"Building and Using MCP Tools" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Audit MCP configs and skill files for over-broad scope and injection risk. 6 of 8 free.
Incident-reporting deadlines from the law: CRA, NIS2, DORA, GDPR, HIPAA, SEC 8-K. 6 of 9 tools free.
Secure MCP Server for WordPress connects AI assistants and agents to WordPress with secure, controlled access. It lets AI interact with WordPress through MCP while helping organizations manage access, enforce policies, protect non-human identities (NHI), and require human approval for sensitive actions. Use it to securely connect tools such as ChatGPT, Claude, and Cursor with WordPress. Marketplace Link: https://wordpress.org/plugins/miniorange-secure-mcp-server/ Official website: https://plugins.miniorange.com/mcp-server-ai-policy-enforcement-wordpress
Pre-trade token safety check for AI agents. Simulates a sell before you buy, then returns one low/medium/high/unknown verdict with the signals behind it: sellability, buy/sell tax, liquidity depth, pair age, same-ticker impersonation, owner powers from bytecode. Ethereum, BSC, Base, Solana. Fail-closed - a check that cannot run answers unknown, never low. Publishes its own measured error rate with the benchmark harness in the repo. Free, no signup, no API key, MIT.
SEO, AEO, GEO, Local SEO & CRO Growth Auditor + Safe Code Fixer with multi-page sitemap crawling, HTTP security headers inspection (HSTS, CSP), and universal WebMCP support.
Live-checks whether a WordPress site is ready to be safely operated by AI agents.
Scan, fix and verify DNS: SPF, DMARC, DKIM, propagation, DNS health, expiry. Validated fixes.
Persistent knowledge graph for AI-augmented teams. Store decisions, findings, and standing rules across agent sessions with semantic search and typed connections. Includes cross-session memory, audit trail, workspace isolation, and secret detection. Built for teams running agents that need to remember. Free until launch with team tier as default, anon trial available.
Verify photos are real camera captures, not AI: C2PA and RAW+JPEG forensics. OAuth or API key.
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
Verify claims, resolve FIGI identity, extract claims, and sign x402 delivery receipts over MCP.
Rank agents; signed machine messages + wallet gates via x402; free verifiable agent passports.
Verifies which domain officially belongs to a software product, AI tool, or company, so the agent stops handing users lookalike download sites. Ownership only, never safety. Every verdict is backed by reproducible evidence. Tools: get_official_url(name), verify_url(url). No auth required.
Domain security reconnaissance tools for AI agents via Model Context Protocol. 13 security tools — DNS, SSL, HTTP headers, email auth, port scan, propagation, reverse DNS, ASN/BGP, RDAP/WHOIS, subnet calc, and comprehensive security scan — callable from Claude Desktop and any MCP-compatible AI agent. Part of DechoNet. Every tool here is also a free web tool at dechonet.com — no sign-up, no API key — backed by error-fix guides. This package brings the same checks to AI agents.
Discovery, OAuth, project operations, and exact project MCP handoff for Spala backend projects.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Give your AI agent an identity it owns: email inbox, US phone number, SMS, voice, and a vault.
Fallax is a phishing simulation and security awareness training platform. Read your results.