Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Changed the definition of "supply_chain_check"
⟨171 unchanged words⟩ in unavailable_checks and overall_risk is 'incomplete', never 'no_signals_found'. Also flags a version marked deprecated on npm or yanked on PyPI.
Changed the definition of "supply_chain_check"
⟨62 unchanged words⟩ gets overall_risk 'package_not_found': the name may be invented,doand should notinstallbeit.installed. A package first published less than 30 days ⟨12 unchanged words⟩ invented and look-alike names get registered, soconfirmthe name is worth confirming against the project's own documentation before installing ( ⟨65 unchanged words⟩
Changed the definition of "address_risk", "ai_crawler_check", "base64" and 37 more
before
—after
Crypto address sanctions check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Crypto address sanctions check"}
before
—AI crawler check
Changed the definition of "maintainer_change_check"
Publisher-change analysis is npm only. Also reports whether the package exists (found) and its age (first_published, package_age_days, new_package if first published less than 30 days ago), for npm and for PyPI; on PyPI only existence and age are available. Flags a previously unseen human publisher taking over ⟨62 unchanged words⟩
{"properties":{"ecosystem":{"description":"Currentlynpmonly(full'npm'analysis)isorsupported.
Changed the definition of "supply_chain_check"
⟨67 unchanged words⟩ may be invented, do not install it. A package first published less than 30 days ago gets the 'new_package' flag and overall_risk 'review_recommended': new packages are where invented and look-alike names get registered, so confirm the name against the project's own documentation before installing (on PyPI the age is that of the oldest release still published; being new does not make a package malicious). Use the individual tools to investigate one signal. ⟨36 unchanged words⟩
Changed the definition of "password_check", "supply_chain_check" and "typosquat_check"
Scores a password's strength (length, character variety, entropy as an upper bound,commonrepeatedpatternspatterns; passphrases are estimated per word) and, with check_breach=true, also looks it ⟨9 unchanged words⟩ k-anonymity (only a hash prefix is sent).; a password found in breaches is always rated very_weak. Use it to evaluate a password someone is ⟨28 unchanged words⟩
Certificate changed, valid to 2026-12-29
Changed the definition of "supply_chain_check"
⟨31 unchanged words⟩ use the individual tools to investigate one signal. Vulnerabilities are checked for the given version, or the latest published one (version_checked, version_source). If a check could not run (rate limit, upstream error), it is listed in unavailable_checks and overall_risk is 'incomplete', never 'no_signals_found'.
⟨17 unchanged words⟩ name to check.","type":"string"},"version":{"description":"Exact version to check for known vulnerabilities. Optional: defaults to the latest published version (npm and PyPI).","type":"string"}},"required":["ecosystem","package"],"type":"object"}
Changed the definition of "link_metadata"
⟨10 unchanged words⟩ URL, Open Graph and Twitter Card tags and favicon (the data behind link previews).ToFollowsfollowredirectsaandURL'sreturnsredirectsfinal_url;hopfavicon_source says whether the icon is declared by the page or only the /favicon.ico guess. To see each redirect hop, use redirect_trace.
Certificate changed, valid to 2026-12-29
Changed the definition of "email_verify"
⟨29 unchanged words⟩ a single signal. Does not probe the mailbox. valid is null (not false) when the MX lookup could not be completed; retry later instead of treating the address as invalid.
Changed the definition of "address_risk" and "password_breach"
Screens a crypto address againsttheevery OFAC SDNsanctionsdigital currency address list. EVMaddresses(0x...)onlyand Bitcoin (0x...bc1...,Ethereum1...,BSC3...) addresses are fully covered (sanctioned true or false,Arbitrumwithand
Changed the definition of "base64", "csv_json", "favicon" and 4 more
{"properties":{"action":{"description":"Either\\\"encode\\\"'encode' or\\\"decode\\\".'decode'.","type":"string"},"text":{ ⟨16 unchanged words⟩
Converts CSV text to JSON or JSON to CSV (direction=: csv-to-json or json-to-csv), for data passedinlineinline. CSV must be comma-separated, with a header row and at least one data row; double-quoted fields may contain commas. Semicolon- or tab-separated input is not detected and comes back
Changed the definition of "address_risk", "ai_crawler_check", "base64" and 37 more
⟨3 unchanged words⟩ EVM address (0x + 40 hex chars)orto screen against the OFAC SDN list. Cosmos SDK bech32addressaddressestoarecheckacceptedagainstbutthenotOFACscreened:SDNtheysanctions
Removed "ip"; changed the definition of "address_risk", "ai_crawler_check", "base64" and 37 more (41 tools before, 40 now)
CheckScreens a crypto address against the OFAC SDN sanctionslistlist. EVM addresses only (0x..., Ethereum, BSC, Arbitrum and other EVM chains); Cosmos bech32 addresses are recognized but not yet screened against any sanctions source.
Added "cve_lookup", "iban_validate", "link_metadata" and 1 more (37 tools before, 41 now)
Direct CVE/GHSA vulnerability lookup by identifier
Validate an IBAN (ISO 7064 mod-97 checksum)
Extract Open Graph / Twitter Card metadata from a URL
Validate an EU VAT number via the official VIES service
Changed the definition of "ip_reputation"
IP reputation check(SpamhausagainstDROP)a curated list of known spam/hijacker netblocks
⟨2 unchanged words⟩ {"description":"IPv4 address to check againstthe SpamhausaDROPcurated list of known spam/hijacker netblocks.","type": ⟨5 unchanged words⟩
Added "rpc_check" and "tx_decode" (35 tools before, 37 now)
Audit a CometBFT RPC endpoint (health, peers, unsafe-method exposure)
Decode a raw signed Cosmos SDK transaction (protobuf)
Added "address_risk" (34 tools before, 35 now)
Check a crypto address against the OFAC sanctions list (EVM)
Added "supply_chain_check" (33 tools before, 34 now)
Combined supply-chain risk check (maintainer-change + vulnerability + typosquat + repo-health)
Certificate recorded, valid to 2026-10-31
Authorization not required
Unknown → Live
First tool surface recorded: 33 tools (server version 2.0.0)
https://presend.pages.dev/mcp (mcp_streamable_http) — from mcp_registry, with the record
Showing the latest 25 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"AI crawler check"}
before
—after
Base64 encode / decode{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Base64 encode / decode"}
before
—after
Color converter{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Color converter"}
before
—after
CSV / JSON converter{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"CSV / JSON converter"}
before
—after
CVE lookup{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"CVE lookup"}
before
—after
DNS lookup{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"DNS lookup"}
before
—after
Disposable email check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Disposable email check"}
before
—after
Email domain security check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Email domain security check"}
before
—after
Email address validation{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Email address validation"}
before
—after
Email verification{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Email verification"}
before
—after
Favicon lookup{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Favicon lookup"}
before
—after
IBAN validation{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"IBAN validation"}
before
—after
IP reputation check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"IP reputation check"}
before
—after
JWT decode{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"JWT decode"}
before
—after
JWT signature verification{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"JWT signature verification"}
before
—after
Link preview metadata{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Link preview metadata"}
before
—after
Package maintainer change check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Package maintainer change check"}
before
—after
Password generator{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Password generator"}
before
—after
Password breach check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Password breach check"}
before
—after
Password strength check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Password strength check"}
before
—after
Phone number validation{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Phone number validation"}
before
—after
Redirect trace{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Redirect trace"}
before
—after
Repository health check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Repository health check"}
before
—after
Cosmos RPC endpoint check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Cosmos RPC endpoint check"}
before
—after
HTTP security headers check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"HTTP security headers check"}
before
—after
Website security scan{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Website security scan"}
before
—after
Subdomain discovery{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Subdomain discovery"}
before
—after
Package supply-chain check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Package supply-chain check"}
before
—after
Text similarity{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Text similarity"}
before
—after
Timestamp converter{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Timestamp converter"}
before
—after
Cosmos transaction decoder{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Cosmos transaction decoder"}
before
—after
Package typosquat check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"Package typosquat check"}
before
—after
URL tracking-parameter cleaner{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"URL tracking-parameter cleaner"}
before
—after
URL reputation check{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"URL reputation check"}
before
—after
User-Agent parser{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"User-Agent parser"}
before
—after
UUID generator{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true,"title":"UUID generator"}
before
—after
EU VAT number validation{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"EU VAT number validation"}
before
—after
Package vulnerability check⟨15 unchanged words⟩ crates.io, Maven, RubyGems, Packagist and NuGet. For npm and PyPI, a name that does not exist returns found: false and vulnerable: null, never a clean result. Use cve_lookup when you already have a CVE/GHSA ⟨7 unchanged words⟩
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"Package vulnerability check"}
before
—after
WHOIS lookup{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true,"title":"WHOIS lookup"}
Call before installing a package whose name you typed or recalled. Checks whether an npm or PyPI package name ⟨35 unchanged words⟩ result does not prove a package is safe. It does not check that the package exists: supply_chain_check does.
{"properties":{"address":{"description":"EVMAddressaddressto screen: EVM (0x + 40 hex chars)toorscreenBitcoinagainst(bc1...,the1...,OFAC3...),SDNbothlist.fullyCosmoscovered.SDKAddressesbech32ofaddressesother chains areacceptedmatchedbutagainstnottheirscreened:liststheytoo; bech32 addresses of other chains (e.g. cosmos1...) return sanctioned: null (unchecked, not clean).when not listed.","type":"string"}},"required": ⟨3 unchanged words⟩
⟨3 unchanged words⟩ :"Password to check against known data-breach corpora.Checked via k-anonymity (onlyOnly apartial5-character SHA-1 hash prefix is sent to HIBP (k-anonymity),--but thefullpasswordisitselfnevertravelstransmitted.in this request's URL; for real passwords, prefer password_check, which takes it in a POST body.","type":"string"}},"required": ⟨3 unchanged words⟩
⟨15 unchanged words⟩ string"},"direction":{"description":"Either\\\"csv-to-json\\\"'csv-to-json' or\\\"json-to-csv\\\".'json-to-csv'.","type":"string"}},"required": ⟨4 unchanged words⟩
Returns the favicon URLfora website declares: fetches the homepage and takes the first <link rel='icon'> (or 'shortcut icon') href, resolved to an absolute URL, which may be adomain.data: URI when the page inlines its icon (source: declared). If no iconcanis declared, or the homepage cannot beverifiedfetched,a defaultreturnsguesstheisconventionalreturnedhttps://<domain>/favicon.ico with source: default and a note,sayingwithoutso.checking that it exists. Use it to display a site icon; it does not download or validate the image.
⟨20 unchanged words⟩ 365 days (the event-stream attack pattern).CI/trusted-publishingnpmandtrusted publishing (verified OIDC identity, not just a bot-like account name), pre-release,transitionsand handovers to a publisher who already maintains another widely used package (100k+ weekly downloads) are reported but not flagged. Does not detect ⟨9 unchanged words⟩
{"properties":{"ecosystem":{"description":"Currently only\\\"npm\\\"'npm' is supported.","type":"string"}," ⟨13 unchanged words⟩
⟨5 unchanged words⟩ , character variety, entropy, common patterns) and,canwith check_breach=true, alsochecklooks itagainstup in Have I Been Pwned breach data viak-anonymity.k-anonymityThe(onlypassworda hash prefix is sent). Use it to evaluate a password someone is choosing; use password_breach when you only need the breach count, and password to generate a new one. The password travels in a POST body, never in a URL.
GitHub repository healthMaintenance signalsfromforthea GitHubAPIrepository given as owner/name: stars, forks, open issues, license, archivedstatusand fork flags, creation date and age, days since lastpush.push,Inputtopics. Use it to judge whether a dependency looks maintained or abandoned. For an npm or PyPI package whose repository you do not know, supply_chain_check resolves it from registry metadata and includes these signals. GitHub only; missing or private repositories return found:owner/name.false.
Auditsa URL'sthe HTTP security headers of one URL (CSP, HSTS, X-Frame-Options, Permissions-Policy, cross-origin policies and others):and returns per-header findings with fix advice, a score and a letter grade.AlsoUseincludedit when you need header hardening advice; security_scan runs this audit together with URL reputation and subdomain discovery insecurity_scan.one call.
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}EncodeEncodes text to Base64 ordecodedecodes a Base64 string back to text (action = encode or decode).
ConvertConverts a colorformatsbetween hex, RGB and HSL. Provide exactly one of hex, rgb or hsl.
ConvertConvertsbetweenCSV text to JSONandor JSON to CSV (GETdirection = csv-to-json or json-to-csv), for data passed inline as text.
DirectLooksCVE/GHSAupvulnerabilityalookupvulnerability by identifier (CVE, GHSA or other OSV ID) on OSV.dev: summary, CVSS severity, affected packages and versions, references. Use when you already have an ID; use vulnerability_check when you have a package name instead.
Returns DNSrecordrecordslookupfor(a domain via Cloudflare DNS-over-HTTPS: A, AAAA, CNAME, MX, TXT,and NS)in one call, or a single record type with 'type'. For registration data use whois_lookup; for SPF/DMARC/DKIM analysis use email_security.
DetectChecksdisposableonly whether an emaildomainsaddress uses a known disposable/temporary email domain. For syntax, MX, disposable and role-account checks in one call, use email_verify.
DomainAudits a domain's email anti-spoofingchecksetup:(SPF/DMARC/DKIM)SPF strength, DMARC policy and a best-effort DKIM lookup on common selectors. A missing DKIM match does not prove DKIM is absent. Checks a domain, not a single address.
ValidateLightweight email check: syntax plus confirmation that the domain has anaddressrecord. Does not detect disposable or role addresses; use email_verify for the combined check.
CombinedMost complete emailverificationcheck in one call: syntax, MX record, disposable-domain detection and role/generic account detection (e.g. info@, admin@). Prefer it over email_validate and email_disposable unless you need a single signal. Does not probe the mailbox.
Fetch aReturnsdomain'sthe favicon URL for a domain. If no icon can be verified, a default guess is returned with a note saying so.
ValidateValidates an IBAN(offline: ISO 7064 mod-97 checksum)and country-specific length. Confirms the number is well-formed, not that the account exists.
IPChecksreputationancheckIPv4 or IPv6 address against a curated list of netblocks knownspam/hijackertonetblocksbe hijacked or run by spam/cyber-crime operations (IPv4-mapped IPv6 uses the IPv4 list). A narrow list-based signal: a clean result is not a safety guarantee. Includes list date and attribution.
{"properties":{"ip":{"description":"IPv4 or IPv6 address to check (IPv4-mapped IPv6 such as ::ffff:1.2.3.4 is checked against the IPv4 list) against a curated list of knownspam/hijackerhijacked or cyber-crime-controlled netblocks.","type":"string"}},"required ⟨3 unchanged words⟩
DecodeDecodes aJWTJWT's header and payload WITHOUT verifying its signature, so its claims must not be trusted on this basis alone. To check authenticity, use jwt_verify.
VerifyCryptographicallyaverifiesJWT'sacryptographicJWT signature (HS256/384/512, RS/PS256/384/512, ES256/384/512) and checks exp/nbf claims. Provide a secret for HS*, or a JWK or JWKS URL for RS/PS/ES. Use instead of jwt_decode whenever authenticity matters.
ExtractFetches a web page and extracts its title, description, canonical URL, Open Graph/and Twitter Cardmetadatatagsfrom(the data behind link previews). To follow aURLURL's redirects hop by hop, use redirect_trace.
Detectnpm only. Flags asuspiciouspreviouslynpmunseen human publisher taking over a packagemaintainerafterchange180+ days of inactivity, within the last 365 days (the event-stream attack pattern). CI/trusted-publishing and pre-release transitions are reported but not flagged. Does not detect hijacked existing accounts; a heuristic for review, not proof.
GenerateGenerates asecurerandom password, with options for length, symbols, uppercase, numbers and excluding ambiguous characters. To evaluate an existing password, use password_check.
CheckChecksifwhether a passwordhasappearsbeeninbreachedknown data breaches (Have I Been Pwned) and how many times, using k-anonymity towards HIBP. Breach check only; password_check adds strength scoring and sends the password in a POST body.
CombinedScorespassworda password's strength+(length,breachcharacter variety, entropy, common patterns) and can also check it against Have I Been Pwned breach data via k-anonymity. The password is sent in a POST body, never in a URL.
ValidateValidates andformatformats a phone number: validity, country, line type, E.164, international and national formats. Numbers without a leading + require 'country', since the end user's country cannot be inferred over MCP.
⟨4 unchanged words⟩ 3166-1 alpha-2 country code (e.g. US, FR), used.toRequiredinterpretunlessathe number starts withno+:leadingover+.MCP the end user's country cannot be inferred.","type":"string"},"number":{ ⟨20 unchanged words⟩
FullFollows a URL's full redirect chaintrace(up to 15 hops) and returns every hop with its status code, plus whether the chain crossed domains. Use it to see where a short or tracking link really leads; check the final URL with url_reputation.
GitHub repository health signals from the GitHub API: stars, forks, open issues, license, archived status and days since last push. Input: owner/name.AuditRead-only audit of a public CometBFT (Cosmos SDK) RPC endpoint:(node status, health, peers,unsafe-methodandexposurewhether unsafe admin methods (dial_seeds, dial_peers, unsafe_flush_mempool) are publicly exposed. Never calls an unsafe method; exposure is inferred from the node's route listing.
AuditAudits a URL's HTTP security headers (CSP, HSTS, X-Frame-Options, Permissions-Policy, cross-origin policies and others): per-header findings with advice, a score and a letter grade. Also included in security_scan.
Combined website check in one call: securitypostureheaders,reportURL reputation and passive subdomain discovery, run in parallel, with an overall score and verdict. Use the individual tools when you need a single signal.
Passive subdomain discovery from Certificate Transparency logs (crt.sh): finds hostnames that appeared in public TLS certificates, not every DNS record. crt.sh is occasionally slow or unavailable.Combined supply-chainOne-call risk check for a package: combines vulnerability_check (maintainer-changeOSV.dev),+typosquat_check,vulnerabilitymaintainer_change_check+(npmtyposquatonly)+andrepo-healthrepo_health_check (when the GitHub repo can be resolved) into one overall verdict. Use before adding a dependency; use the individual tools to investigate one signal.
TextNear-duplicatesimilaritydetectionviawith a 64-bit SimHash(over word shingles: send 1 text to get its hash, or 2 texts)to compare them. Detects paraphrased or lightly edited copies; unrelated texts score around 50%, not 0%.
ConvertReturnstimestampsthe current time, or converts between a Unix timestamp (seconds) and an ISO date. Provide unix or date, or neither for the current time.
DecodeDecodes a raw signed Cosmos SDK transaction (protobufbase64 TxRaw bytes, as found in a CometBFT block's data.txs) into JSON: messages, fee, gas, signers and signatures. Bank, staking, gov and authz messages are fully decoded; other types are returned as type URL plus raw hex.
PackageChecks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting),checkwith an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe.
CleanRemovesa60+singleknown tracking parameters (utm_*, fbclid, gclid and similar) from a URL and returns the clean URL. Does not follow redirects; for that, use redirect_trace.
CheckChecks a URL againstmalware/phishingURLhaus (abuse.ch), a public database of known malware distribution URLs. A clean result only means the URL is not listed, not that it is safe.
ParseParses a User-Agent string into browser and version, operating system and version, device type, and whether it looks like a bot.
{"properties":{"ua":{"description":"User-Agent string to parse.IfRequiredomitted,over MCP: therequest'sserverowncannotUser-Agentseeheadertheisendparseduser'sinstead.own User-Agent.","type":"string"}},"required":["ua"],"type":"object"}
GenerateGeneratesUUIDs1 to 100 random UUID v4 values.
ValidateChecks an EU VAT numberviain real time against theofficialEuropean Commission's VIES service and, when valid, returns the registered company name and address. VIES is occasionally unavailable for some member states.
PackageChecksvulnerabilityacheckpackage (OSV.devoptionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. Use cve_lookup when you already have a CVE/GHSA ID, or supply_chain_check for a combined verdict.
Domain registrationlookup (WHOISdata via RDAP (the modern WHOIS): registrar, creation and expiration dates, domain age in days, nameservers. For DNS records, use dns_lookup.
Get caller IP geolocation