Audits any MCP server (stdio or Streamable HTTP, legacy or modern era) with wire-level conformance, security, and behavior-regression checks, producing a fingerprinted delivery report and CI regression suite.
Passive security scanner that audits a running MCP server against the OWASP MCP Top 10 and grades it A-F. Read-only static analysis of the advertised tools, prompts and resources with console/JSON/SARIF output, and it also runs as an MCP server itself.
A domain security and privacy checker MCP server that runs locally, performing DNS, TLS, HTTP, and RDAP lookups to generate a scored report covering certificates, email authentication, DNS, and web security headers.
Security auditor for MCP servers that enumerates tools, resources, and prompts, scans for injection patterns, classifies risk levels, and produces a scored report (0-100, grades A-F).
Audits HAR captures locally with MCP tools for triage, findings, vendor blast radius, CSP generation, and sanitization—no network calls, redacted by default.