MCP 服务器

nittim

com.nittim/nittim
开发者工具 安全 公开且可连接 MCP 2025-11-25

此 MCP 可以做什么

Audits repositories and posted source for production risks, secrets, dependency vulnerabilities, and other code-quality findings, with fix verification.

audit_repo
Audit a GitHub Repository
Paid nittim AI audit of a GitHub repository: one structured pass over the highest-signal source; the only tool here that returns scores and a verdict. Answers with the audit's id, not the report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.DELIVERED AS A BATCH: the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours.
可访问外部资源
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['repoUrl'], 'properties': {'repoUrl': {'type': 'string', 'minLength': 1, 'description': "GitHub repository URL or owner/repo. A private repo needs a githubToken, unless the account has installed nittim's GitHub App at nittim.com for it."}, 'fullScan': {'type': 'boolean', 'description': 'True buys the wider Full Audit tier: every eligible source file, priced by pass count.'}, 'payInstead': {'type': 'boolean', 'description': 'True pays credits now instead of queuing for the daily free-audit budget to reopen, skipping the covered (Audit) entitlement even when it would otherwise be free.'}, 'deployedUrl': {'type': 'string', 'description': "Optional URL of this repository's live deployment, for an origin the account owner actually operates. When set, the audit adds one bounded, READ-ONLY fetch pass against it and reports drift between the deployed artifact and the audited commit. Redirects are never followed; private addresses are refused."}, 'githubToken': {'type': 'string', 'description': "Optional read-only GitHub token for a private repo. Without one, only public repos are reachable â\x80\x94 unless the account has installed nittim's GitHub App at nittim.com for this repo, in which case a private repo works with no token at all."}, 'authorization': {'type': 'string', 'description': 'HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.'}, 'confirmedCost': {'type': 'object', 'required': ['kind', 'credits'], 'properties': {'kind': {'type': 'string', 'description': "The `kind` from the quoted cost, e.g. 'credits'."}, 'credits': {'type': 'number', 'description': 'The `credits` number from the quoted cost.'}, 'centicredits': {'type': 'number', 'description': 'The `centicredits` integer from the quoted cost, if it carried one.'}}, 'description': 'COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.'}}}
audit_source
Audit Posted Source (no GitHub repo required)
Paid nittim AI audit of source files you post, for a project with no GitHub remote. Send SOURCE files, not build output — no node_modules or dist. On nittim's own key this answers with the audit's id; the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours. On your own key (BYOK Pro) the report comes back in this call instead. Costs 5.14 credits (a paid+subscribed org's included allowance, an unspent Audit, then prepaid credits), always saved as a PRIVATE report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'files'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'content'], 'properties': {'path': {'type': 'string', 'minLength': 1, 'description': "Relative path, e.g. 'src/index.ts'. No absolute paths, no '..', no backslashes."}, 'content': {'type': 'string', 'description': "The file's full text."}, 'encoding': {'type': 'string', 'description': "Omit or 'utf8' for text files. Any other value (e.g. 'base64') is rejected â\x80\x94 text only in v1."}}}, 'maxItems': 1000, 'minItems': 1, 'description': 'Source files as { path, content }[] â\x80\x94 not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win.'}, 'fullScan': {'type': 'boolean', 'description': 'True buys the wider Full Audit tier over the files you post, priced by pass count.'}, 'uploadGrant': {'type': 'string', 'description': 'Optional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.'}, 'authorization': {'type': 'string', 'description': 'HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.'}, 'confirmedCost': {'type': 'object', 'required': ['kind', 'credits'], 'properties': {'kind': {'type': 'string', 'description': "The `kind` from the quoted cost, e.g. 'credits'."}, 'credits': {'type': 'number', 'description': 'The `credits` number from the quoted cost.'}, 'centicredits': {'type': 'number', 'description': 'The `centicredits` integer from the quoted cost, if it carried one.'}}, 'description': 'COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.'}}}
describe_protocol
How This Server's Protocol Works
How this server works, in full: how a paid call quotes and charges, the two audit tiers, the Nittim Loop and its reward rules and caps, and dispute guidance. Free, no key, no charge, no side effects — it reads static text and calls no model. `section` picks one page; omitted, it returns all of them.
只读 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'section': {'enum': ['money', 'tiers', 'loop', 'disputes', 'all'], 'type': 'string', 'description': 'Which page: money, tiers, loop, disputes, or all (the default).'}}}
dispute_finding
Dispute or Confirm a Finding
NEEDS A KEY: mint one at https://nittim.com/keys. Records that a finding from a prior audit is wrong (stance:'dispute') or genuinely real (stance:'confirm'), backed by evidence from the repo. Free. A SIGNAL for owner triage — it never changes the audit's scores, verdict or stored report on its own. The finding is identified by its findingKey (from the digest), or by its exact dimension and title.
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['auditId', 'stance', 'evidence'], 'properties': {'title': {'type': 'string', 'description': "The finding's exact title â\x80\x94 required if findingKey is omitted."}, 'stance': {'enum': ['dispute', 'confirm'], 'type': 'string', 'description': "'dispute' = this finding is wrong. 'confirm' = this finding is genuinely real."}, 'auditId': {'type': 'string', 'format': 'uuid', 'pattern': '^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$', 'description': 'The audit UUID, from its report link.'}, 'evidence': {'type': 'object', 'required': ['file', 'explanation'], 'properties': {'file': {'type': 'string', 'minLength': 1, 'description': 'The file path your evidence points to.'}, 'lines': {'type': 'string', 'description': "Line range, e.g. '42-58'."}, 'snippet': {'type': 'string', 'description': 'A short excerpt of the actual code supporting your stance.'}, 'explanation': {'type': 'string', 'minLength': 1, 'description': 'Why this finding is wrong or confirmed real, in your own words.'}}, 'description': 'What you can see in the repo that supports your stance.'}, 'dimension': {'type': 'string', 'description': "The finding's dimension, e.g. 'security' â\x80\x94 required if findingKey is omitted."}, 'findingKey': {'type': 'string', 'description': "The finding's stable key from the digest, if you have it (preferred over dimension+title)."}}}
estimate_audit
Estimate an Audit's Price — No Upload Required
Price an audit before buying one: give a GitHub repository URL, or a manifest of paths and byte sizes — no file content, nothing uploaded — and get the tier (Audit or Full Audit), the pass count and the exact price. No account or key is needed: it never charges, runs no audit, calls no model and stores nothing. Signed in it also returns your credit balance and whether an unspent Audit covers the run; a guest quote omits both. `fullScan: true` prices Full Audit.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'bytes'], 'properties': {'path': {'type': 'string', 'minLength': 1, 'description': "Relative path, e.g. 'src/index.ts'."}, 'bytes': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': "The file's byte size. This shape has no `content` â\x80\x94 nothing is uploaded."}}}, 'minItems': 1, 'description': 'A manifest of paths and sizes only, in place of `repoUrl` â\x80\x94 the same set you would post. Over the cap the answer names it and how to trim. Send one or the other.'}, 'repoUrl': {'type': 'string', 'minLength': 1, 'description': 'GitHub repository URL or owner/repo. Mutually exclusive with `files` â\x80\x94 send one.'}, 'fullScan': {'type': 'boolean', 'description': 'Price Full Audit (every eligible file, or a refusal with the reason when the selection is too large) instead of the default Audit.'}, 'githubToken': {'type': 'string', 'description': "Optional GitHub personal access token (read-only) for a private repo. Without one, a signed-in account with nittim's GitHub App installed at nittim.com for this repo still prices it â\x80\x94 no token needed."}}}
get_audit
Fetch a Saved Audit
Retrieve a nittim audit by its UUID, at any stage: the finished markdown digest (verdict, scores, top findings) plus its report link, or — no error, nothing charged — that it is still running, or why it failed and what happened to the charge. Free. Reading needs the key of the account that owns the audit.
只读 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['id'], 'properties': {'id': {'type': 'string', 'format': 'uuid', 'pattern': '^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$', 'description': 'The UUID of the saved audit, from the /report/{id} URL.'}}}
get_loop
Read the Nittim Loop Checklist
Returns the current text of nittim's free, tool-agnostic self-review checklist — the same content served at https://nittim.com/selfcheck.md. Reviews a codebase against the public shape of nittim's 13-category Priority Framework, plus a 14th on what the code gives away, and states the procedure for running it as a loop. No arguments. No key, no account and no charge — nothing here is sent anywhere.
只读 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
judge_output
Judge Arbitrary Output (independent cross-vendor model)
Run a cross-vendor judge model over any text you post: code, a document, another model's output, anything. Returns findings + rationale ONLY — never a score, never a pass/fail verdict. Costs 5.03 credits. The judge always comes from a different vendor family than whatever produced the content, and the answer says which one ran. `modelUnderTest` names that family. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['content'], 'properties': {'content': {'type': 'string', 'maxLength': 100000, 'minLength': 1, 'description': "The text to judge â\x80\x94 code, a document, another model's output. Up to ~100KB."}, 'context': {'type': 'string', 'description': 'Optional â\x80\x94 background the judge should know, e.g. what this content is for.'}, 'criteria': {'type': 'string', 'description': "Optional â\x80\x94 what to judge it against, e.g. 'correctness and security'."}, 'authorization': {'type': 'string', 'description': 'HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.'}, 'confirmedCost': {'type': 'object', 'required': ['kind', 'credits'], 'properties': {'kind': {'type': 'string', 'description': "The `kind` from the quoted cost, e.g. 'credits'."}, 'credits': {'type': 'number', 'description': 'The `credits` number from the quoted cost.'}, 'centicredits': {'type': 'number', 'description': 'The `centicredits` integer from the quoted cost, if it carried one.'}}, 'description': 'COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.'}, 'modelUnderTest': {'enum': ['anthropic', 'openai', 'unspecified'], 'type': 'string', 'description': "Optional â\x80\x94 which vendor family produced `content`, if it is itself a model's output. The judge that runs is always a different family than this names. Use 'unspecified' for anything that is not model output, or when the family is unknown."}}}
list_modules
List nittim Audit Modules
List every audit module nittim can run: the two deterministic scanners (secret scan + OSV dependency CVE check) and the LLM-reasoned checks. Returns each module's key, tier, and a plain-English description of what it checks. Each module's key identifies it for running individually.
只读 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
mint_key
Get a One-Time Link to Mint a nittim Key
For a client that cannot sign in over OAuth: a short, one-time link to https://nittim.com/keys/claim/<token>. Opening it, signed in, mints a real nittim API key and shows it once — the key itself is NEVER returned by this tool or by any other MCP result. The link expires in a few minutes and works exactly once. Free.
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'keyName': {'type': 'string', 'maxLength': 80, 'description': "Optional display name for the key that will be minted, e.g. 'my-cursor-key'. Defaults to 'API key'."}}}
preview_upload
Preview an Upload Before Any Source Leaves the Machine
NEEDS A KEY: mint one at https://nittim.com/keys. Send the paths and sizes of the files you would post — no content leaves your machine to ask this — and get back the list, the byte count, and a link for the account owner to approve it. Free. The approval covers that file list and no other, and a paid audit's own confirmation already covers the file list beside the price, so approving ahead of time is optional.
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'files'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'bytes'], 'properties': {'path': {'type': 'string', 'minLength': 1, 'description': "Relative path, e.g. 'src/index.ts'."}, 'bytes': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': "The file's size in bytes. No content."}}}, 'maxItems': 1000, 'minItems': 1, 'description': 'Paths and sizes only â\x80\x94 the same set you would post. Never file content.'}}}
report_loop
Report a Completed Nittim Loop (opt-in, counts only)
NEEDS A KEY: mint one at https://nittim.com/keys. Records anonymised counts from a Nittim Loop the developer has finished and agreed to send: pass numbers, a findings-by-category tally, a fixed count, and whether each pass was clean. Counts only — never a title, file path or snippet. Nothing is charged, and an eligible report can earn a credit reward (rules and caps: see describe_protocol). Reporting the same repo again updates the existing record; the reply says which happened. Results appear at https://nittim.com/loop.
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['repo_hash', 'repo_size_bucket', 'passes'], 'properties': {'mode': {'enum': ['one_shot', 'serial'], 'type': 'string', 'description': "Optional: 'one_shot' (every lens sweeps the whole tree first, then one fix wave, then a short convergence loop) or 'serial' (one lens or area per pass, fixing between passes)."}, 'swept': {'type': 'boolean', 'description': 'Optional: was the CLASS swept â\x80\x94 a guard, lint rule or exhaustiveness check that makes a new instance loud â\x80\x94 rather than only the instances a pass named? Never derived, never changes the reward. On a repeat report, omitting it keeps the last answer; `false` withdraws it.'}, 'passes': {'type': 'array', 'items': {'type': 'object', 'required': ['n', 'fixed', 'clean'], 'properties': {'n': {'type': 'integer', 'maximum': 9007199254740991, 'description': "This pass's number, starting at 1.", 'exclusiveMinimum': 0}, 'clean': {'type': 'boolean', 'description': 'True iff this pass found nothing new.'}, 'fixed': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 0, 'description': 'How many findings this pass fixed.'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['category'], 'properties': {'low': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0}, 'high': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0}, 'medium': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0}, 'category': {'enum': ['security', 'privacy', 'reliability', 'code_quality', 'ai_risk', 'performance', 'devops', 'data', 'business', 'devex', 'accessibility', 'observability', 'maintainability'], 'type': 'string'}, 'critical': {'type': 'integer', 'default': 0, 'maximum': 9007199254740991, 'minimum': 0}}, 'additionalProperties': False}, 'maxItems': 13, 'description': 'Findings this pass named â\x80\x94 one entry per category with something to report; omit a category that found nothing. Each count defaults to 0 when omitted.'}}, 'additionalProperties': False}, 'maxItems': 100, 'minItems': 1, 'description': 'One entry per pass you actually ran, in order.'}, 'repo_hash': {'type': 'string', 'pattern': '^[0-9a-f]{64}$', 'description': "sha256 of the repository's canonical identity (the lowercased 'owner/repo', or a stable local fingerprint) â\x80\x94 never the repo name itself. nittim never sees the name."}, 'client_name': {'type': 'string', 'maxLength': 64, 'description': 'Your own name â\x80\x94 omit to read it from the MCP connection instead.'}, 'convergence': {'enum': ['converged', 'cap_reached'], 'type': 'string', 'description': "Optional: 'converged' (two consecutive clean passes) or 'cap_reached' (stopped for any other reason). Omit if unsure â\x80\x94 the read from `passes` is derived either way."}, 'client_version': {'type': 'string', 'maxLength': 64, 'description': 'Your own version string, if you have one.'}, 'repo_size_bucket': {'enum': ['xs', 's', 'm', 'l', 'xl'], 'type': 'string', 'description': 'A rough size bucket for the repo you looped over.'}, 'first_wave_lenses': {'type': 'integer', 'maximum': 100, 'description': "Optional, with mode 'one_shot' only: how many lenses ran in parallel on pass 1.", 'exclusiveMinimum': 0}}}
run_module
Run a Single Audit Module
Run ONE nittim audit module against a GitHub repository, never producing scores or a verdict. The two deterministic modules (secret-scan, dependency-cve) return scanner evidence directly, free, with nothing to confirm. Deep-tier modules make one focused model call, cost 5.03 credits each and follow the protocol below. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.
可访问外部资源
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['repoUrl', 'moduleKey'], 'properties': {'repoUrl': {'type': 'string', 'minLength': 1, 'description': 'GitHub repository URL or owner/repo. A private repo needs a githubToken.'}, 'moduleKey': {'type': 'string', 'minLength': 1, 'description': "The module's key, e.g. 'secret-scan', 'dependency-cve', 'security', 'privacy', 'gdpr'."}, 'githubToken': {'type': 'string', 'description': 'Optional read-only GitHub token. Without one, only public repos are reachable.'}, 'authorization': {'type': 'string', 'description': 'HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.'}, 'confirmedCost': {'type': 'object', 'required': ['kind', 'credits'], 'properties': {'kind': {'type': 'string', 'description': "The `kind` from the quoted cost, e.g. 'credits'."}, 'credits': {'type': 'number', 'description': 'The `credits` number from the quoted cost.'}, 'centicredits': {'type': 'number', 'description': 'The `centicredits` integer from the quoted cost, if it carried one.'}}, 'description': 'COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.'}}}
scan_source
Free Scan of Posted Source (no GitHub repo required)
Free nittim look: committed secrets and known CVEs over posted source files. No account, no key, no nittim credits. Hard evidence only: never scores, never a production verdict. Send SOURCE files, not build output (no node_modules, no dist, no binaries).
只读 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['name', 'files'], 'properties': {'name': {'type': 'string', 'maxLength': 200, 'minLength': 1, 'description': "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'content'], 'properties': {'path': {'type': 'string', 'minLength': 1, 'description': "Relative path, e.g. 'src/index.ts'. No absolute paths, no '..', no backslashes."}, 'content': {'type': 'string', 'description': "The file's full text."}, 'encoding': {'type': 'string', 'description': "Omit or 'utf8' for text files. Any other value (e.g. 'base64') is rejected â\x80\x94 text only in v1."}}}, 'maxItems': 1000, 'minItems': 1, 'description': 'Source files as { path, content }[] â\x80\x94 not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win.'}, 'uploadGrant': {'type': 'string', 'description': 'Optional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.'}}}
verify_fix
Re-check One Finding Against Current Code
NEEDS A KEY: mint one at https://nittim.com/keys. Re-checks ONE finding from a finished audit against the repository's current code, or a commit named in the call, and answers fixed, still present, or undetermined — with the reason. It reads only the file that finding cites. Free, capped per day, and it moves no score or verdict: the report keeps recording what was true of the commit it ran on.
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['auditId', 'findingKey'], 'properties': {'ref': {'type': 'string', 'description': "A commit SHA or branch to check instead of the repository's current HEAD. Must be the audited commit or newer."}, 'auditId': {'type': 'string', 'format': 'uuid', 'pattern': '^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$', 'description': 'The audit UUID, from its report link.'}, 'findingKey': {'type': 'string', 'minLength': 1, 'description': "The finding's stable key, as printed beside it in the report's findings list."}}}
已更改
estimate_audit
2026年9月27日 02:53
已更改
audit_repo
2026年9月27日 02:53
已添加
preview_upload
2026年9月17日 12:36
已添加
report_loop
2026年9月17日 12:36
已添加
dispute_finding
2026年9月17日 12:36
已添加
judge_output
2026年9月17日 12:36
已添加
run_module
2026年9月17日 12:36
已添加
mint_key
2026年9月17日 12:36
已添加
describe_protocol
2026年9月17日 12:36
已添加
get_loop
2026年9月17日 12:36
已添加
list_modules
2026年9月17日 12:36
已添加
verify_fix
2026年9月17日 12:36
已添加
get_audit
2026年9月17日 12:36
已添加
estimate_audit
2026年9月17日 12:36
已添加
scan_source
2026年9月17日 12:36
已添加
audit_source
2026年9月17日 12:36
已添加
audit_repo
2026年9月17日 12:36

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…