; your criterion lives in Unl; the read joins them and returns a verdict, altering neither.
What this is
Think inside your AI world — you stay in command
Unlimitless (Unl to friends) holds what you've settled, reads what your tools are showing, and catches what's changed out in the world — and hands your AI whatever bears on the work, the moment it's needed, without you asking. The right thing, in front of the model, unprompted, with you in command of the call. So you keep moving toward what you set out to build, on top of everything you've already decided.
It plugs into Claude, Claude Code, ChatGPT and Cursor as an MCP connector. Quick to connect, in a couple of steps.
Unlimitless is open now to invited Alpha. Apply for the Beta waitlist to come in ahead of the full launch:
Alpha is invite-only · free at launch.