"How to access developer tools in web browsers" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
Free AI security tools: injection payloads, OWASP LLM mapper, ADLC release planner, test builder.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Free email checks: 24 blacklists, spoofing/BEC grade, redirect tracing, email spam test, WHOIS.
Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts.
Explain a regex in plain English and detect catastrophic backtracking risk.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
Exploit-DB: new public exploits & PoCs, daily. Register in-session — free testnet funds.
Dependency vulns & malicious-package advisories. Register in-session — free testnet funds.
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Scan a page for content planted to hijack an AI browsing/shopping agent before it acts on the page.
454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.