"Resources and information on conducting deep research" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Scan a site or AI-built app for exposed databases, keys and MCP endpoints, then verify the fixes.
Free AI test helpers: injection inputs, OWASP mapping, release plans, response and tool-call packs.
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Offline methodology engine for authorized penetration testing, CTF, and security research.
CVE, KEV, EPSS, SBOM and advisory lookups; per-CVE exposure from Shodan data (© Shodan). Keyless.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Triage a CVE: how severe it is, whether it is exploited, and how likely exploitation is.
Scan a deployed app URL for exposed keys, open Supabase tables and missing security headers.
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Check a live app you own for public databases, leaked keys and exposed files.