"Creating a tool to replicate NowCerts API functionality" matching MCP connectors:
Matching Connector Tools:
Verify a skill, tool, or package for malicious behavior before your agent installs it. Hosted.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
Free no-account URL security scan: 0-100 Launch Readiness score for any live site in ~15 seconds.
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
TLPTOracle — 17-tool TIBER-EU TLPT framework: scope, threat intel, scenarios, reports.
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Deep security scans of repos you own from your editor: dependency CVEs, SAST, git-history secrets.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
Browser QA agent that won't return a false green: verified PASS/FAIL + access-control probing.