"An open-source penetration testing framework" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Signed third-party verdict on what an npm package or file does when run. No key, no signup.
Check an npm/PyPI package before an AI agent installs it: 5 focused supply-chain tools.
Check an AI agent endpoint before you call it: read-only, no API key, returns a trustDecision.
Free MCP server of security & dev API tools -- supply-chain, CVE, DNS, WHOIS, OFAC, Cosmos SDK.
Parallel Solana token risk and transaction safety for AI agents. Paid MCP tools inspect tokens and unsigned transactions; the HTTP risk panel queries compatible advisors in parallel and returns an indicative consensus. x402-compatible clients pay USDC automatically, with no signup or API key.
Mint an agent identity in two free calls. Verify anyone. Earn 75% when someone reads you.
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
Protects AI coding agents from installing malicious open source packages. Every npm and PyPI package is checked against SafeDep’s real-time threat intelligence before installation.
Give your AI agent an identity it owns: email inbox, US phone number, SMS, voice, and a vault.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
Hosted, OAuth-gated endpoint for quantakrypto's post-quantum crypto tools: scan code for quantum-vulnerable cryptography (RSA/ECDH/ECDSA/DH) and get NIST ML-KEM/ML-DSA/SLH-DSA migration guidance over authenticated HTTP — nothing to install. Sign-in required (Google/GitHub/email). Same tools as the open-source @quantakrypto/mcp server; source at github.com/quantakrypto/pqc-tools.
The first covenant-governed trust protocol for AI agents. Screen → Attest → Certify → Verify → Reputation → Revoke. Open-source SDK. MIT license.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
Read-only breach intel, full history 2007-today: reports THAT an org was breached, never the data.
The trust harness for AI agents. Set what an agent can do before it acts.
Flags phantom-squatted/typosquatted domains and known-malicious URLs before an agent follows them.
Check an agent action against its operator's mandate before acting: permit, deny or escalate.
Trooth is an infrastructure and cybersecurity company providing Machine-Readable Trust.
Check an agent's INAM reputation before trusting it, and sign a receipt when work is done.
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.