"A server that reviews GitHub pull requests or provides diffs" matching MCP connectors:
Matching Connector Tools:
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Offline methodology engine for authorized penetration testing, CTF, and security research.
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Free lockfile malware check plus paid pre-install scan of any skill, tool, or package.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
Scan your home network and local machine for security risks, open ports, weak Wi-Fi, unknown devices. Providing with a trust score and clear explanations.
MEOK MCP Hardening MCP — automated security red-team for any MCP server. Maps OWASP LLM Top 10
Security research canary remote MCP server for owned-account testing.
Security audits for WordPress plugins and themes — 62 verification layers, fix plans and SBOMs.