"A security license quality system or service" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Production-safety audits for AI-generated code, with a fix for every finding. Scan for committed secrets and known vulnerable dependencies free with no key; a full audit returns a verdict with security, privacy, reliability and architecture findings, priced per audit and quoted before it runs.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Explain a regex in plain English and detect catastrophic backtracking risk.
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
Security scanner for n8n workflows: 18 rules, OWASP Agentic mapped. Free MCP, paid x402 API.
Free, read-only security scanner for remote MCP servers, before you connect them.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Package dependency vulnerabilities + malicious-package advisories, patched versions. Hourly.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.