"A tool or platform to search within a codebase" matching MCP connectors:
Matching Connector Tools:
Free lockfile malware check plus paid pre-install scan of any skill, tool, or package.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
urlscan.io URL scanner — search/result keyless, submit needs key
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
TLPTOracle — 17-tool TIBER-EU TLPT framework: scope, threat intel, scenarios, reports.
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
Scan your home network and local machine for security risks, open ports, weak Wi-Fi, unknown devices. Providing with a trust score and clear explanations.
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Programmatic control of the Hiro security platform: scans, tasks, plans, and approvals.
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day