"A Python server using FastAPI to expose public web API endpoints to an agent" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Production-safety audits for AI-generated code, with a fix for every finding.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Check a live app you own for public databases, leaked keys and exposed files.
Scan any public URL for hidden instructions aimed at AI agents (prompt injection). Free, no auth.
Scan a page for hidden prompt-injection payloads targeting AI agents.
Read-only agent-commerce audit for UCP, x402, remediation and verification evidence.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Explain a regex in plain English and detect catastrophic backtracking risk.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Check dependencies against CISA's real Known Exploited Vulnerabilities feed.
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...