"Web search services that don't require an API key" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Pay-per-call agent tools: PDF, OCR, DOCX templates, speech to text, image, web, DNS, chain reads.
Production-safety audits for AI-generated code, with a fix for every finding.
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Scan a deployed app URL for exposed keys, open Supabase tables and missing security headers.
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts.
Explain a regex in plain English and detect catastrophic backtracking risk.
Scan a page for hidden prompt-injection payloads targeting AI agents.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Check dependencies against CISA's real Known Exploited Vulnerabilities feed.
ドメインの設定を調べる MCP サーバー。SPF / DKIM / DMARC・DNS・SSL 証明書・セキュリティヘッダ・サブドメイン・類似ドメインを、公開情報だけで確認します。登録不要・無料。
Free front-end security check for any website: a grade plus the secrets and keys it exposes.