"Resources for Learning or Writing Code" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
23 security tools for AI agents: phishing links, exposure maps, DNS, SSL, PQC, headers, email.
Production-safety audits for AI-generated code, with a fix for every finding.
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Scan a deployed app URL for exposed keys, open Supabase tables and missing security headers.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Offline methodology engine for authorized penetration testing, CTF, and security research.
Check a live app you own for public databases, leaked keys and exposed files.
Scan any public URL for hidden instructions aimed at AI agents (prompt injection). Free, no auth.
Check breach exposure for your verified email and check locally computed password hash prefixes.
Scan a page for hidden prompt-injection payloads targeting AI agents.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes