"Understanding the term 'flux' or its various applications" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
Check if an MCP server tool changed or hides injection patterns before you trust it.
ACAO star-or-origin, value discarded
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
MDN HTTP Observatory — grade any website's HTTP security headers and get the specific fixes, from…
Scan a page for content planted to hijack an AI browsing/shopping agent before it acts on the page.
Discover a site's pages from its sitemap and sample them for WCAG and prompt-injection risk.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
Audit MCP servers for tool poisoning and shadowing. Scan a remote server by URL or paste its tools.
Programmatic control of the Hiro security platform: scans, tasks, plans, and approvals.
Query and retrieve information about various adversarial tactics and techniques used in cyber atta…