"Windows Performance Toolkit and xperf.exe" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Scan agent skills and MCP servers for malicious patterns before you load them
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Scan your home network and local machine for security risks, open ports, weak Wi-Fi, unknown devices. Providing with a trust score and clear explanations.
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
Real-time CVE, exploit, and vulnerability intelligence for AI assistants (350K+ CVEs, 115K+ PoCs)
Security audits for WordPress plugins and themes — 62 verification layers, fix plans and SBOMs.