"Creating an app from files" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
Check a live app you own for public databases, leaked keys and exposed files.
Scan a page for content planted to hijack an AI browsing/shopping agent before it acts on the page.
Discover a site's pages from its sitemap and sample them for WCAG and prompt-injection risk.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Scan a page for hidden prompt-injection payloads targeting AI agents.
Read-only agent-commerce audit for UCP, x402, remediation and verification evidence.
Check dependencies against CISA's real Known Exploited Vulnerabilities feed.
Exploit-DB: new public exploits & PoCs, daily. Register in-session — free testnet funds.
Daily CVE priorities ranked by real exploitation (KEV+EPSS) for AI agents; free teaser, paid full
Read-only smart-contract security intelligence for autonomous agents.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.