"An official Figma MCP server" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Incident-reporting deadlines from the law: CRA, NIS2, DORA, GDPR, HIPAA, SEC 8-K. 6 of 9 tools free.
Scan, fix and verify DNS: SPF, DMARC, DKIM, propagation, DNS health, expiry. Validated fixes.
Persistent knowledge graph for AI-augmented teams. Store decisions, findings, and standing rules across agent sessions with semantic search and typed connections. Includes cross-session memory, audit trail, workspace isolation, and secret detection. Built for teams running agents that need to remember. Free until launch with team tier as default, anon trial available.
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
The miniOrange MCP Server Plugin is a secure WordPress MCP Server that exposes your WordPress site as an MCP endpoint while adding enterprise-grade security, policy enforcement, and complete audit logging. Unlike a basic MCP server that simply connects AI tools to WordPress, this plugin verifies every AI request before it reaches your website. Every request is authenticated, checked against security policies, logged, and can even require human approval before execution.
Verify claims, resolve FIGI identity, extract claims, and sign x402 delivery receipts over MCP.
Rank agents; signed machine messages + wallet gates via x402; free verifiable agent passports.
Verifies which domain officially belongs to a software product, AI tool, or company, so the agent stops handing users lookalike download sites. Ownership only, never safety. Every verdict is backed by reproducible evidence. Tools: get_official_url(name), verify_url(url). No auth required.
Domain security reconnaissance tools for AI agents via Model Context Protocol. 13 security tools — DNS, SSL, HTTP headers, email auth, port scan, propagation, reverse DNS, ASN/BGP, RDAP/WHOIS, subnet calc, and comprehensive security scan — callable from Claude Desktop and any MCP-compatible AI agent. Part of DechoNet. Every tool here is also a free web tool at dechonet.com — no sign-up, no API key — backed by error-fix guides. This package brings the same checks to AI agents.
Lumethic checks whether a photo is a real, unmodified camera capture. Give it the RAW file and the JPEG export from the same shot for a forensic comparison, or a single image to validate its C2PA Content Credentials. You get an authenticity verdict with confidence, per-check findings, and a shareable report. From your assistant you can verify photos, tag and annotate them, share reports, request layered PSD exports, and publish verified work to a public portfolio page. 32 tools, all annotated as read-only, open-world or destructive so the assistant asks before anything irreversible. Connect from the assistant: the first connection opens a Lumethic sign-in screen, you enter your email and the six-digit code we send, and you choose what the assistant may do. New addresses get a free account with 5 verifications a month; Content Credentials checks are free and unlimited. Servers and scripts can use an API key as the bearer token instead. Claude Code: `claude mcp add --transport http lumethic https://api.lumethic.com/mcp` Docs and full tool reference: https://www.lumethic.com/en/mcp
Discovery, OAuth, project operations, and exact project MCP handoff for Spala backend projects.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Give your AI agent an identity it owns: email inbox, US phone number, SMS, voice, and a vault.
Fallax is a phishing simulation and security awareness training platform. Read your results.
Anonymize and redact PII before it reaches AI models. GDPR, HIPAA, EU AI Act.
AI URL safety validator: SAFE/SUSPICIOUS/DANGEROUS verdict, trust score, threat intel.
Paid x402 tools over MCP: search, FX, LEI, company research, risk. Pay-per-call USDC on Base.
Mint an agent identity in two free calls. Verify anyone. Earn 75% when someone reads you.