Serveur MCP

Presend MCP Server

io.github.presendapp/presend-mcp
Outils développeur Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Provides security and developer utilities including DNS, WHOIS-related checks, vulnerability and reputation checks, JWT tools, encoding, and repository supply-chain analysis.

address_risk
Screens a crypto address against every OFAC SDN digital currency address list. EVM (0x...) and Bitcoin (bc1..., 1..., 3...) addresses are fully covered (sanctioned true or false, with the matching lists). Addresses of other chains are flagged when listed; Cosmos SDK bech32 addresses return sanctioned: null when not listed, as OFAC publishes none. A sanctions signal only, not a full risk score.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['address'], 'properties': {'address': {'type': 'string', 'description': 'Address to screen: EVM (0x + 40 hex chars) or Bitcoin (bc1..., 1..., 3...), both fully covered. Addresses of other chains are matched against their lists too; bech32 addresses of other chains (e.g. cosmos1...) return sanctioned: null (unchecked, not clean) when not listed.'}}}
ai_crawler_check
Fetches a domain's robots.txt and reports which known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot and others) are allowed or blocked, including wildcard rules. Reflects robots.txt only, not server-side blocking.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to check, e.g. example.com. robots.txt is fetched from https://<domain>/robots.txt.'}}}
base64
Encodes text to Base64 or decodes a Base64 string back to text (action = encode or decode).
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['action', 'text'], 'properties': {'text': {'type': 'string', 'description': 'Text to encode, or Base64 string to decode.'}, 'action': {'type': 'string', 'description': "Either 'encode' or 'decode'."}}}
color
Converts a color between hex, RGB and HSL. Provide exactly one of hex, rgb or hsl.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': [], 'properties': {'hex': {'type': 'string', 'description': 'Hex color code, e.g. #ff0000 or ff0000. Provide exactly one of hex, rgb, or hsl.'}, 'hsl': {'type': 'string', 'description': 'HSL color, e.g. 0,100%,50%. Provide exactly one of hex, rgb, or hsl.'}, 'rgb': {'type': 'string', 'description': 'RGB color, e.g. 255,0,0. Provide exactly one of hex, rgb, or hsl.'}}}
csv_json
Converts CSV text to JSON or JSON to CSV (direction: csv-to-json or json-to-csv), for data passed inline. CSV must be comma-separated, with a header row and at least one data row; double-quoted fields may contain commas. Semicolon- or tab-separated input is not detected and comes back as a single column. JSON input must be an array of objects: the union of their keys becomes the CSV header and missing values are left empty. Returns result (the converted text), rows and cols. Max 500,000 characters.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['direction', 'data'], 'properties': {'data': {'type': 'string', 'description': 'The CSV or JSON text to convert, matching the chosen direction.'}, 'direction': {'type': 'string', 'description': "Either 'csv-to-json' or 'json-to-csv'."}}}
cve_lookup
Looks up a vulnerability by identifier (CVE, GHSA or other OSV ID) on OSV.dev: summary, CVSS severity, affected packages and versions, references. Use when you already have an ID; use vulnerability_check when you have a package name instead.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'CVE, GHSA, or other OSV-native identifier, e.g. CVE-2021-44228.'}}}
dns_lookup
Returns DNS records for a domain via Cloudflare DNS-over-HTTPS: A, AAAA, CNAME, MX, TXT and NS in one call, or a single record type with 'type'. For registration data use whois_lookup; for SPF/DMARC/DKIM analysis use email_security.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['domain'], 'properties': {'type': {'type': 'string', 'description': 'Narrow to a single record type. Omit to get all 6 at once.'}, 'domain': {'type': 'string', 'description': 'Domain to look up, e.g. example.com.'}}}
email_disposable
Checks only whether an email address uses a known disposable/temporary email domain. For syntax, MX, disposable and role-account checks in one call, use email_verify.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['email'], 'properties': {'email': {'type': 'string', 'description': 'Email address to check against a list of known disposable/temporary email domains.'}}}
email_security
Audits a domain's email anti-spoofing setup: SPF strength, DMARC policy and a best-effort DKIM lookup on common selectors. A missing DKIM match does not prove DKIM is absent. Checks a domain, not a single address.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to check SPF, DKIM, and DMARC records for, e.g. example.com.'}}}
email_validate
Lightweight email check: syntax plus confirmation that the domain has an MX record. Does not detect disposable or role addresses; use email_verify for the combined check.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['email'], 'properties': {'email': {'type': 'string', 'description': 'Email address to validate for correct syntax and a resolvable domain.'}}}
email_verify
Most complete email check in one call: syntax, MX record, disposable-domain detection and role/generic account detection (e.g. info@, admin@). Prefer it over email_validate and email_disposable unless you need a single signal. Does not probe the mailbox. valid is null (not false) when the MX lookup could not be completed; retry later instead of treating the address as invalid.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['email'], 'properties': {'email': {'type': 'string', 'description': 'Email address to run through combined syntax, disposable-domain, and MX-record checks.'}}}
favicon
Returns the favicon URL a website declares: fetches the homepage and takes the first <link rel='icon'> (or 'shortcut icon') href, resolved to an absolute URL, which may be a data: URI when the page inlines its icon (source: declared). If no icon is declared, or the homepage cannot be fetched, returns the conventional https://<domain>/favicon.ico with source: default and a note, without checking that it exists. Use it to display a site icon; it does not download or validate the image.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to fetch the favicon URL for, e.g. example.com.'}}}
iban_validate
Validates an IBAN offline: ISO 7064 mod-97 checksum and country-specific length. Confirms the number is well-formed, not that the account exists.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['iban'], 'properties': {'iban': {'type': 'string', 'description': 'IBAN to validate. Spaces are ignored.'}}}
ip_reputation
Checks an IPv4 or IPv6 address against a curated list of netblocks known to be hijacked or run by spam/cyber-crime operations (IPv4-mapped IPv6 uses the IPv4 list). A narrow list-based signal: a clean result is not a safety guarantee. Includes list date and attribution.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'description': 'IPv4 or IPv6 address to check (IPv4-mapped IPv6 such as ::ffff:1.2.3.4 is checked against the IPv4 list) against a curated list of known hijacked or cyber-crime-controlled netblocks.'}}}
jwt_decode
Decodes a JWT's header and payload WITHOUT verifying its signature, so its claims must not be trusted on this basis alone. To check authenticity, use jwt_verify.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['token'], 'properties': {'token': {'type': 'string', 'description': 'The JWT to decode. Decodes header and payload only -- does not verify the signature (use /jwt-verify for that).'}}}
jwt_verify
Cryptographically verifies a JWT signature (HS256/384/512, RS/PS256/384/512, ES256/384/512) and checks exp/nbf claims. Provide a secret for HS*, or a JWK or JWKS URL for RS/PS/ES. Use instead of jwt_decode whenever authenticity matters.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['token'], 'properties': {'jwk': {'type': 'object', 'description': 'Public key in JWK format, for RS/PS/ES algorithms.'}, 'token': {'type': 'string', 'description': 'The JWT to verify. Checks the cryptographic signature -- use /jwt-decode if you only need to read the header and payload.'}, 'secret': {'type': 'string', 'description': 'Required for HS256/384/512.'}, 'jwks_url': {'type': 'string', 'description': 'URL to a JWKS document; the key is matched by the token\'s "kid" header.'}}}
link_metadata
Fetches a web page and extracts its title, description, canonical URL, Open Graph and Twitter Card tags (the data behind link previews). To follow a URL's redirects hop by hop, use redirect_trace.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to extract title, description, and Open Graph / Twitter Card metadata from.'}}}
maintainer_change_check
npm only. Flags a previously unseen human publisher taking over a package after 180+ days of inactivity, within the last 365 days (the event-stream attack pattern). npm trusted publishing (verified OIDC identity, not just a bot-like account name), pre-release, and handovers to a publisher who already maintains another widely used package (100k+ weekly downloads) are reported but not flagged. Does not detect hijacked existing accounts; a heuristic for review, not proof.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name, e.g. lodash'}, 'ecosystem': {'type': 'string', 'description': "Currently only 'npm' is supported."}}}
password
Generates a random password, with options for length, symbols, uppercase, numbers and excluding ambiguous characters. To evaluate an existing password, use password_check.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': [], 'properties': {'length': {'type': 'string', 'description': 'Desired password length. Defaults to a reasonable secure length if omitted.'}, 'numbers': {'type': 'string', 'description': 'Whether to include numeric digits. 1 for yes, 0 for no.'}, 'symbols': {'type': 'string', 'description': 'Whether to include symbol characters. 1 for yes, 0 for no.'}, 'uppercase': {'type': 'string', 'description': 'Whether to include uppercase letters. 1 for yes, 0 for no.'}, 'exclude_ambiguous': {'type': 'string', 'description': 'Whether to exclude visually ambiguous characters (e.g. 0/O, 1/l). 1 for yes, 0 for no.'}}}
password_breach
Checks whether a password appears in known data breaches (Have I Been Pwned) and how many times, using k-anonymity towards HIBP. Breach check only; password_check adds strength scoring and sends the password in a POST body.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['password'], 'properties': {'password': {'type': 'string', 'description': "Password to check against known data-breach corpora. Only a 5-character SHA-1 hash prefix is sent to HIBP (k-anonymity), but the password itself travels in this request's URL; for real passwords, prefer password_check, which takes it in a POST body."}}}
password_check
Scores a password's strength (length, character variety, entropy, common patterns) and, with check_breach=true, also looks it up in Have I Been Pwned breach data via k-anonymity (only a hash prefix is sent). Use it to evaluate a password someone is choosing; use password_breach when you only need the breach count, and password to generate a new one. The password travels in a POST body, never in a URL.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['password'], 'properties': {'password': {'type': 'string', 'description': 'Password to evaluate for strength (length, character variety, common patterns).'}, 'check_breach': {'type': 'boolean', 'description': 'Whether to also check the password against known data-breach corpora via k-anonymity. true or false.'}}}
phone_verify
Validates and formats a phone number: validity, country, line type, E.164, international and national formats. Numbers without a leading + require 'country', since the end user's country cannot be inferred over MCP.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['number'], 'properties': {'number': {'type': 'string', 'description': 'Phone number to validate and format, ideally in E.164 format (e.g. +14155552671).'}, 'country': {'type': 'string', 'description': "ISO 3166-1 alpha-2 country code (e.g. US, FR). Required unless the number starts with +: over MCP the end user's country cannot be inferred."}}}
redirect_trace
Follows a URL's full redirect chain (up to 15 hops) and returns every hop with its status code, plus whether the chain crossed domains. Use it to see where a short or tracking link really leads; check the final URL with url_reputation.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to follow the full redirect chain for, hop by hop.'}}}
repo_health_check
Maintenance signals for a GitHub repository given as owner/name: stars, forks, open issues, license, archived and fork flags, creation date and age, days since last push, topics. Use it to judge whether a dependency looks maintained or abandoned. For an npm or PyPI package whose repository you do not know, supply_chain_check resolves it from registry metadata and includes these signals. GitHub only; missing or private repositories return found: false.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['repo'], 'properties': {'repo': {'type': 'string', 'description': 'GitHub repository in owner/name format, e.g. lodash/lodash.'}}}
rpc_check
Read-only audit of a public CometBFT (Cosmos SDK) RPC endpoint: node status, health, peers, and whether unsafe admin methods (dial_seeds, dial_peers, unsafe_flush_mempool) are publicly exposed. Never calls an unsafe method; exposure is inferred from the node's route listing.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'Base URL of a CometBFT RPC endpoint to audit, e.g. https://rpc.cosmos.network:443.'}}}
security_headers
Audits the HTTP security headers of one URL (CSP, HSTS, X-Frame-Options, Permissions-Policy, cross-origin policies and others) and returns per-header findings with fix advice, a score and a letter grade. Use it when you need header hardening advice; security_scan runs this audit together with URL reputation and subdomain discovery in one call.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to audit HTTP security headers for (CSP, HSTS, X-Frame-Options, etc.).'}}}
security_scan
Combined website check in one call: security headers, URL reputation and passive subdomain discovery, run in parallel, with an overall score and verdict. Use the individual tools when you need a single signal.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to run a combined security posture check against (headers, reputation, and related signals).'}}}
subdomains
Passive subdomain discovery from Certificate Transparency logs (crt.sh): finds hostnames that appeared in public TLS certificates, not every DNS record. crt.sh is occasionally slow or unavailable.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to passively discover subdomains for via Certificate Transparency logs, e.g. example.com.'}}}
supply_chain_check
One-call risk check for a package: combines vulnerability_check (OSV.dev), typosquat_check, maintainer_change_check (npm only) and repo_health_check (when the GitHub repo can be resolved) into one overall verdict. Use before adding a dependency; use the individual tools to investigate one signal.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check.'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm. maintainer-change-check only runs for npm.'}}}
text_similarity
Near-duplicate detection with a 64-bit SimHash over word shingles: send 1 text to get its hash, or 2 texts to compare them. Detects paraphrased or lightly edited copies; unrelated texts score around 50%, not 0%.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['texts'], 'properties': {'texts': {'type': 'array', 'description': '1 text (hash only) or 2 texts (compare). Max 200,000 characters each.'}}}
timestamp
Returns the current time, or converts between a Unix timestamp (seconds) and an ISO date. Provide unix or date, or neither for the current time.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': [], 'properties': {'date': {'type': 'string', 'description': 'Date/time string to convert to a Unix timestamp. Provide either unix or date, not both.'}, 'unix': {'type': 'string', 'description': 'Unix timestamp (seconds since epoch) to convert to a human-readable date. Provide either unix or date, not both.'}}}
tx_decode
Decodes a raw signed Cosmos SDK transaction (base64 TxRaw bytes, as found in a CometBFT block's data.txs) into JSON: messages, fee, gas, signers and signatures. Bank, staking, gov and authz messages are fully decoded; other types are returned as type URL plus raw hex.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['tx'], 'properties': {'tx': {'type': 'string', 'description': "Base64-encoded Cosmos SDK TxRaw protobuf bytes, as returned by a chain's CometBFT RPC /block or /tx_search endpoints."}}}
typosquat_check
Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check for likely typosquatting of a well-known package in the given ecosystem.'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm or PyPI.'}}}
url_clean
Removes 60+ known tracking parameters (utm_*, fbclid, gclid and similar) from a URL and returns the clean URL. Does not follow redirects; for that, use redirect_trace.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to strip tracking parameters from (utm_*, fbclid, gclid, and similar).'}}}
url_reputation
Checks a URL against URLhaus (abuse.ch), a public database of known malware distribution URLs. A clean result only means the URL is not listed, not that it is safe.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to check against known phishing/malware URL databases.'}}}
user_agent
Parses a User-Agent string into browser and version, operating system and version, device type, and whether it looks like a bot.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['ua'], 'properties': {'ua': {'type': 'string', 'description': "User-Agent string to parse. Required over MCP: the server cannot see the end user's own User-Agent."}}}
uuid
Generates 1 to 100 random UUID v4 values.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': [], 'properties': {'count': {'type': 'string', 'description': 'Number of UUIDs (v4) to generate. Defaults to 1 if omitted.'}}}
vat_validate
Checks an EU VAT number in real time against the European Commission's VIES service and, when valid, returns the registered company name and address. VIES is occasionally unavailable for some member states.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['vat'], 'properties': {'vat': {'type': 'string', 'description': 'VAT number, with or without the country prefix.'}, 'country': {'type': 'string', 'description': '2-letter EU country code (EL for Greece, XI for Northern Ireland). Optional if vat includes the prefix.'}}}
vulnerability_check
Checks a package (optionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. Use cve_lookup when you already have a CVE/GHSA ID, or supply_chain_check for a combined verdict.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check against OSV.dev for known CVEs.'}, 'version': {'type': 'string', 'description': 'Omit to check all versions of the package.'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist, or NuGet.'}}}
whois_lookup
Domain registration data via RDAP (the modern WHOIS): registrar, creation and expiration dates, domain age in days, nameservers. For DNS records, use dns_lookup.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to look up registration details for via RDAP, e.g. example.com.'}}}
Modifié
password_breach
29 September 2026 02:56
Modifié
email_verify
29 September 2026 02:56
Modifié
address_risk
29 September 2026 02:56
Supprimé
ip
27 September 2026 02:47
Modifié
whois_lookup
27 September 2026 02:47
Modifié
vulnerability_check
27 September 2026 02:47
Ajouté
vat_validate
27 September 2026 02:47
Modifié
uuid
27 September 2026 02:47
Modifié
user_agent
27 September 2026 02:47
Modifié
url_reputation
27 September 2026 02:47
Modifié
url_clean
27 September 2026 02:47
Modifié
typosquat_check
27 September 2026 02:47
Modifié
tx_decode
27 September 2026 02:47
Modifié
timestamp
27 September 2026 02:47
Modifié
text_similarity
27 September 2026 02:47
Modifié
supply_chain_check
27 September 2026 02:47
Modifié
subdomains
27 September 2026 02:47
Modifié
security_scan
27 September 2026 02:47
Modifié
security_headers
27 September 2026 02:47
Modifié
rpc_check
27 September 2026 02:47
Modifié
repo_health_check
27 September 2026 02:47
Modifié
redirect_trace
27 September 2026 02:47
Modifié
phone_verify
27 September 2026 02:47
Modifié
password_check
27 September 2026 02:47
Modifié
password_breach
27 September 2026 02:47
Modifié
password
27 September 2026 02:47
Modifié
maintainer_change_check
27 September 2026 02:47
Ajouté
link_metadata
27 September 2026 02:47
Modifié
jwt_verify
27 September 2026 02:47
Modifié
jwt_decode
27 September 2026 02:47

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…