"Exploring Operating Systems, Shells, and Command-Line Tools" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Offline methodology engine for authorized penetration testing, CTF, and security research.
Manufacturer-cited router default logins and compliance check, plus MAC/OUI vendor lookup. Free.
Check a live app you own for public databases, leaked keys and exposed files.
Check breach exposure for your verified email and check locally computed password hash prefixes.
Read-only agent-commerce audit for UCP, x402, remediation and verification evidence.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Explain a regex in plain English and detect catastrophic backtracking risk.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.