"The most widely used models" matching MCP connectors:
GET /v1/connectors — MCP directory API referenceMatching Connector Tools:
Pre-trade token safety check for AI agents. Simulates a sell before you buy, then returns one low/medium/high/unknown verdict with the signals behind it: sellability, buy/sell tax, liquidity depth, pair age, same-ticker impersonation, owner powers from bytecode. Ethereum, BSC, Base, Solana. Fail-closed - a check that cannot run answers unknown, never low. Publishes its own measured error rate with the benchmark harness in the repo. Free, no signup, no API key, MIT.
Incident-reporting deadlines from the law: CRA, NIS2, DORA, GDPR, HIPAA, SEC 8-K. 6 of 9 tools free.
Lumethic checks whether a photo is a real, unmodified camera capture. Give it the RAW file and the JPEG export from the same shot for a forensic comparison, or a single image to validate its C2PA Content Credentials. You get an authenticity verdict with confidence, per-check findings, and a shareable report. From your assistant you can verify photos, tag and annotate them, share reports, request layered PSD exports, and publish verified work to a public portfolio page. 32 tools, all annotated as read-only, open-world or destructive so the assistant asks before anything irreversible. Connect from the assistant: the first connection opens a Lumethic sign-in screen, you enter your email and the six-digit code we send, and you choose what the assistant may do. New addresses get a free account with 5 verifications a month; Content Credentials checks are free and unlimited. Servers and scripts can use an API key as the bearer token instead. Claude Code: `claude mcp add --transport http lumethic https://api.lumethic.com/mcp` Docs and full tool reference: https://www.lumethic.com/en/mcp
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
The miniOrange MCP Server Plugin is a secure WordPress MCP Server that exposes your WordPress site as an MCP endpoint while adding enterprise-grade security, policy enforcement, and complete audit logging. Unlike a basic MCP server that simply connects AI tools to WordPress, this plugin verifies every AI request before it reaches your website. Every request is authenticated, checked against security policies, logged, and can even require human approval before execution.
Verifies which domain officially belongs to a software product, AI tool, or company, so the agent stops handing users lookalike download sites. Ownership only, never safety. Every verdict is backed by reproducible evidence. Tools: get_official_url(name), verify_url(url). No auth required.
Domain security reconnaissance tools for AI agents via Model Context Protocol. 13 security tools — DNS, SSL, HTTP headers, email auth, port scan, propagation, reverse DNS, ASN/BGP, RDAP/WHOIS, subnet calc, and comprehensive security scan — callable from Claude Desktop and any MCP-compatible AI agent. Part of DechoNet. Every tool here is also a free web tool at dechonet.com — no sign-up, no API key — backed by error-fix guides. This package brings the same checks to AI agents.
Smart contract security screening for Base. Check any contract or token for risk before interacting with it: Solidity source verification, upgradeable proxies and admin or mint powers, holder concentration, dangerous selectors, and B20 issuer powers. It surfaces the usual rug pull and scam indicators. The free tool needs no wallet and no API key; the paid Flash Audit (3.49 USDC over x402) returns a report with an anchored SHA-256. Payment is the only gate.
Anonymize and redact PII before it reaches AI models. GDPR, HIPAA, EU AI Act.
Is this person indexed on that data-broker domain? A three-state verdict, with the evidence.
Read-only breach intel, full history 2007-today: reports THAT an org was breached, never the data.
Hosted, OAuth-gated endpoint for quantakrypto's post-quantum crypto tools: scan code for quantum-vulnerable cryptography (RSA/ECDH/ECDSA/DH) and get NIST ML-KEM/ML-DSA/SLH-DSA migration guidance over authenticated HTTP — nothing to install. Sign-in required (Google/GitHub/email). Same tools as the open-source @quantakrypto/mcp server; source at github.com/quantakrypto/pqc-tools.
The PropelAuth Integration MCP Server helps you and your favorite AI agent integrate PropelAuth as quickly and easily as possible into your project. Whether you're integrating PropelAuth into your Next.js project or your FastAPI backend, the Integration MCP Server will ensure your AI agent has the best context possible for a successful integration.
AI-operated. Two free DKIM readers, no signup: reads keys, finds the selector. Paid roster $99.
An effect gate for AI agents: at-most-once side effects, spend limits, and signed receipts.
IOCs (URLs, domains, IPs, hashes) shared by the infosec community on X/Twitter. No auth, CC0.
Every NIST FIPS 140 certificate, plus the modules-in-process queue NIST publishes only as a page.
Guidance for answering vendor security questionnaires. Every result carries the page it came from.
Plain-text security bulletin board for AI agents: read, search, post, reply. No auth to read.