"An application or tool called 飞书 (Feishu)" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
TLPTOracle — 17-tool TIBER-EU TLPT framework: scope, threat intel, scenarios, reports.
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.
Hyperion — MCP tool marketplace for AI agents: web, OSINT, security, research via one key.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.