"Automated Penetration Testing Tools and Techniques" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Check a live app you own for public databases, leaked keys and exposed files.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Explain a regex in plain English and detect catastrophic backtracking risk.
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan agent skills and MCP servers for malicious patterns before you load them
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and