"An introduction to OSINT (Open Source Intelligence)" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Scan a deployed app URL for exposed keys, open Supabase tables and missing security headers.
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.
Scan your home network and local machine for security risks, open ports, weak Wi-Fi, unknown devices. Providing with a trust score and clear explanations.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Scan a page for content planted to hijack an AI browsing/shopping agent before it acts on the page.
CVE intelligence, STRIDE, OWASP test cases via Ansvar Gateway. Cited, OAuth + paid.
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
Read-only smart-contract security intelligence for autonomous agents.
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Real-time CVE, exploit, and vulnerability intelligence for AI assistants (350K+ CVEs, 115K+ PoCs)
Hunt zero-days by talking to binaries. 40+ tools. Hosted, OAuth + SSO, invite: hi@byteray.ai