MCP Server

ProfitCollector

ca.bakhour/profitcollector
Developer Tools Security Public & reachable MCP 2025-11-25

What this MCP does

Performs DNS, TLS, HTTP security, repository risk, dependency, hashing, encoding, JSON, and media-processing utilities.

get_dns_lookup
Resolve ONE DNS record type for a domain. For all record types at once use /domain/intelligence; for a bundled DNS+TLS+headers audit use /web/audit or /security/posture; for mail-security plus a scored verdict use /domain/due-diligence.
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain'}, 'record_type': {'type': 'string', 'title': 'Record Type', 'default': 'A'}}, 'additionalProperties': False}
get_domain_intelligence
Collect ALL common DNS record types (A/AAAA/MX/NS/TXT/CAA) for a domain in one call -- the multi-record bundle version of /dns/lookup.
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain'}}, 'additionalProperties': False}
get_jwt_decode
Decode a JWT payload without signature verification.
Input schema
{'type': 'object', 'required': ['token'], 'properties': {'token': {'type': 'string', 'title': 'Token'}}, 'additionalProperties': False}
get_security_headers
Inspect HTTP security headers for ONE URL only. For headers combined with TLS and DNS, use /web/audit (raw) or /security/posture (scored).
Input schema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'title': 'Url'}}, 'additionalProperties': False}
get_security_posture
Assess TLS and HTTP security posture for a public HTTPS website -- the SAME inspection as /web/audit, but returns a 0-100 score/grade and findings instead of raw fields.
Input schema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'title': 'Url'}}, 'additionalProperties': False}
get_ssl_check
Inspect the TLS certificate for ONE hostname only. For TLS combined with HTTP headers and DNS, use /web/audit (raw) or /security/posture (scored).
Input schema
{'type': 'object', 'required': ['hostname'], 'properties': {'hostname': {'type': 'string', 'title': 'Hostname'}}, 'additionalProperties': False}
get_subnet_calculate
Calculate subnet information from CIDR notation.
Input schema
{'type': 'object', 'required': ['cidr'], 'properties': {'cidr': {'type': 'string', 'title': 'Cidr'}}, 'additionalProperties': False}
get_timestamp_convert
Convert a Unix timestamp to UTC ISO-8601.
Input schema
{'type': 'object', 'required': ['timestamp'], 'properties': {'timestamp': {'type': 'number', 'title': 'Timestamp'}}, 'additionalProperties': False}
get_url_parse
Parse a URL into structured components.
Input schema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'title': 'Url'}}, 'additionalProperties': False}
get_uuid_generate
Generate a random UUID version 4.
Input schema
{'type': 'object', 'properties': {'count': {'type': 'integer', 'title': 'Count', 'default': 1}}, 'additionalProperties': False}
get_web_audit
Consolidated DNS, TLS and HTTP security audit for a public HTTPS website, returned as RAW findings (no score) -- the bundled version of /dns/lookup + /ssl/check + /security/headers. Use /security/posture instead for a 0-100 score/grade.
Input schema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'title': 'Url'}}, 'additionalProperties': False}
post_base64_decode
Decode Base64 to UTF-8 text.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_base64_encode
Encode UTF-8 text using Base64.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_data_transform
Normalize and transform common structured text automatically.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}, 'operation': {'enum': ['auto', 'json_pretty', 'json_minify', 'base64_encode', 'base64_decode', 'dedupe_lines'], 'type': 'string', 'default': 'auto'}}, 'additionalProperties': False}
post_domain_due_diligence
The most comprehensive domain assessment: DNS + mail security (SPF/DKIM/DMARC) + TLS + HTTP headers, scored. The only endpoint in this group that adds mail-security analysis. Use for a one-shot decision-grade verdict on an unfamiliar domain; use /dns/lookup, /ssl/check, /security/headers, /web/audit or /security/posture instead for a single fact or a cheaper signal.
Input schema
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'title': 'Domain', 'examples': ['example.com'], 'minLength': 1, 'description': 'Public domain name to assess'}}, 'additionalProperties': False}
post_freshdep_scan
Flags pinned dependencies in a repository's requirements.txt, package-lock.json, or uv.lock published more recently than a freshness threshold -- a supply-chain-compromise tripwire. Free CLI (requirements.txt/package-lock.json only, uv.lock support pending there): github.com/sbakhour/freshdep.
Input schema
{'type': 'object', 'required': ['repo_url'], 'properties': {'ref': {'type': 'string', 'description': 'Optional branch/tag to check out instead of the default branch.'}, 'repo_url': {'type': 'string', 'description': 'Full https://github.com/<owner>/<repo> URL to scan.'}, 'threshold_days': {'type': 'number', 'description': 'Flag anything published more recently than this many days ago. Defaults to 7.'}}, 'additionalProperties': False}
post_hash_sha256
Generate SHA-256 digest from text.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_hash_sha512
Generate SHA-512 digest from text.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_json_minify
Minify valid JSON text.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_json_pretty
Pretty-print valid JSON text.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_json_repair
Repair common malformed JSON formatting issues.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_json_validate
Validate JSON text and return parsing details.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_media_image_convert
Convert an image between common formats (e.g. PNG/JPEG/WebP) from a URL or base64 payload.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
post_quebec_invoice_compliance_check
Verifies GST/QST were calculated correctly per Revenu Quebec's current (non-compounded) formula, and flags whether a French invoice version is present per Charter of the French Language s.57/89/91. Pure arithmetic + text check; not legal or tax advice.
Input schema
{'type': 'object', 'required': ['subtotal', 'gst_amount', 'qst_amount'], 'properties': {'subtotal': {'type': 'number', 'description': 'Pre-tax subtotal in CAD.'}, 'gst_amount': {'type': 'number', 'description': 'GST amount as shown on the invoice.'}, 'qst_amount': {'type': 'number', 'description': 'QST amount as shown on the invoice.'}, 'french_text': {'type': 'string', 'description': "The invoice's French text, if any (optional -- its absence is itself flagged)."}, 'english_text': {'type': 'string', 'description': "The invoice's primary/other-language text (optional but needed for the language check)."}}, 'additionalProperties': False}
post_quebec_invoice_generate
Assembles a bilingual (French/English) Quebec invoice document with GST/QST computed exactly per Revenu Quebec's current formula -- you supply both languages' line-item text, this does not translate. Not legal or tax advice.
Input schema
{'type': 'object', 'required': ['invoice_number', 'seller_name', 'line_items'], 'properties': {'line_items': {'type': 'array', 'items': {'type': 'object', 'required': ['description_en', 'description_fr', 'amount'], 'properties': {'amount': {'type': 'number'}, 'description_en': {'type': 'string'}, 'description_fr': {'type': 'string'}}}, 'description': 'Each item needs description_en, description_fr (both required -- this assembles, it does not translate), and amount.'}, 'seller_name': {'type': 'string', 'description': 'Seller/business name to display.'}, 'invoice_number': {'type': 'string', 'description': 'Your own invoice number/reference.'}, 'seller_gst_number': {'type': 'string', 'description': 'GST registration number, optional.'}, 'seller_qst_number': {'type': 'string', 'description': 'QST registration number, optional.'}}, 'additionalProperties': False}
post_security_repo_risk_report_deep
Everything in the standard report, plus a repo-wide secret/credential exposure scan (matched values are never returned).
Input schema
{'type': 'object', 'required': ['repo_url'], 'properties': {'ref': {'type': 'string', 'description': "Optional branch/tag to analyze. Defaults to the repository's default branch."}, 'repo_url': {'type': 'string', 'description': 'Public https://github.com/... or https://gitlab.com/... repository URL.'}}, 'additionalProperties': False}
post_security_repo_risk_report_due_diligence
Everything in the deep report, plus real OpenSSF Scorecard maintainer/governance signals and a prioritized recommendation. An automated baseline positioned against $5,000-$95,000 human technical due diligence.
Input schema
{'type': 'object', 'required': ['repo_url'], 'properties': {'ref': {'type': 'string', 'description': "Optional branch/tag to analyze. Defaults to the repository's default branch."}, 'repo_url': {'type': 'string', 'description': 'Public https://github.com/... or https://gitlab.com/... repository URL.'}}, 'additionalProperties': False}
post_security_repo_risk_report_standard
SBOM inventory plus real OSV.dev dependency-vulnerability matches and dependency-freshness signals for a public Git repository. One-shot alternative to a per-seat secret-scanning subscription.
Input schema
{'type': 'object', 'required': ['repo_url'], 'properties': {'ref': {'type': 'string', 'description': "Optional branch/tag to analyze. Defaults to the repository's default branch."}, 'repo_url': {'type': 'string', 'description': 'Public https://github.com/... or https://gitlab.com/... repository URL.'}}, 'additionalProperties': False}
post_text_dedupe_lines
Remove duplicate lines while preserving original order.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_text_stats
Calculate character, word, line and byte statistics.
Input schema
{'type': 'object', 'required': ['text'], 'properties': {'text': {'type': 'string'}}, 'additionalProperties': False}
post_x402_service_trust_report
Live, on-demand check of ONE x402-protected endpoint before you pay it: payment-requirements structure, TLS certificate, payTo on-chain balance, known-asset recognition, resource/host consistency, and discovery-manifest cross-check -- not a cached aggregate reputation score.
Input schema
{'type': 'object', 'required': ['target_url'], 'properties': {'target_url': {'type': 'string', 'description': 'The full https:// URL of the x402-protected endpoint to evaluate.'}, 'target_method': {'enum': ['GET', 'POST'], 'type': 'string', 'description': 'HTTP method to request target_url with. Defaults to GET; use POST for action-style endpoints that only 402-challenge on POST.'}}, 'additionalProperties': False}
Added
get_ssl_check
Sept. 17, 2026, 7:58 a.m.
Added
get_security_headers
Sept. 17, 2026, 7:58 a.m.
Added
post_data_transform
Sept. 17, 2026, 7:58 a.m.
Added
get_security_posture
Sept. 17, 2026, 7:58 a.m.
Added
get_web_audit
Sept. 17, 2026, 7:58 a.m.
Added
get_domain_intelligence
Sept. 17, 2026, 7:58 a.m.
Added
post_domain_due_diligence
Sept. 17, 2026, 7:58 a.m.
Added
get_timestamp_convert
Sept. 17, 2026, 7:58 a.m.
Added
post_text_dedupe_lines
Sept. 17, 2026, 7:58 a.m.
Added
post_text_stats
Sept. 17, 2026, 7:58 a.m.
Added
get_url_parse
Sept. 17, 2026, 7:58 a.m.
Added
get_uuid_generate
Sept. 17, 2026, 7:58 a.m.
Added
post_hash_sha512
Sept. 17, 2026, 7:58 a.m.
Added
post_hash_sha256
Sept. 17, 2026, 7:58 a.m.
Added
post_base64_decode
Sept. 17, 2026, 7:58 a.m.
Added
post_base64_encode
Sept. 17, 2026, 7:58 a.m.
Added
post_json_minify
Sept. 17, 2026, 7:58 a.m.
Added
post_json_pretty
Sept. 17, 2026, 7:58 a.m.
Added
post_json_validate
Sept. 17, 2026, 7:58 a.m.
Added
post_quebec_invoice_generate
Sept. 17, 2026, 7:58 a.m.
Added
post_quebec_invoice_compliance_check
Sept. 17, 2026, 7:58 a.m.
Added
post_freshdep_scan
Sept. 17, 2026, 7:58 a.m.
Added
post_x402_service_trust_report
Sept. 17, 2026, 7:58 a.m.
Added
post_security_repo_risk_report_due_diligence
Sept. 17, 2026, 7:58 a.m.
Added
post_security_repo_risk_report_deep
Sept. 17, 2026, 7:58 a.m.
Added
post_security_repo_risk_report_standard
Sept. 17, 2026, 7:58 a.m.
Added
post_media_image_convert
Sept. 17, 2026, 7:58 a.m.
Added
post_json_repair
Sept. 17, 2026, 7:58 a.m.
Added
get_subnet_calculate
Sept. 17, 2026, 7:58 a.m.
Added
get_jwt_decode
Sept. 17, 2026, 7:58 a.m.

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…