"Understanding VS Code Agents or Extensions" matching MCP connectors:
Matching Connector Tools:
Free lockfile malware check plus paid pre-install scan of any skill, tool, or package.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Formally-verified injection/exfiltration detector for AI agents (MCP-02).
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
Five free MCP tools, including proof-before-payment preview, plus one authorized x402 pack.
Programmatic control of the Hiro security platform: scans, tasks, plans, and approvals.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day