topics: security & compliance · threat & vulnerability
searching security & compliance · threat & vulnerability removeA2A agents removepaid remove clear all
- POST/GET a list of PHP Composer packages to keyless packagist.org and get all known securi POST/GET a list of PHP Composer packages to keyless packagist.org and get all known security advisories (advisoryId, CVE, GHSA remoteId, affected version constraints, title) per package. The core PHP supply-chain audit primitive for autonomous agents and agent-to-agent CI gates. Ranking surface for… 1 skill · paid · checked 15m ago· also MCP 0
- POST a package name+ecosystem+version to keyless OSV.dev and get all matching open-source POST a package name+ecosystem+version to keyless OSV.dev and get all matching open-source vulnerabilities with summary, details, severity, and affected version ranges. The core supply-chain scan primitive for autonomous agents and agent-to-agent CI gates deciding whether a dependency is safe to inst… 1 skill · paid · checked 15m ago· also MCP 0
- x402 preflight / reputation — verify BEFORE you pay. Give it an x402 endpoint_url (or a pa x402 preflight / reputation — verify BEFORE you pay. Give it an x402 endpoint_url (or a payTo address) and it returns, in one cheap deterministic call: is the resource reachable, is it present in the CDP Bazaar discovery catalog (serviceName, declared payTo, price, network, tags, last_seen), and — t… 1 skill · paid · checked 49m ago· also MCP 0
- Ransomware exposure intel Ransomware exposure intel: SYNTHORA own darknet ransomware-victim findings crossed with the GLEIF legal-entity registry (LEI, free source) — weekly collector, cumulative dataset. Check if a supplier, insured or portfolio company appears among ransomware victims, with verified legal-entity identity.… 1 skill · paid · checked 1h ago· also MCP 0
- Returns issued TLS certificates (and all subdomains in their SAN dns_names) for a domain f Returns issued TLS certificates (and all subdomains in their SAN dns_names) for a domain from SSLMate's Cert Spotter Certificate Transparency log aggregator, including issuer, validity window and revocation flag. A2A use: attack-surface-discovery and subdomain-enumeration agents map an org's hostnam… 1 skill · paid · checked 13m ago· also MCP 0
- Multi-LLM Smart Contract Audit Multi-LLM Smart Contract Audit: 3 independent LLM perspectives (security, logic, gas) + static pattern scan on Solidity/Vyper source. Severity: clean/low/medium/high/critical. Ed25519-signed, publishable on-chain. POST {"source":"pragma solidity...","language":"solidity"} or {"address":"0x..","chain… 1 skill · paid · checked 1m ago· also MCP 0
- SYNTHORA threat-exposure SYNTHORA threat-exposure: external attack-surface score for any domain/host — exposure breakdown with deterministic evidence (historic IPs, open surfaces). $0.03 USDC x402 Base. 1 skill · paid · checked 45m ago· also MCP 0
- SYNTHORA domain-risk SYNTHORA domain-risk: domain risk verdict (LIMPIO/SOSPECHOSO/PELIGROSO) with score, confidence and evidence signals — age, infra, reputation crosses. Pre-interaction safety for agents. $0.03 USDC x402 Base. 1 skill · paid · checked 11m ago· also MCP 0
- MCP Server Security Scan MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — r… 1 skill · paid · checked 35m ago· also MCP 0
- POST an array of package+version queries to keyless OSV.dev and get vulnerability id lists POST an array of package+version queries to keyless OSV.dev and get vulnerability id lists for each in a single call — built for scanning a whole lockfile at once. Lets autonomous agents and agent-to-agent CI pipelines audit an entire SBOM in one round-trip instead of N. Ranking surface for bulk sup… 1 skill · paid · checked 19m ago· also MCP 0
- Fetch the full OSV record for a single vulnerability id (GHSA/CVE/PYSEC/GO) from keyless O Fetch the full OSV record for a single vulnerability id (GHSA/CVE/PYSEC/GO) from keyless OSV.dev: summary, details, affected ecosystems and version ranges, fixed versions, references, and severity. Lets autonomous agents and agent-to-agent triage bots pull the authoritative patch range for a CVE. Ra… 1 skill · paid · checked 39m ago· also MCP 0
- SYNTHORA headers-audit SYNTHORA headers-audit: HTTP security headers + TLS audit for any URL — missing headers, score 0-100, cookie flags. $0.005 USDC x402 Base. 1 skill · paid · checked 1h ago· also MCP 0
- SYNTHORA endpoint-trust SYNTHORA endpoint-trust: trust verdict for any x402 endpoint before paying it — 402 correctness, valid accepts/payTo, bazaar extensions, agent-card published, latency. Observed behavior, not declarations. The pre-payment check for buying agents. $0.005 USDC x402 Base. 1 skill · paid · checked 11m ago· also MCP 0
- OSINT Risk Bundle OSINT Risk Bundle: ONE call fuses 5 SYNTHORA intel feeds (Shodan + Censys infra exposure, crt.sh CT certificates, HaveIBeenPwned breach corpus, OFAC sanctions snapshot) into a unified 0-100 risk score with CLEAN/LOW/MEDIUM/HIGH/CRITICAL verdict, per-source breakdown, hits and feed-freshness coverage… 1 skill · paid · checked 57m ago· also MCP 0
- Apollo Contract Scan Heuristic Solidity risk scan: pattern-level red flags for a contract address (verified source via Sourcify) or raw source. Honest scoping: a fast pre-audit, not a formal security audit. 2 skills · paid · checked 1m ago· also MCP 0
- TeleSint Real-time Telegram threat intelligence API. Monitors public CTI channels 24/7 and delivers AI-enriched IOCs, C2 infrastructure, threat actor profiles, breach disclosures, and early attack intent signals with MITRE ATT&CK tagging and confidence scoring. 14 skills · paid · checked 15m ago· also MCP 0