"Setting Up or Using an MQTT Server" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
Experimental MCP server for current empirical verification of explicit public HTTPS endpoint claims.
454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
ACAO star-or-origin, value discarded