"A search for information on Common Vulnerabilities and Exposures (CVE)" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Production-safety audits for AI-generated code, with a fix for every finding.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Manufacturer-cited router default logins and compliance check, plus MAC/OUI vendor lookup. Free.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts.
Check a live app you own for public databases, leaked keys and exposed files.
Scan any public URL for hidden instructions aimed at AI agents (prompt injection). Free, no auth.