"An explanation or exploration of reasoning" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Read-only agent-commerce audit for UCP, x402, remediation and verification evidence.
Experimental MCP server for current empirical verification of explicit public HTTPS endpoint claims.
Exploit-DB: new public exploits & PoCs, daily. Register in-session — free testnet funds.
ACAO star-or-origin, value discarded
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
Scan a page for content planted to hijack an AI browsing/shopping agent before it acts on the page.
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
CVE triage in one call: NVD, CVSS, CISA KEV, EPSS, public exploits and an explained risk score.
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.
Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
Programmatic control of the Hiro security platform: scans, tasks, plans, and approvals.
Deep security scans of repos you own from your editor: dependency CVEs, SAST, git-history secrets.