"CodeQL static analysis tool and semantic code analysis platform" matching MCP connectors:
Matching Connector Tools:
Scan your home network and local machine for security risks, open ports, weak Wi-Fi, unknown devices. Providing with a trust score and clear explanations.
Verify a skill, tool, or package for malicious behavior before your agent installs it. Hosted.
Scan agent skills and MCP servers for malicious patterns before you load them
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.
Real-time CVE, exploit, and vulnerability intelligence for AI assistants (350K+ CVEs, 115K+ PoCs)
TLPTOracle — 17-tool TIBER-EU TLPT framework: scope, threat intel, scenarios, reports.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
No-account public website privacy risk scans with 20 new scans/day and free recent-result reuse.
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.