MCP 服务器

Presend MCP Server

io.github.presendapp/presend-mcp
开发者工具 安全 公开且可连接 MCP 2026-07-28

此 MCP 可以做什么

Provides security and developer utilities including DNS, WHOIS-related checks, vulnerability and reputation checks, JWT tools, encoding, and repository supply-chain analysis.

address_risk
Screens a crypto address against every OFAC SDN digital currency address list. EVM (0x...) and Bitcoin (bc1..., 1..., 3...) addresses are fully covered (sanctioned true or false, with the matching lists). Addresses of other chains are flagged when listed; Cosmos SDK bech32 addresses return sanctioned: null when not listed, as OFAC publishes none. A sanctions signal only, not a full risk score.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['address'], 'properties': {'address': {'type': 'string', 'description': 'Address to screen: EVM (0x + 40 hex chars) or Bitcoin (bc1..., 1..., 3...), both fully covered. Addresses of other chains are matched against their lists too; bech32 addresses of other chains (e.g. cosmos1...) return sanctioned: null (unchecked, not clean) when not listed.'}}}
ai_crawler_check
Fetches a domain's robots.txt and reports which known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot and others) are allowed or blocked, including wildcard rules. Reflects robots.txt only, not server-side blocking.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to check, e.g. example.com. robots.txt is fetched from https://<domain>/robots.txt.'}}}
base64
Encodes text to Base64 or decodes a Base64 string back to text (action = encode or decode).
只读 幂等
输入模式
{'type': 'object', 'required': ['action', 'text'], 'properties': {'text': {'type': 'string', 'description': 'Text to encode, or Base64 string to decode.'}, 'action': {'type': 'string', 'description': "Either 'encode' or 'decode'."}}}
color
Converts a color between hex, RGB and HSL. Provide exactly one of hex, rgb or hsl.
只读 幂等
输入模式
{'type': 'object', 'required': [], 'properties': {'hex': {'type': 'string', 'description': 'Hex color code, e.g. #ff0000 or ff0000. Provide exactly one of hex, rgb, or hsl.'}, 'hsl': {'type': 'string', 'description': 'HSL color, e.g. 0,100%,50%. Provide exactly one of hex, rgb, or hsl.'}, 'rgb': {'type': 'string', 'description': 'RGB color, e.g. 255,0,0. Provide exactly one of hex, rgb, or hsl.'}}}
csv_json
Converts CSV text to JSON or JSON to CSV (direction: csv-to-json or json-to-csv), for data passed inline. CSV must be comma-separated, with a header row and at least one data row; double-quoted fields may contain commas. Semicolon- or tab-separated input is not detected and comes back as a single column. JSON input must be an array of objects: the union of their keys becomes the CSV header and missing values are left empty. Returns result (the converted text), rows and cols. Max 500,000 characters.
只读 幂等
输入模式
{'type': 'object', 'required': ['direction', 'data'], 'properties': {'data': {'type': 'string', 'description': 'The CSV or JSON text to convert, matching the chosen direction.'}, 'direction': {'type': 'string', 'description': "Either 'csv-to-json' or 'json-to-csv'."}}}
cve_lookup
Looks up a vulnerability by identifier (CVE, GHSA or other OSV ID) on OSV.dev: summary, CVSS severity, affected packages and versions, references. Use when you already have an ID; use vulnerability_check when you have a package name instead.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'CVE, GHSA, or other OSV-native identifier, e.g. CVE-2021-44228.'}}}
dns_lookup
Returns DNS records for a domain via Cloudflare DNS-over-HTTPS: A, AAAA, CNAME, MX, TXT and NS in one call, or a single record type with 'type'. For registration data use whois_lookup; for SPF/DMARC/DKIM analysis use email_security.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'type': {'type': 'string', 'description': 'Narrow to a single record type. Omit to get all 6 at once.'}, 'domain': {'type': 'string', 'description': 'Domain to look up, e.g. example.com.'}}}
email_disposable
Checks only whether an email address uses a known disposable/temporary email domain. For syntax, MX, disposable and role-account checks in one call, use email_verify.
只读 幂等
输入模式
{'type': 'object', 'required': ['email'], 'properties': {'email': {'type': 'string', 'description': 'Email address to check against a list of known disposable/temporary email domains.'}}}
email_security
Audits a domain's email anti-spoofing setup: SPF strength, DMARC policy and a best-effort DKIM lookup on common selectors. A missing DKIM match does not prove DKIM is absent. Checks a domain, not a single address.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to check SPF, DKIM, and DMARC records for, e.g. example.com.'}}}
email_validate
Lightweight email check: syntax plus confirmation that the domain has an MX record. Does not detect disposable or role addresses; use email_verify for the combined check.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['email'], 'properties': {'email': {'type': 'string', 'description': 'Email address to validate for correct syntax and a resolvable domain.'}}}
email_verify
Most complete email check in one call: syntax, MX record, disposable-domain detection and role/generic account detection (e.g. info@, admin@). Prefer it over email_validate and email_disposable unless you need a single signal. Does not probe the mailbox. valid is null (not false) when the MX lookup could not be completed; retry later instead of treating the address as invalid.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['email'], 'properties': {'email': {'type': 'string', 'description': 'Email address to run through combined syntax, disposable-domain, and MX-record checks.'}}}
favicon
Returns the favicon URL a website declares: fetches the homepage and takes the first <link rel='icon'> (or 'shortcut icon') href, resolved to an absolute URL, which may be a data: URI when the page inlines its icon (source: declared). If no icon is declared, or the homepage cannot be fetched, returns the conventional https://<domain>/favicon.ico with source: default and a note, without checking that it exists. Use it to display a site icon; it does not download or validate the image.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to fetch the favicon URL for, e.g. example.com.'}}}
iban_validate
Validates an IBAN offline: ISO 7064 mod-97 checksum and country-specific length. Confirms the number is well-formed, not that the account exists.
只读 幂等
输入模式
{'type': 'object', 'required': ['iban'], 'properties': {'iban': {'type': 'string', 'description': 'IBAN to validate. Spaces are ignored.'}}}
ip_reputation
Checks an IPv4 or IPv6 address against a curated list of netblocks known to be hijacked or run by spam/cyber-crime operations (IPv4-mapped IPv6 uses the IPv4 list). A narrow list-based signal: a clean result is not a safety guarantee. Includes list date and attribution.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['ip'], 'properties': {'ip': {'type': 'string', 'description': 'IPv4 or IPv6 address to check (IPv4-mapped IPv6 such as ::ffff:1.2.3.4 is checked against the IPv4 list) against a curated list of known hijacked or cyber-crime-controlled netblocks.'}}}
jwt_decode
Decodes a JWT's header and payload WITHOUT verifying its signature, so its claims must not be trusted on this basis alone. To check authenticity, use jwt_verify.
只读 幂等
输入模式
{'type': 'object', 'required': ['token'], 'properties': {'token': {'type': 'string', 'description': 'The JWT to decode. Decodes header and payload only -- does not verify the signature (use /jwt-verify for that).'}}}
jwt_verify
Cryptographically verifies a JWT signature (HS256/384/512, RS/PS256/384/512, ES256/384/512) and checks exp/nbf claims. Provide a secret for HS*, or a JWK or JWKS URL for RS/PS/ES. Use instead of jwt_decode whenever authenticity matters.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['token'], 'properties': {'jwk': {'type': 'object', 'description': 'Public key in JWK format, for RS/PS/ES algorithms.'}, 'token': {'type': 'string', 'description': 'The JWT to verify. Checks the cryptographic signature -- use /jwt-decode if you only need to read the header and payload.'}, 'secret': {'type': 'string', 'description': 'Required for HS256/384/512.'}, 'jwks_url': {'type': 'string', 'description': 'URL to a JWKS document; the key is matched by the token\'s "kid" header.'}}}
link_metadata
Fetches a web page and extracts its title, description, canonical URL, Open Graph and Twitter Card tags (the data behind link previews). To follow a URL's redirects hop by hop, use redirect_trace.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to extract title, description, and Open Graph / Twitter Card metadata from.'}}}
maintainer_change_check
npm only. Flags a previously unseen human publisher taking over a package after 180+ days of inactivity, within the last 365 days (the event-stream attack pattern). npm trusted publishing (verified OIDC identity, not just a bot-like account name), pre-release, and handovers to a publisher who already maintains another widely used package (100k+ weekly downloads) are reported but not flagged. Does not detect hijacked existing accounts; a heuristic for review, not proof.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name, e.g. lodash'}, 'ecosystem': {'type': 'string', 'description': "Currently only 'npm' is supported."}}}
password
Generates a random password, with options for length, symbols, uppercase, numbers and excluding ambiguous characters. To evaluate an existing password, use password_check.
只读 幂等
输入模式
{'type': 'object', 'required': [], 'properties': {'length': {'type': 'string', 'description': 'Desired password length. Defaults to a reasonable secure length if omitted.'}, 'numbers': {'type': 'string', 'description': 'Whether to include numeric digits. 1 for yes, 0 for no.'}, 'symbols': {'type': 'string', 'description': 'Whether to include symbol characters. 1 for yes, 0 for no.'}, 'uppercase': {'type': 'string', 'description': 'Whether to include uppercase letters. 1 for yes, 0 for no.'}, 'exclude_ambiguous': {'type': 'string', 'description': 'Whether to exclude visually ambiguous characters (e.g. 0/O, 1/l). 1 for yes, 0 for no.'}}}
password_breach
Checks whether a password appears in known data breaches (Have I Been Pwned) and how many times, using k-anonymity towards HIBP. Breach check only; password_check adds strength scoring and sends the password in a POST body.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['password'], 'properties': {'password': {'type': 'string', 'description': "Password to check against known data-breach corpora. Only a 5-character SHA-1 hash prefix is sent to HIBP (k-anonymity), but the password itself travels in this request's URL; for real passwords, prefer password_check, which takes it in a POST body."}}}
password_check
Scores a password's strength (length, character variety, entropy, common patterns) and, with check_breach=true, also looks it up in Have I Been Pwned breach data via k-anonymity (only a hash prefix is sent). Use it to evaluate a password someone is choosing; use password_breach when you only need the breach count, and password to generate a new one. The password travels in a POST body, never in a URL.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['password'], 'properties': {'password': {'type': 'string', 'description': 'Password to evaluate for strength (length, character variety, common patterns).'}, 'check_breach': {'type': 'boolean', 'description': 'Whether to also check the password against known data-breach corpora via k-anonymity. true or false.'}}}
phone_verify
Validates and formats a phone number: validity, country, line type, E.164, international and national formats. Numbers without a leading + require 'country', since the end user's country cannot be inferred over MCP.
只读 幂等
输入模式
{'type': 'object', 'required': ['number'], 'properties': {'number': {'type': 'string', 'description': 'Phone number to validate and format, ideally in E.164 format (e.g. +14155552671).'}, 'country': {'type': 'string', 'description': "ISO 3166-1 alpha-2 country code (e.g. US, FR). Required unless the number starts with +: over MCP the end user's country cannot be inferred."}}}
redirect_trace
Follows a URL's full redirect chain (up to 15 hops) and returns every hop with its status code, plus whether the chain crossed domains. Use it to see where a short or tracking link really leads; check the final URL with url_reputation.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to follow the full redirect chain for, hop by hop.'}}}
repo_health_check
Maintenance signals for a GitHub repository given as owner/name: stars, forks, open issues, license, archived and fork flags, creation date and age, days since last push, topics. Use it to judge whether a dependency looks maintained or abandoned. For an npm or PyPI package whose repository you do not know, supply_chain_check resolves it from registry metadata and includes these signals. GitHub only; missing or private repositories return found: false.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['repo'], 'properties': {'repo': {'type': 'string', 'description': 'GitHub repository in owner/name format, e.g. lodash/lodash.'}}}
rpc_check
Read-only audit of a public CometBFT (Cosmos SDK) RPC endpoint: node status, health, peers, and whether unsafe admin methods (dial_seeds, dial_peers, unsafe_flush_mempool) are publicly exposed. Never calls an unsafe method; exposure is inferred from the node's route listing.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'Base URL of a CometBFT RPC endpoint to audit, e.g. https://rpc.cosmos.network:443.'}}}
security_headers
Audits the HTTP security headers of one URL (CSP, HSTS, X-Frame-Options, Permissions-Policy, cross-origin policies and others) and returns per-header findings with fix advice, a score and a letter grade. Use it when you need header hardening advice; security_scan runs this audit together with URL reputation and subdomain discovery in one call.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to audit HTTP security headers for (CSP, HSTS, X-Frame-Options, etc.).'}}}
security_scan
Combined website check in one call: security headers, URL reputation and passive subdomain discovery, run in parallel, with an overall score and verdict. Use the individual tools when you need a single signal.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to run a combined security posture check against (headers, reputation, and related signals).'}}}
subdomains
Passive subdomain discovery from Certificate Transparency logs (crt.sh): finds hostnames that appeared in public TLS certificates, not every DNS record. crt.sh is occasionally slow or unavailable.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to passively discover subdomains for via Certificate Transparency logs, e.g. example.com.'}}}
supply_chain_check
One-call risk check for a package: combines vulnerability_check (OSV.dev), typosquat_check, maintainer_change_check (npm only) and repo_health_check (when the GitHub repo can be resolved) into one overall verdict. Use before adding a dependency; use the individual tools to investigate one signal.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check.'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm. maintainer-change-check only runs for npm.'}}}
text_similarity
Near-duplicate detection with a 64-bit SimHash over word shingles: send 1 text to get its hash, or 2 texts to compare them. Detects paraphrased or lightly edited copies; unrelated texts score around 50%, not 0%.
只读 幂等
输入模式
{'type': 'object', 'required': ['texts'], 'properties': {'texts': {'type': 'array', 'description': '1 text (hash only) or 2 texts (compare). Max 200,000 characters each.'}}}
timestamp
Returns the current time, or converts between a Unix timestamp (seconds) and an ISO date. Provide unix or date, or neither for the current time.
只读 幂等
输入模式
{'type': 'object', 'required': [], 'properties': {'date': {'type': 'string', 'description': 'Date/time string to convert to a Unix timestamp. Provide either unix or date, not both.'}, 'unix': {'type': 'string', 'description': 'Unix timestamp (seconds since epoch) to convert to a human-readable date. Provide either unix or date, not both.'}}}
tx_decode
Decodes a raw signed Cosmos SDK transaction (base64 TxRaw bytes, as found in a CometBFT block's data.txs) into JSON: messages, fee, gas, signers and signatures. Bank, staking, gov and authz messages are fully decoded; other types are returned as type URL plus raw hex.
只读 幂等
输入模式
{'type': 'object', 'required': ['tx'], 'properties': {'tx': {'type': 'string', 'description': "Base64-encoded Cosmos SDK TxRaw protobuf bytes, as returned by a chain's CometBFT RPC /block or /tx_search endpoints."}}}
typosquat_check
Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe.
只读 幂等
输入模式
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check for likely typosquatting of a well-known package in the given ecosystem.'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm or PyPI.'}}}
url_clean
Removes 60+ known tracking parameters (utm_*, fbclid, gclid and similar) from a URL and returns the clean URL. Does not follow redirects; for that, use redirect_trace.
只读 幂等
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to strip tracking parameters from (utm_*, fbclid, gclid, and similar).'}}}
url_reputation
Checks a URL against URLhaus (abuse.ch), a public database of known malware distribution URLs. A clean result only means the URL is not listed, not that it is safe.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'URL to check against known phishing/malware URL databases.'}}}
user_agent
Parses a User-Agent string into browser and version, operating system and version, device type, and whether it looks like a bot.
只读 幂等
输入模式
{'type': 'object', 'required': ['ua'], 'properties': {'ua': {'type': 'string', 'description': "User-Agent string to parse. Required over MCP: the server cannot see the end user's own User-Agent."}}}
uuid
Generates 1 to 100 random UUID v4 values.
只读 幂等
输入模式
{'type': 'object', 'required': [], 'properties': {'count': {'type': 'string', 'description': 'Number of UUIDs (v4) to generate. Defaults to 1 if omitted.'}}}
vat_validate
Checks an EU VAT number in real time against the European Commission's VIES service and, when valid, returns the registered company name and address. VIES is occasionally unavailable for some member states.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['vat'], 'properties': {'vat': {'type': 'string', 'description': 'VAT number, with or without the country prefix.'}, 'country': {'type': 'string', 'description': '2-letter EU country code (EL for Greece, XI for Northern Ireland). Optional if vat includes the prefix.'}}}
vulnerability_check
Checks a package (optionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. Use cve_lookup when you already have a CVE/GHSA ID, or supply_chain_check for a combined verdict.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['ecosystem', 'package'], 'properties': {'package': {'type': 'string', 'description': 'Package name to check against OSV.dev for known CVEs.'}, 'version': {'type': 'string', 'description': 'Omit to check all versions of the package.'}, 'ecosystem': {'type': 'string', 'description': 'Package ecosystem, e.g. npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist, or NuGet.'}}}
whois_lookup
Domain registration data via RDAP (the modern WHOIS): registrar, creation and expiration dates, domain age in days, nameservers. For DNS records, use dns_lookup.
只读 可访问外部资源 幂等
输入模式
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'Domain to look up registration details for via RDAP, e.g. example.com.'}}}
已更改
password_breach
2026年9月29日 02:56
已更改
email_verify
2026年9月29日 02:56
已更改
address_risk
2026年9月29日 02:56
已移除
ip
2026年9月27日 02:47
已更改
whois_lookup
2026年9月27日 02:47
已更改
vulnerability_check
2026年9月27日 02:47
已添加
vat_validate
2026年9月27日 02:47
已更改
uuid
2026年9月27日 02:47
已更改
user_agent
2026年9月27日 02:47
已更改
url_reputation
2026年9月27日 02:47
已更改
url_clean
2026年9月27日 02:47
已更改
typosquat_check
2026年9月27日 02:47
已更改
tx_decode
2026年9月27日 02:47
已更改
timestamp
2026年9月27日 02:47
已更改
text_similarity
2026年9月27日 02:47
已更改
supply_chain_check
2026年9月27日 02:47
已更改
subdomains
2026年9月27日 02:47
已更改
security_scan
2026年9月27日 02:47
已更改
security_headers
2026年9月27日 02:47
已更改
rpc_check
2026年9月27日 02:47
已更改
repo_health_check
2026年9月27日 02:47
已更改
redirect_trace
2026年9月27日 02:47
已更改
phone_verify
2026年9月27日 02:47
已更改
password_check
2026年9月27日 02:47
已更改
password_breach
2026年9月27日 02:47
已更改
password
2026年9月27日 02:47
已更改
maintainer_change_check
2026年9月27日 02:47
已添加
link_metadata
2026年9月27日 02:47
已更改
jwt_verify
2026年9月27日 02:47
已更改
jwt_decode
2026年9月27日 02:47

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…