"An open-source MCP service leveraging large models for innovative problem-solving" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Production-safety audits for AI-generated code, with a fix for every finding.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Manufacturer-cited router default logins and compliance check, plus MAC/OUI vendor lookup. Free.
Scan any public URL for hidden instructions aimed at AI agents (prompt injection). Free, no auth.
Check a live app you own for public databases, leaked keys and exposed files.
35-probe LLM/agent security red-team scan (injection, jailbreak, MCP abuse) with report.
Check breach exposure for your verified email and check locally computed password hash prefixes.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Scan a page for hidden prompt-injection payloads targeting AI agents.