"How to test a React app" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
ドメインの設定を調べる MCP サーバー。SPF / DKIM / DMARC・DNS・SSL 証明書・セキュリティヘッダ・サブドメイン・類似ドメインを、公開情報だけで確認します。登録不要・無料。
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Daily CVE priorities ranked by real exploitation (KEV+EPSS) for AI agents; free teaser, paid full
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
AI pentesting: run scans, triage vulnerabilities, review PRs, manage schedules and assets.
MITRE Common Weakness Enumeration (CWE) API
urlscan.io URL scanner — search/result keyless, submit needs key
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.