"A service for error tracking and performance monitoring" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
Production-safety audits for AI-generated code, with a fix for every finding.
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Manufacturer-cited router default logins and compliance check, plus MAC/OUI vendor lookup. Free.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts.
Check a live app you own for public databases, leaked keys and exposed files.
Scan any public URL for hidden instructions aimed at AI agents (prompt injection). Free, no auth.
Check breach exposure for your verified email and check locally computed password hash prefixes.