"A guide to building a website" matching MCP connectors:
Matching Connector Tools:
Verify a skill, tool, or package before an agent installs it, or verify a scan attestation.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
urlscan.io URL scanner — search/result keyless, submit needs key
No-account public website privacy risk scans with 20 new scans/day and free recent-result reuse.
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
Scan your home network and local machine for security risks, open ports, weak Wi-Fi, unknown devices. Providing with a trust score and clear explanations.
Five free MCP tools, including proof-before-payment preview, plus one authorized x402 pack.
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.