"Understanding Workspace Control Systems or Tools" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Free email checks: 24 blacklists, spoofing/BEC grade, redirect tracing, email spam test, WHOIS.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.
ACAO star-or-origin, value discarded
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.