"Functions or features enabled by the cursor" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
Daily CVE priorities ranked by real exploitation (KEV+EPSS) for AI agents; free teaser, paid full
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
ACAO star-or-origin, value discarded
Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
MDN HTTP Observatory — grade any website's HTTP security headers and get the specific fixes, from…
Scan a page for content planted to hijack an AI browsing/shopping agent before it acts on the page.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
Audit MCP servers for tool poisoning and shadowing. Scan a remote server by URL or paste its tools.
Hunt zero-days by talking to binaries. 40+ tools. Hosted, OAuth + SSO, invite: hi@byteray.ai