"Using Claude to Check the Current Weather Without an API Key" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
MITRE Common Weakness Enumeration (CWE) API
urlscan.io URL scanner — search/result keyless, submit needs key
Verificação de segurança e conformidade de sites: cabeçalhos, TLS, DNS, e-mail, LGPD e pentest.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
Free no-account URL security scan: 0-100 Launch Readiness score for any live site in ~15 seconds.
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).