"How to connect to the internet, browse a webpage, and take screenshots" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Free, read-only security scanner for remote MCP servers, before you connect them.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan agent skills and MCP servers for malicious patterns before you load them
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.