"A tool to query data in Metabase and ask questions" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Production-safety audits for AI-generated code, with a fix for every finding.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Explain a regex in plain English and detect catastrophic backtracking risk.
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Exploit-DB feed: new public exploits & PoCs — RCE, webapps, DoS, remote/local. Weaponized CVE intel.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Package dependency vulnerabilities + malicious-package advisories, patched versions. Hourly.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Scan agent skills and MCP servers for malicious patterns before you load them
Check if an MCP server tool changed or hides injection patterns before you trust it.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and