"OWASP Dependency-Check" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Pre-trade token safety check for AI agents. Simulates a sell before you buy, then returns one low/medium/high/unknown verdict with the signals behind it: sellability, buy/sell tax, liquidity depth, pair age, same-ticker impersonation, owner powers from bytecode. Ethereum, BSC, Base, Solana. Fail-closed - a check that cannot run answers unknown, never low. Publishes its own measured error rate with the benchmark harness in the repo. Free, no signup, no API key, MIT.
Inspect one endpoint's served certificate, expiry, hostname coverage, and accepted TLS versions.
Magery Forge is a security-audit engine for people who ship code fast and don't have a security team. Use cases: • Pre-release security check • Weekly automated security monitoring • Agent-driven security scanning (MCP) • Clearing a shipped product of common vulnerabilities before users hit them
Email security and AI discoverability scores for any domain, with the exact record or tag to fix.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
Verify anything: email, phone, domain, URL and IBAN validation, phishing/malware URL screening, and OFAC sanctions checks. Pay-per-check in USDC on Base via x402 — no signup, no API keys.
Trust infrastructure for AI agents: check reliability, verification, and trustDecision by URL.
Pre-send EVM address checks: free pre-check, $0.01 check, $0.05 deep scan. x402: payment is auth.
Live-checks whether a WordPress site is ready to be safely operated by AI agents.
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
Check a document for hidden text before your agent reads it. PDF, Office, RTF, HTML.
Email posture for any domain: can it receive mail, can it be spoofed? MX, SPF and DMARC.
Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.
npm/PyPI/Django dependency upgrades: security, runtime compatibility, migration, package ranking.
Check x402 endpoints before spending: free readiness and policy checks, paid trust evidence.
Verify artifacts, hand off public state, and record, check and find evidence about capabilities.