"Someone with knowledge of AWS and CDK" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Production-safety audits for AI-generated code, with a fix for every finding.
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Manufacturer-cited router default logins and compliance check, plus MAC/OUI vendor lookup. Free.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts.
Check a live app you own for public databases, leaked keys and exposed files.
Check breach exposure for your verified email and check locally computed password hash prefixes.
35-probe LLM/agent security red-team scan (injection, jailbreak, MCP abuse) with report.
Explain a regex in plain English and detect catastrophic backtracking risk.