"A hub for monitoring MCP trends" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
Free AI security tools: injection payloads, OWASP LLM mapper, ADLC release planner, test builder.
Production-safety audits for AI-generated code, with a fix for every finding.
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Manufacturer-cited router default logins and compliance check, plus MAC/OUI vendor lookup. Free.
CVE, KEV, EPSS, SBOM and advisory lookups; per-CVE exposure from Shodan data (© Shodan). Keyless.
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Triage a CVE: how severe it is, whether it is exploited, and how likely exploitation is.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.