Index / Verified tools / Security and compliance

Security and compliance

Scanning, auditing, sanctions and vulnerability data. Every tool below was read from that server's own tools/list, so the name and arguments are what the server exposes, not what its description claims.

ToolServer
cveanswers
Paid $0.01 USDC exact on Base: CVE / NVD vulnerability lookup via public NIST NVD 2.0. id=CVE-2021-44228 or q=log4j. Optional severity=low|medium|high|critical, hits=1..8. NVD-only metadata; no exploit/PoC. Complement...
arguments: id, q, severity, hits
x402 Checker (AI Nock)
io.github.nock-for-mak
cve_lookupanswers
Retrieve detailed CVE data by ID: description, CVSS v3.1 + vector, CVSS v2 (always emitted), EPSS score + percentile, CISA KEV status (expanded: due_date, required_action, ransomware flag, vendor_project, product, vul...
arguments: cve_id, include_affected_products, include_full_references, include_reference_tags, include_severity_breakdown
ContrastAPI
com.contrastcyber
cve_searchanswers
Search CVE database with filters: product/vendor, severity, published date range, EPSS score, CWE, CVSS range, CISA KEV status. Default response is SLIM per-result (cve_id, summary, severity, cvss_v3, cwe_id, epss, ke...
arguments: product, severity, published_after, published_before, kev, epss_min
ContrastAPI
com.contrastcyber
bulk_cve_lookupanswers
Batch query multiple CVEs (up to 50 per call, same for Free and Pro): retrieve full CVE details for all in 1 request instead of N. By default each CVE's affected_products is truncated to the first 20 entries (total_pr...
arguments: cve_ids, include_affected_products, include_full_references, include_reference_tags, include_severity_breakdown
ContrastAPI
com.contrastcyber
vessel_sanctionsanswers
SYNTHORA vessel-sanctions: screen any vessel (IMO or name) against the OFAC SDN sanctioned-vessels list (1,524 ships tracked) — the compliance check before touching tanker/shipping trades or chokepoint bets. List mode...
arguments: input
SYNTHORA x402 Intelligence Mesh
com.hergertsynthora
screen_sanctioned_nameanswers
Screen a counterparty name against a dated snapshot of the official EU Consolidated Financial Sanctions List. Returns ranked CANDIDATE designations with deterministic match scores, or 'clear'/'needs_review'/'possible_...
arguments: name, subjectType, country
Jithox EU Counterparty Sanctions Preflight
com.jithox
screen_sanctioned_identifieranswers
Deterministic EXACT match of an identifier (passport / national id / registration / other) against listed designations' identifiers — no fuzzy matching. 'match' / 'clear' / 'unavailable'. Screening evidence only; not ...
arguments: identifier, type
Jithox EU Counterparty Sanctions Preflight
com.jithox
get_sanctions_listinganswers
Return the full official listing detail (names, programme, legal basis, listing date, identifier types, countries) for a candidate logicalId surfaced by a prior screen, with provenance. 'found' / 'not_found' / 'unavai...
arguments: logicalId
Jithox EU Counterparty Sanctions Preflight
com.jithox
lion_compliance_bundleanswers
Full counterparty pack: OFAC + entity sanctions + domain + firmographics + signed receipt. Use instead of stacking wallet_screen + research. Needs an address. $0.05 Base USDC. [x402 paid: GET /api/x402/compliance-bund...
arguments: address, domain, token, name, receipt
LION — Verified Company & Compliance Data
com.lionx402
package_vulnerability_checkanswers
Look up a package (optionally pinned to a version) against OSV.dev's aggregated vulnerability database (GitHub Advisories, PyPA, RustSec, Go vuln DB, etc.) for known CVEs/advisories. Supports npm, PyPI, crates.io, Rub...
arguments: ecosystem, name, version
mcp-toolbelt
com.papacasper
compliance_signalanswers
Compliance-status snapshot for a company: screens against Treasury OFAC SDN entries and SEC enforcement actions, and returns a 0-100 compliance score, tier, decision_hint (proceed / proceed_with_review / escalate / bl...
arguments: company, domain, ticker, buyer_profile
Ready APIs
com.readyapis
compliance_walletanswers
Screen a blockchain wallet address against sanctioned/blacklisted crypto addresses (OFAC SDN, USDT Blacklist, USDC Blacklist, Ransomwhere, OpenSanctions, UK OFSI). Costs $0.003 USDC via x402.
arguments: address, chain
SENTINEL Compliance Intelligence
io.github.injprotocol
compliance_wallet_entityanswers
Compound Web2+Web3 screen: wallet address + entity name in one call with convergence detection. Bridges blockchain wallets to traditional sanctions databases. Costs $0.003 USDC via x402.
arguments: address, name, chain, list
SENTINEL Compliance Intelligence
io.github.injprotocol
check_sanctionsanswers
Public compliance pre-flight: fuzzy-match a name against the OpenSanctions consolidated dataset (EU/US/UK/UA/UN sanctions + PEP + crime lists). Returns top-N hits with similarity 0..1. Use BEFORE signing a CartMandate...
arguments: query, country, topic, limit
Gemalli B2B Trade
com.gemalli
GET /security/advisories/cvrf/cve/{cve_id}answers
Used to obtain an advisory in CVRF format for a given Common Vulnerability Enumerator (CVE). The `cve_id` format is CVE-YYYY-NNNN. For more information about CVE visit http://cve.mitre.org/
Cisco PSIRT openVuln API
cisco.com
check_vulnerabilityanswers
Is this exact package (and version) vulnerable? FULL historical lookup across the entire OSV.dev corpus (Google) — every matching advisory + the versions that fix it. Use to check a dependency: "does lodash 4.17.10 ha...
arguments: package, version, ecosystem
ai.dynamicfeed/dynamic-feed
ai.dynamicfeed
compliance_screenanswers
OFAC sanctions screening: is this address on the US OFAC sanctioned-address list? Send { address }. Every agent moving money legally needs this pre-transaction check. [x402 paid tool — price $0.05; POST /api/complianc...
arguments: address
ai.firmbrain/x402-services
ai.firmbrain
compliance_riskanswers
Address risk score (0-100): OFAC status, interaction with sanctioned addresses, contract verification, and activity, with a risk level and flags. Send { address }. Chainalysis-lite risk in one call. [x402 paid tool — ...
arguments: address
ai.firmbrain/x402-services
ai.firmbrain
compliance_taintanswers
Tainted-funds tracing: does this wallet's incoming money trace back to a sanctioned address within N hops? Multi-hop fund-flow trace on Base. Send { address, hops? }. Screen incoming payments before accepting them. [x...
arguments: address, hops
ai.firmbrain/x402-services
ai.firmbrain
cve-intelanswers
PAID MCP TOOL — $0.136 USDC per successful call via native x402. Discovery is free. CVE vulnerability lookup via NVD NIST. Query by CVE ID, keyword, or severity. Returns CVSS score, attack vector, CWEs, and references...
arguments: query, severity, days, limit
The Stall
ai.intuitek.the-stall
sanctions-screeninganswers
PAID MCP TOOL — $0.165 USDC per successful call via native x402. Discovery is free. OFAC SDN sanctions screening — checks whether a person, company, vessel, or aircraft appears on the US Treasury Specially Designated ...
arguments: name, type, limit
The Stall
ai.intuitek.the-stall
lookup_vulnerabilityanswers
Given a vulnerability identifier such as a CVE, return what is held about it: the affected package and version range, the version that fixes it, severity, and whether it is recorded as known-exploited. Use this when y...
arguments: cve
Daystruct
ai.daystruct.api
vulnerability_infoanswers
Get detailed information about a specific CVE. ## What this tool does Retrieves the full vulnerability record for a CVE from SecDB, including: - official description and summary - CVSS metrics (all versions available...
arguments: cve_id
ZEN SecDB
cloud.nttzen.secdb
vulnerability_scoreanswers
Get CVSS and current EPSS score for a specific CVE. ## What this tool does Returns a full risk snapshot for a CVE, including: - CVSS version - CVSS base score - CVSS severity - CVSS vector string - human-readable exp...
arguments: cve_id
ZEN SecDB
cloud.nttzen.secdb
vulnerability_searchanswers
Perform a full-text vulnerability search in SecDB. ## What this tool does Searches across: - CVE entries - Security advisories - Exploit references - Product and vendor vulnerability data Results are formatted in Ma...
arguments: query
ZEN SecDB
cloud.nttzen.secdb
compliance_edd_reportanswers
Build a paid enhanced due diligence memo for a wallet set using exact-match OFAC screening, sanctions evidence, and follow-up actions, returning structured JSON or an inline PDF/DOCX artifact. Use this for case handof...
arguments: subject_name, case_name, review_reason, jurisdiction, requested_by, reference_id
AurelianFlo
com.aurelianflo
lion_compliance_bundleanswers
Full counterparty pack: OFAC + entity sanctions + domain + firmographics + signed receipt. Use instead of stacking wallet_screen + research. Needs an address. $0.05 Base USDC. [x402 paid: GET /api/x402/compliance-bund...
arguments: address, domain, token, name, receipt
LION - keyless x402 data + RPC for agents
dev.workers.lionmaster-operations.lion-x402
screen_sanctionsanswers
Screen one or more person or company names against UN, EU, OFAC and PEP sanctions lists (768K+ entries via OpenSanctions). Typical use: counterparty checks before onboarding or processing a payment. Returns per-name m...
arguments: names, min_score, fuzzy
io.github.Mnymann/nordic-data
io.github.mnymann
check_complianceanswers
Run a full pre-flight compliance check on an IBAN before sending a SEPA / cross-border payment. USE WHEN: the user is about to send a payment / payout / refund and wants to triage risk first, asks "is this IBAN safe t...
arguments: iban
io.github.cammac-creator/ibanforge
io.github.cammac-creator
osv_get_vulnerabilityanswers
Fetch the full advisory record for an OSV vulnerability ID. Returns the complete record: summary, full details text, CVE aliases, all affected packages and version ranges, fix versions, CVSS severity vectors, CWE weak...
arguments: id
io.github.cyanheads/osv-advisory-mcp-server
io.github.cyanheads
sanctions_screen_nameanswers
Screen a name (person, company, vessel, aircraft) against all loaded sanctions watchlists at once — OFAC SDN + Consolidated, EU, UK, and UN — alias- and fuzzy-aware. Returns scored potential matches with the source li...
arguments: name, entityType, matchMode, minScore, sources, limit
io.github.cyanheads/sanctions-screening-mcp-server
io.github.cyanheads
sanctions_get_designationanswers
Fetch the full record for one sanctions designation by source list + entry ID — the drill-in after sanctions_screen_name surfaces a candidate. Returns all published aliases, identifiers (passport/national-ID/tax), add...
arguments: source, entryId
io.github.cyanheads/sanctions-screening-mcp-server
io.github.cyanheads
sanctions_screenanswers
Screen a name against the official EU consolidated sanctions list (FISMA) — returns matches with a similarity score and context (EU reference, type, programme), not a binary yes/no. Price: $0.05 per call (x402 payment...
arguments: name, type, threshold, limit
io.github.digitalweb33333-creator/x402-endpoints
io.github.digitalweb33333-creator
cve_lookupanswers
Security vulnerability lookup (CVE) against the official NVD (NIST) database — by exact CVE id or by keyword/product. Returns description, CVSS severity, CWE weaknesses and references. Worldwide. Price: $0.01 per call...
arguments: cve_id, keyword, limit
io.github.digitalweb33333-creator/x402-endpoints
io.github.digitalweb33333-creator
compliance_wallet_screenanswers
Crypto wallet sanctions & compliance screening (AML/KYT): screen any EVM/Solana/Bitcoin/Tron/XRP wallet against the official OFAC SDN crypto list (UN/UK declared) with mixer (Tornado Cash) exposure and wallet age, ret...
arguments: wallet, chains
io.github.digitalweb33333-creator/x402-endpoints
io.github.digitalweb33333-creator
sanctions_screener_multianswers
Screening Sanctions Multi-listes — Gapup agent-payable C-suite expertise (RISK). Returns a structured, audited deliverable. Answers: For <entity>, run full OFAC + EU + UK HMT + UN + SECO + Canada SEMA + PEP + adverse ...
arguments: entity_type, entity_name, aliases, date_of_birth, country_of_registration, address
io.github.getgapup/gapup-mcp
io.github.getgapup
cve_security_lookupanswers
Look up CVE vulnerability data for enterprise security teams, DevSecOps and SOC analysts. Supports two modes: exact CVE ID lookup (e.g. 'CVE-2024-3094') or keyword search by product/vendor (e.g. 'openssl', 'Apache Tom...
arguments: query, mode, severity_min, published_after, max_results, async
io.github.getgapup/gapup-mcp
io.github.getgapup
dependency_vulnerability_scananswers
SCA (Software Composition Analysis) — scans a project dependency manifest and returns known vulnerabilities for each dependency. Supports: package.json (npm), requirements.txt (Python), go.mod (Go), Cargo.toml (Rust),...
arguments: mode, manifest_content, severity_min, include_transitive, async
io.github.getgapup/gapup-mcp
io.github.getgapup
company_fr_complianceanswers
Checks a French company against multiple public alert and sanctions sources. The absence of a match must not be interpreted as a guarantee of compliance. Use when: You need to check a French company against the suppor...
arguments: identifier, domain
HelpMyAgent
io.github.helpmyagent
compliance_name_screenanswers
Screens a name against integrated French, UK and UN public sanctions/freezing lists using explainable fuzzy matching. Use when: Screen a person or organization name against public sanctions lists. You have a person or...
arguments: name, threshold
HelpMyAgent
io.github.helpmyagent
compliance_profileanswers
Returns your current compliance configuration (regime, retention_days, export_formats, enabled) and the catalog of supported regimes (EU AI Act Art.12, DORA, NYDFS 500, HIPAA, PCI DSS, SOC 2, generic) and export forma...
TunnelMind Data API
ai.tunnelmind
compliance_configureanswers
Set the customizable knob: which regulatory regime your auditor maps to, how long to retain decision content, and which export formats to offer. Body: { enabled?, regime?, retention_days?, export_formats? }. retention...
arguments: enabled, regime, retention_days, export_formats
TunnelMind Data API
ai.tunnelmind
compliance_ledgeranswers
Returns your hash-chained decision records — one per verdict-bearing call (/v1/verify, /v1/explain, /v1/preflight, /v1/profile) made while compliance is enabled. Each entry carries its node, verdict, scores, receipt_i...
arguments: from, to, cursor, limit
TunnelMind Data API
ai.tunnelmind
compliance_exportanswers
Generates a signed export bundle of your ledger over an optional time window, mapped to your regime's field names and citation, with a manifest + chain-integrity proof + the latest signed checkpoint. Choose the format...
arguments: format, regime, from, to
TunnelMind Data API
ai.tunnelmind
compliance_verifyanswers
Recomputes your entire hash chain server-side and reports integrity ({ intact, entry_count, chain_head_hash } — plus reason + first_break_seq if a record was altered or deleted), alongside the most recent Ed25519 chec...
TunnelMind Data API
ai.tunnelmind
kev_status_by_cveanswers
CISA Known Exploited Vulnerabilities status for one CVE: whether it is on the KEV catalog, the due date, required action and ransomware-campaign flag. $0.01 per call via x402 (USDC on Base); response includes a proven...
arguments: id, payment
Clink Forge
com.clinkforge
tech_stack_cve_auditanswers
Composite tech-stack + CVE audit (MCP-only, no REST endpoint). Detects technologies on the target domain, queries CVE database for known vulnerabilities per product, enriches top-10 CVE candidates with CISA KEV federa...
arguments: domain
ContrastAPI
com.contrastcyber
cve_leadinganswers
List CVEs indexed from MITRE/GHSA BEFORE NVD publication (early-warning, freshest data). By default each result is slim (no description, no cvss_breakdown, no affected_products list, no references) — pass include='ful...
arguments: limit, offset, include
ContrastAPI
com.contrastcyber
gns_get_compliance_reportanswers
Returns a full EU AI Act compliance report for a GNS agent, including trust score, chain verification, Merkle epoch proofs, delegation certificate, and regulatory status.
arguments: agentHandle
com.geiant/mcp-perception
com.geiant
firm_compliance_historyanswers
Build a recent, source-bounded FDA public-record timeline for a device firm: matched recalls, warning letters, and Form 483 citations where exact FEI numbers are available. Product codes are discovered from Constat's ...
arguments: firm_name, product_codes, fei_numbers, since, limit
Constat MCP — FDA Device Evidence Lifecycle
com.healthai
sanctions_screenanswers
SYNTHORA sanctions-screen: sanctions screening with MATCH / CLEAR verdict over 4 official downloads (OFAC SDN primary and alias lists, UN, OpenSanctions). Multilingual, tested on Cyrillic transliterations.
arguments: input
SYNTHORA x402 Intelligence Mesh
com.hergertsynthora
list_sanctions_regimesanswers
Enumerate the EU sanctions programmes/regimes present in the snapshot (regulation/legal basis, since date, subject count) — the policy-layer read. 'found' / 'unavailable'. Reference only, not legal advice. Every resul...
Jithox EU Counterparty Sanctions Preflight
com.jithox
lion_multi_sanctions_bundleanswers
Use when you have an address AND/OR entity name/domain and need a signed multi-list receipt. Prefer over lion_wallet_screen when you need more than OFAC SDN. $0.02 Base USDC. [x402 paid: GET /api/x402/multi-sanctions-...
arguments: address, name, domain
LION — Verified Company & Compliance Data
com.lionx402
sanction_watch_searchanswers
Search Japanese administrative sanctions (FSA jirei archive). Each hit includes firstSeenAt and ledgerVerified.
arguments: query, regulator, sanctionType, status, since, limit
Japan Public Ledgers MCP
com.mcp-revenue-empire
sanction_watch_getanswers
Get a sanction detail plus full event timeline. Returns firstSeenAt and ledgerVerified.
arguments: itemId
Japan Public Ledgers MCP
com.mcp-revenue-empire
sanction_watch_timelineanswers
Time-ordered events only for a sanction (the differentiator: when it appeared and when it was lifted). Includes firstSeenAt and ledgerVerified.
arguments: itemId
Japan Public Ledgers MCP
com.mcp-revenue-empire
sanction_watch_recent_changesanswers
Recent appearance / lift events across all sanctions since the given ISO8601 timestamp. Each item includes firstSeenAt and ledgerVerified.
arguments: since, regulator, limit
Japan Public Ledgers MCP
com.mcp-revenue-empire
sanction_watch_verify_ledgeranswers
Verify the hash-chain integrity of a sanction record (tamper detection). Returns chainValid, brokenAt (if any), checked event count, firstSeenAt and ledgerVerified.
arguments: itemId
Japan Public Ledgers MCP
com.mcp-revenue-empire
onchain_risk_sanctions_screenanswers
Screen an address against the bundled OFAC-style sanction list; returns the sanctioned flag, any matches and the list size. Pure list lookup. Read-only; price 0.0 (free).
arguments: address, chain
Japan Public Ledgers MCP
com.mcp-revenue-empire
sanctions_screen_entityanswers
Screen an entity name against public consolidated sanctions lists (OFAC SDN / UN / EU), fetched at request time. Returns scored fuzzy matches with programs and countries. Informational only, not legal advice. Read-onl...
arguments: name, minScore, types, limit
Japan Public Ledgers MCP
com.mcp-revenue-empire
Showing 60 of 520 verified tools. Search the whole set, including full input schemas, at https://neuronto.com/tools?q=..., or connect an agent to https://neuronto.com/mcp and call find_tool. No key, no signup.

"Answers" means the endpoint responded to a handshake when last probed, and "auth required" means it demanded credentials. Both are statements about reachability, never about trustworthiness.

Other capabilities

Analytics and monitoring
6,547 verified tools
Maps, location and weather
6,463 verified tools
Calendar and scheduling
5,527 verified tools
Files and storage
5,336 verified tools
Payments and billing
5,054 verified tools
Crypto and blockchain
4,389 verified tools
Legal and government data
4,159 verified tools
Science and research
4,038 verified tools
GitHub and version control
3,679 verified tools