"An open-source penetration testing framework" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
TLPTOracle — 17-tool TIBER-EU TLPT framework: scope, threat intel, scenarios, reports.
Scan your home network and local machine for security risks, open ports, weak Wi-Fi, unknown devices. Providing with a trust score and clear explanations.
Scan a page for content planted to hijack an AI browsing/shopping agent before it acts on the page.
CVE triage in one call: NVD, CVSS, CISA KEV, EPSS, public exploits and an explained risk score.
Security research canary remote MCP server for owned-account testing.
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.