topics: security & compliance · threat & vulnerability
searching security & compliance · threat & vulnerability removeMCP servers remove clear all
- TeleSint Threat intelligence API that extracts indicators of compromise, C2 infrastructure, threat actor profiles, breach disclosures and CVE signals from public Telegram security channels, returned as structured JSON with MITRE ATT&CK tags and confidence scores. [not the operator's words] 0 skills · unprobed · checked 42m ago· also A2A 10
- synthora-mcp_scan MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — r… 1 skill · unprobed · checked 42m ago· also A2A 0
- synthora-domain_risk SYNTHORA domain-risk: domain risk verdict (LIMPIO/SOSPECHOSO/PELIGROSO) with score, confidence and evidence signals — age, infra, reputation crosses. Pre-interaction safety for agents. $0.03 USDC x402 Base. 1 skill · unprobed · checked 19m ago· also A2A 0
- synthora-ransomware_gleif Ransomware exposure intel: SYNTHORA own darknet ransomware-victim findings crossed with the GLEIF legal-entity registry (LEI, free source) — weekly collector, cumulative dataset. Check if a supplier, insured or portfolio company appears among ransomware victims, with verified legal-entity identity.… 1 skill · unprobed · checked 50m ago· also A2A 0
- synthora-threat_exposure SYNTHORA threat-exposure: external attack-surface score for any domain/host — exposure breakdown with deterministic evidence (historic IPs, open surfaces). $0.03 USDC x402 Base. 1 skill · unprobed · checked 7m ago· also A2A 0
- synthora-headers_audit SYNTHORA headers-audit: HTTP security headers + TLS audit for any URL — missing headers, score 0-100, cookie flags. $0.005 USDC x402 Base. 1 skill · unprobed · checked 1h ago· also A2A 0
- synthora-endpoint_trust SYNTHORA endpoint-trust: trust verdict for any x402 endpoint before paying it — 402 correctness, valid accepts/payTo, bazaar extensions, agent-card published, latency. Observed behavior, not declarations. The pre-payment check for buying agents. $0.005 USDC x402 Base. 1 skill · unprobed · checked just now· also A2A 0
- pulsefeed-x402 PulseFeed — verify before you pay or install. Check an x402 endpoint before paying it, audit an npm/MCP package before installing it, and read live observations of anomalies with on-chain references. All tools here are free and read-only. 11 skills · free · checked 54m ago· also A2A 0
- CF Package Check package_check costs $0.02 per call and is paid with x402 on eip155:8453. An unpaid call returns a 402 whose payment-required header carries the payment requirements. package_sources is free. 2 skills · free · checked 40m ago· also A2A 0
- com.fablerlabs/x402-tools Free catalog for Fabler's USDC-paid x402 agent tools on Base; no account or wallet required. [not the operator's words] 2 skills · free · checked 1h ago 0
- CF Package Check package_check costs $0.02 per call and is paid with x402 on eip155:8453. An unpaid call returns a 402 whose payment-required header carries the payment requirements. package_sources is free. 2 skills · free · checked 1h ago· also A2A 0
- sri Call check_mcp_server before connecting to an MCP server you have not read. It reports what the server actually does, quoted at file:line. Usage is free right now — no key, no invoice, no setup. Covers MCP servers only, not npm or PyPI libraries. To see what has already been read — and what could no… 2 skills · free · checked 7m ago 0
- Hermes Plant Deterministic pre-execution safety gates and signed evidence for AI agents. The Action Safety pair scores consequential shell, Git, SQL, infrastructure, and deployment commands, returning risk, matched rule IDs, and an exact machine-readable escalation call: $0.01 for the quick preflight, $0.25 for the full workflow with a signed receipt and free verification. [not the operator's words] 25 skills · free · checked 14m ago· also A2A 0
- shieldapi-mcp ShieldAPI - x402 security preflight before agents connect to IP infrastructure [not the operator's words] 9 skills · free · checked 18m ago 0
- mizan Call mizan_check with the endpoint URL before making any x402 payment. 'avoid' means Mizan paid that endpoint and got nothing back, with the charge visible on Base. 'unrated' means nobody has checked it — not that it is safe. 3 skills · unprobed · checked 3m ago 0
- cybercentry-x402 Cybercentry security and verification services. list_services and recent_exploits are free. Every other tool costs USDC per call, payable over x402 or with a subscription token. 12 skills · free · checked 1h ago 0
- cybercentry-x402 Cybercentry security and verification services. list_services and recent_exploits are free. Every other tool costs USDC per call, payable over x402 or with a subscription token. 12 skills · free · checked 58m ago 0
- sicherwerk Paid tools via x402. tools/list is free. Send the payment proof in the PAYMENT-SIGNATURE header for tools/call; without it, the payment request and inputSchema are returned. 23 skills · unprobed · checked 34m ago· also A2A 0
- netzhandwerker-agent-tools This listing exposes screenshot, url_risk_scan, domain_intel, the capability an agent calls it for [not the operator's words] 39 skills · unprobed · checked 52m ago· also A2A 0
- netzhandwerker-agent-tools A toolbox of agent utilities: address and email validation, domain and mail-security checks, sanctions screening, PII redaction, geocoding and analytics helpers. 39 skills · unprobed · checked 38m ago· also A2A 0
- paketwerk Paid tools use x402. tools/list is free. Send payment proof for tools/call in the PAYMENT-SIGNATURE header; without it, the payment challenge includes inputSchema. 14 skills · unprobed · checked 36m ago· also A2A 0
- uai-x402-security-mcp This listing exposes catalog, secret-scan-preview, policy-genie, the capability an agent calls it for [not the operator's words] 23 skills · unprobed · checked 3m ago 0
- depwerk Paid tools via x402. tools/list is free. Send the payment proof in the PAYMENT-SIGNATURE header for tools/call; without it, the payment request and inputSchema are returned. 10 skills · unprobed · checked 54m ago· also A2A 0
- Agent Guard Validate an EVM address (format and checksum style) or a Solana base58 address. [not the operator's words] 11 skills · unprobed · checked 8m ago 0
- com.mcpscores/dev-package-intel You are about to add a dependency and do not know if it is current, licensed for this use, deprecated, or already carries a CVE. Tool calls are x402-paid in USDC on Base — send the base64 X-PAYMENT header on this POST /mcp request (or params._meta['x402/payment']). package_info costs $0.005; package… 5 skills · unprobed · checked 9m ago 0
- safebrowz SafeBrowz detects phishing, scams, brand impersonation and crypto wallet drainers. Call check_url before visiting, buying from, or signing anything on an unfamiliar site; honor agent_action (proceed / ask_human / block). domain_history returns past threat records for a domain - absence of records do… 4 skills · unprobed · checked 17m ago 0
- synthora-code_audit Multi-LLM Smart Contract Audit: 3 independent LLM perspectives (security, logic, gas) + static pattern scan on Solidity/Vyper source. Severity: clean/low/medium/high/critical. Ed25519-signed, publishable on-chain. POST {"source":"pragma solidity...","language":"solidity"} or {"address":"0x..","chain… 1 skill · unprobed · checked 25m ago· also A2A 0
- synthora-osv_vuln_by_id Fetch the full OSV record for a single vulnerability id (GHSA/CVE/PYSEC/GO) from keyless OSV.dev: summary, details, affected ecosystems and version ranges, fixed versions, references, and severity. Lets autonomous agents and agent-to-agent triage bots pull the authoritative patch range for a CVE. Ra… 1 skill · unprobed · checked 29m ago· also A2A 0
- synthora-osv_vuln_query POST a package name+ecosystem+version to keyless OSV.dev and get all matching open-source vulnerabilities with summary, details, severity, and affected version ranges. The core supply-chain scan primitive for autonomous agents and agent-to-agent CI gates deciding whether a dependency is safe to inst… 1 skill · unprobed · checked 1m ago· also A2A 0
- synthora-depsdev_dependency_graph Returns the fully resolved transitive dependency tree (direct + indirect nodes with pinned versions and relation type) for a package version, from keyless deps.dev. Powers autonomous agents doing supply-chain blast-radius analysis, dependency-confusion detection, and agent-to-agent SBOM generation.… 1 skill · unprobed · checked 31m ago· also A2A 0
- synthora-osint OSINT Risk Bundle: ONE call fuses 5 SYNTHORA intel feeds (Shodan + Censys infra exposure, crt.sh CT certificates, HaveIBeenPwned breach corpus, OFAC sanctions snapshot) into a unified 0-100 risk score with CLEAN/LOW/MEDIUM/HIGH/CRITICAL verdict, per-source breakdown, hits and feed-freshness coverage… 1 skill · unprobed · checked 46m ago· also A2A 0
- synthora-osv_vuln_querybatch POST an array of package+version queries to keyless OSV.dev and get vulnerability id lists for each in a single call — built for scanning a whole lockfile at once. Lets autonomous agents and agent-to-agent CI pipelines audit an entire SBOM in one round-trip instead of N. Ranking surface for bulk sup… 1 skill · unprobed · checked 12m ago· also A2A 0
- synthora-certspotter_ct_issuances Returns issued TLS certificates (and all subdomains in their SAN dns_names) for a domain from SSLMate's Cert Spotter Certificate Transparency log aggregator, including issuer, validity window and revocation flag. A2A use: attack-surface-discovery and subdomain-enumeration agents map an org's hostnam… 1 skill · unprobed · checked 30m ago· also A2A 0
- synthora-packagist_security_advisories POST/GET a list of PHP Composer packages to keyless packagist.org and get all known security advisories (advisoryId, CVE, GHSA remoteId, affected version constraints, title) per package. The core PHP supply-chain audit primitive for autonomous agents and agent-to-agent CI gates. Ranking surface for… 1 skill · unprobed · checked 25m ago· also A2A 0
- cve-security Read-only CVE intelligence. All tools are keyless over MCP; an API key on the HTTP request (Authorization: Bearer cvs_live_…, free via POST /api/signup) is honored for attribution. Absence semantics apply to every field: null means this dataset holds no record. The source may still hold one. 9 skills · unprobed · checked 31m ago 0
- nist-nvd-mcp-server This server provides read-only access to the NIST National Vulnerability Database (NVD). - Use nvd_search_cves to discover CVEs by keyword, severity, CWE, date range, or CISA KEV status. - Use nvd_get_cve for full CVSS details on specific CVE IDs (up to 100 per call). - Use nvd_search_cpes to find t… 5 skills · free · checked 1h ago 0
- x402.robtex.com/api/v1/check_email Added by scraper. Domain owners can authenticate for free to edit information. [not the operator's words] 0 skills · unprobed · checked 48m ago 0
- apollo-contract-scan.vercel.app Heuristic Solidity risk scan: pattern-level red flags for a contract address (verified source via Sourcify) or raw source. Honest scoping: a fast pre-audit, not a formal security audit. [not the operator's words] 0 skills · unprobed · checked 54m ago· also A2A 0
- cisa-cybersecurity-mcp-server This server serves four CISA datasets, all keyless and all read-only. Start at cisa_check_cve_status for CVE IDs you already have — it answers up to 200 per call from a cached catalog at no upstream cost — and at cisa_search_kev to discover entries by vendor, due date, or overdue status. cisa_get_ss… 7 skills · free · checked 50m ago 0
- shadow-ai-list Shadow AI List is a maintained, risk-ranked registry of AI tools (the 'AI Exposure Index'). Use these tools to look up an AI tool's data-exposure risk, check whether a domain is a known AI tool (i.e. shadow AI on a network), browse tools by category, or get the highest-risk AI tools. Coverage is the… 4 skills · free · checked 42m ago 0