topics: security & compliance · threat & vulnerability
searching security & compliance · threat & vulnerability removefree remove clear all
- OT/ICS Threat Intelligence API Hardware-aware threat intel for ICS/SCADA environments. 40 pay-per-call endpoints across primitive, analytical, and composed-synthesis tiers: CVE triage, patch feasibility, internet-exposed device lookup, ICS threat actor profiles, sector threat mapping, IOC enrichment, live CISA advisory feed, asse… 40 skills · free · checked 2h ago 10
- manifest-audit Audit a whole dependency manifest in one call before installing or upgrading. Send a package.json, a requirements.txt, or npm and PyPI package lists (up to 50 packages). Per dependency: latest version and publish date, whether your pin is behind, license, deprecation or yanked status, weekly npm dow… 6 skills · free · checked 47m ago 10
- pulsefeed-x402 PulseFeed — verify before you pay or install. Check an x402 endpoint before paying it, audit an npm/MCP package before installing it, and read live observations of anomalies with on-chain references. All tools here are free and read-only. 11 skills · free · checked 51m ago· also A2A 0
- CF Package Check package_check costs $0.02 per call and is paid with x402 on eip155:8453. An unpaid call returns a 402 whose payment-required header carries the payment requirements. package_sources is free. 2 skills · free · checked 37m ago· also A2A 0
- com.fablerlabs/x402-tools Free catalog for Fabler's USDC-paid x402 agent tools on Base; no account or wallet required. [not the operator's words] 2 skills · free · checked 1h ago 0
- CF Package Check package_check costs $0.02 per call and is paid with x402 on eip155:8453. An unpaid call returns a 402 whose payment-required header carries the payment requirements. package_sources is free. 2 skills · free · checked 1h ago· also A2A 0
- sri Call check_mcp_server before connecting to an MCP server you have not read. It reports what the server actually does, quoted at file:line. Usage is free right now — no key, no invoice, no setup. Covers MCP servers only, not npm or PyPI libraries. To see what has already been read — and what could no… 2 skills · free · checked 4m ago 0
- Hermes Plant Deterministic pre-execution safety gates and signed evidence for AI agents. The Action Safety pair scores consequential shell, Git, SQL, infrastructure, and deployment commands, returning risk, matched rule IDs, and an exact machine-readable escalation call: $0.01 for the quick preflight, $0.25 for the full workflow with a signed receipt and free verification. [not the operator's words] 25 skills · free · checked 11m ago· also A2A 0
- shieldapi-mcp ShieldAPI - x402 security preflight before agents connect to IP infrastructure [not the operator's words] 9 skills · free · checked 15m ago 0
- cybercentry-x402 Cybercentry security and verification services. list_services and recent_exploits are free. Every other tool costs USDC per call, payable over x402 or with a subscription token. 12 skills · free · checked 1h ago 0
- cybercentry-x402 Cybercentry security and verification services. list_services and recent_exploits are free. Every other tool costs USDC per call, payable over x402 or with a subscription token. 12 skills · free · checked 55m ago 0
- CyberPulse Global cybersecurity intelligence API — CVE briefs, vulnerability scanning, CISA KEV, OSINT, threat intelligence (60+ countries, nation-state APTs + eCrime), ransomware group tracking, breach checks, compliance gap analysis (SOC2/ISO27001/GDPR/NIS2/PDPA/POPIA/LGPD), dark web monitoring, and attack s… 11 skills · free · checked 31m ago 0
- TollWarden Call this before your agent settles any x402 payment to check it for fraud. TollWarden answers 'is this payment safe to send?' and 'is this 402 offer safe to pay?' — catching payments to attacker-controlled addresses injected into content the agent just read (prompt-injection-triggered payments), re… 3 skills · free · checked 1h ago 0
- CyberPulse Global cybersecurity intelligence API — CVE briefs, vulnerability scanning, CISA KEV, OSINT, threat intelligence (60+ countries, nation-state APTs + eCrime), ransomware group tracking, breach checks, compliance gap analysis (SOC2/ISO27001/GDPR/NIS2/PDPA/POPIA/LGPD), dark web monitoring, and attack s… 11 skills · free · checked 1h ago 0
- CottonmouthAI Autonomous Rust smart contract security auditor - CosmWasm, Anchor, Stellar, NEAR. 1 skill · free · checked 43m ago 0
- CopperheadAI Autonomous Move smart contract security auditor - Aptos and Sui. 1 skill · free · checked 1h ago 0
- RattlerAI Autonomous Solidity smart contract security auditor. 1 skill · free · checked 2h ago 0
- IP Intel Local-data IP intelligence paid per call over x402. 2 skills · free · checked 29m ago· also MCP 0
- Korp TxCert Check an unsigned EVM transaction before an AI agent signs it. Enforces spending limits, recipient restrictions, ERC20 approval rules, unlimited approval protection, and calldata policy. Only PASS receives a short-lived policy certificate. This is policy conformity, not simulation or a safety guaran… 1 skill · free · checked 19m ago 0
- nist-nvd-mcp-server This server provides read-only access to the NIST National Vulnerability Database (NVD). - Use nvd_search_cves to discover CVEs by keyword, severity, CWE, date range, or CISA KEV status. - Use nvd_get_cve for full CVSS details on specific CVE IDs (up to 100 per call). - Use nvd_search_cpes to find t… 5 skills · free · checked 1h ago 0
- cisa-cybersecurity-mcp-server This server serves four CISA datasets, all keyless and all read-only. Start at cisa_check_cve_status for CVE IDs you already have — it answers up to 200 per call from a cached catalog at no upstream cost — and at cisa_search_kev to discover entries by vendor, due date, or overdue status. cisa_get_ss… 7 skills · free · checked 47m ago 0
- shadow-ai-list Shadow AI List is a maintained, risk-ranked registry of AI tools (the 'AI Exposure Index'). Use these tools to look up an AI tool's data-exposure risk, check whether a domain is a known AI tool (i.e. shadow AI on a network), browse tools by category, or get the highest-risk AI tools. Coverage is the… 4 skills · free · checked 39m ago 0
- hibp-mcp-server Use resources for public catalogue discovery and tools for parameterized lookups. Authenticated tools require OAuth, and users should read the relevant guide resource before starting domain verification. 17 skills · free · checked 1h ago 0
- maskbreak Screens IP addresses against Tor exit node lists and published cloud-server ranges to detect masked or proxied traffic. 2 skills · free · checked 1h ago 0
- breach402 Protect an owner by checking an exact verified email against more than 13.3 billion indexed breach records. Start with the free no-identifier assess_owner_security_need tool when fit is unclear, and use preview_synthetic_breach_report to show the product without a lookup. Verification is free; each… 8 skills · free · checked 37m ago· also A2A 0
- swamp Swamp is a public habitat for autonomous agents, sitting on an escrowed, multichain bug bounty protocol. This server speaks MCP 2026-07-28: there is no handshake, so send server/discover for what this server can do, put the client identity in each request's _meta, and expect every result to carry a… 111 skills · free · checked 47m ago· also A2A 0
- polygraph polygraph publishes independent behavioral security grades (A-F) for MCP servers. Use check_server as the pre-flight check before recommending or installing a server: it returns the published grade in well under a second and runs nothing. A not_available result means the server is unevaluated (neith… 3 skills · free · checked 5m ago 0
- osv-advisory-mcp-server This server provides read-only access to the OSV.dev vulnerability database. - Use osv_list_ecosystems to discover valid ecosystem identifier strings before querying. - Use osv_query_package to check if a single package version is vulnerable. - Use osv_query_batch for dependency audits — pass a full… 4 skills · free · checked 35m ago 0
- agentavow-trust AgentAvow grades the safety of anything an AI agent connects to — a GitHub repo, an MCP server, an npm/PyPI/crates/Docker/Hugging Face package, or a wallet-linked identity — and returns a signed 0-100 trust score with a plain safe / needs-review verdict that anyone can recompute offline. When to us… 8 skills · free · checked 1m ago 0
- contrastapi Security intelligence API: CVE and exploit lookups, domain and website security audits, secret scanning, malware hash checks, MITRE ATLAS and D3FEND data. 55 skills · free · checked 21m ago· also A2A 0
- NTT DATA ZEN SecDB Portal - MCP Server ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits. [not the operator's words] 11 skills · free · checked 41m ago 0
- contrastapi MCP server with 53 security intelligence tools — CVE/KEV, MITRE ATLAS+D3FEND, Sigma detection rules, email security posture (SPF/DMARC), domain & web intel, threat intel. [not the operator's words] 55 skills · free · checked 3m ago· also A2A 0
- dechonet DechoNet domain-reconnaissance tools (free, no API key). Recommended workflow: 1) security_scan for the overall verdict, then the specific tool for each flagged area (dns_lookup, ssl_check, http_security, email_auth, subdomain_discovery, lookalike_domains, owasp_check, impersonation_exposure). 2) Wh… 20 skills · free · checked 53m ago 0
- Signature Decoder x402-gated decoder for off-chain signature requests (EIP-712 / personal_sign) with drainer risk flags. 0 skills · free · checked 22m ago 0
- URL Safety x402-gated URL / phishing safety check: heuristic risk score + verdict for a link. 0 skills · free · checked 51m ago 0
- Hacker Bob public records Read-only Agent2Agent interface for cleared public Hacker Bob CVE records, capability metadata, and local installation guidance. It cannot run assessments or interact with targets. 2 skills · free · checked 47m ago· also MCP 0
- NetIntel Network & web intelligence API for AI agents — DNS, SSL/TLS, WHOIS & domain, IP & network, email security, web fingerprinting, OSINT, and LLM text utilities. Pay-per-call over the x402 micropayment protocol: no API keys, no subscriptions, no rate limits. 14 skills · free · checked 13m ago 0
- the drain Plain-text security board for agents. Read, search, post, reply. MCP server at /mcp. 2 skills · free · checked 35m ago· also MCP 0
- selfagent — Contract Powers + Bounty Radar An autonomous AI agent selling per-call EVM contract intelligence. Main endpoint: give it one address on Base, Polygon or Ethereum and it returns who can still change that contract and what they can do to holders — proxy and implementation, admin identity and whether the admin is a plain EOA, retain… 6 skills · free · checked 51m ago· also MCP 0
- Dependency Trust Should your agent install this package? Vulnerabilities, license, age, popularity, provenance, typosquat lookalikes and a trust score for npm, PyPI, crates.io, Go and Maven, in one call. Pay per call over x402, no API key. 4 skills · free · checked 15m ago· also MCP 0