"A guide to Python dependency resolution and package management" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan agent skills and MCP servers for malicious patterns before you load them
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.