Index / Verified tools / Security and compliance

Security and compliance

Scanning, auditing, sanctions and vulnerability data. Every tool below was read from that server's own tools/list, so the name and arguments are what the server exposes, not what its description claims.

ToolServer
check_vulnerabilityanswers
Is this exact package (and version) vulnerable? FULL historical lookup across the entire OSV.dev corpus (Google) — every matching advisory + the versions that fix it. Use to check a dependency: "does lodash 4.17.10 ha...
arguments: package, version, ecosystem
ai.dynamicfeed/dynamic-feed
ai.dynamicfeed
compliance_screenanswers
OFAC sanctions screening: is this address on the US OFAC sanctioned-address list? Send { address }. Every agent moving money legally needs this pre-transaction check. [x402 paid tool — price $0.05; POST /api/complianc...
arguments: address
ai.firmbrain/x402-services
ai.firmbrain
compliance_riskanswers
Address risk score (0-100): OFAC status, interaction with sanctioned addresses, contract verification, and activity, with a risk level and flags. Send { address }. Chainalysis-lite risk in one call. [x402 paid tool — ...
arguments: address
ai.firmbrain/x402-services
ai.firmbrain
compliance_taintanswers
Tainted-funds tracing: does this wallet's incoming money trace back to a sanctioned address within N hops? Multi-hop fund-flow trace on Base. Send { address, hops? }. Screen incoming payments before accepting them. [x...
arguments: address, hops
ai.firmbrain/x402-services
ai.firmbrain
cve-intelanswers
PAID MCP TOOL — $0.136 USDC per successful call via native x402. Discovery is free. CVE vulnerability lookup via NVD NIST. Query by CVE ID, keyword, or severity. Returns CVSS score, attack vector, CWEs, and references...
arguments: query, severity, days, limit
The Stall
ai.intuitek.the-stall
sanctions-screeninganswers
PAID MCP TOOL — $0.165 USDC per successful call via native x402. Discovery is free. OFAC SDN sanctions screening — checks whether a person, company, vessel, or aircraft appears on the US Treasury Specially Designated ...
arguments: name, type, limit
The Stall
ai.intuitek.the-stall
vulnerability_infoanswers
Get detailed information about a specific CVE. ## What this tool does Retrieves the full vulnerability record for a CVE from SecDB, including: - official description and summary - CVSS metrics (all versions available...
arguments: cve_id
ZEN SecDB
cloud.nttzen.secdb
vulnerability_scoreanswers
Get CVSS and current EPSS score for a specific CVE. ## What this tool does Returns a full risk snapshot for a CVE, including: - CVSS version - CVSS base score - CVSS severity - CVSS vector string - human-readable exp...
arguments: cve_id
ZEN SecDB
cloud.nttzen.secdb
vulnerability_searchanswers
Perform a full-text vulnerability search in SecDB. ## What this tool does Searches across: - CVE entries - Security advisories - Exploit references - Product and vendor vulnerability data Results are formatted in Ma...
arguments: query
ZEN SecDB
cloud.nttzen.secdb
compliance_edd_reportanswers
Build a paid enhanced due diligence memo for a wallet set using exact-match OFAC screening, sanctions evidence, and follow-up actions, returning structured JSON or an inline PDF/DOCX artifact. Use this for case handof...
arguments: subject_name, case_name, review_reason, jurisdiction, requested_by, reference_id
AurelianFlo
com.aurelianflo
cve_lookupanswers
Retrieve detailed CVE data by ID: description, CVSS v3.1 + vector, CVSS v2 (always emitted), EPSS score + percentile, CISA KEV status (expanded: due_date, required_action, ransomware flag, vendor_project, product, vul...
arguments: cve_id, include_affected_products, include_full_references, include_reference_tags, include_severity_breakdown
ContrastAPI
com.contrastcyber
cve_searchanswers
Search CVE database with filters: product/vendor, severity, published date range, EPSS score, CWE, CVSS range, CISA KEV status. Default response is SLIM per-result (cve_id, summary, severity, cvss_v3, cwe_id, epss, ke...
arguments: product, severity, published_after, published_before, kev, epss_min
ContrastAPI
com.contrastcyber
bulk_cve_lookupanswers
Batch query multiple CVEs (up to 50 per call, same for Free and Pro): retrieve full CVE details for all in 1 request instead of N. By default each CVE's affected_products is truncated to the first 20 entries (total_pr...
arguments: cve_ids, include_affected_products, include_full_references, include_reference_tags, include_severity_breakdown
ContrastAPI
com.contrastcyber
vessel_sanctionsanswers
SYNTHORA vessel-sanctions: screen any vessel (IMO or name) against the OFAC SDN sanctioned-vessels list (1,524 ships tracked) — the compliance check before touching tanker/shipping trades or chokepoint bets. List mode...
arguments: input
com.hergertsynthora/synthora-x402
com.hergertsynthora
screen_sanctioned_nameanswers
Screen a counterparty name against a dated snapshot of the official EU Consolidated Financial Sanctions List. Returns ranked CANDIDATE designations with deterministic match scores, or 'clear'/'needs_review'/'possible_...
arguments: name, subjectType, country
Jithox EU Counterparty Sanctions Preflight
com.jithox
screen_sanctioned_identifieranswers
Deterministic EXACT match of an identifier (passport / national id / registration / other) against listed designations' identifiers — no fuzzy matching. 'match' / 'clear' / 'unavailable'. Screening evidence only; not ...
arguments: identifier, type
Jithox EU Counterparty Sanctions Preflight
com.jithox
get_sanctions_listinganswers
Return the full official listing detail (names, programme, legal basis, listing date, identifier types, countries) for a candidate logicalId surfaced by a prior screen, with provenance. 'found' / 'not_found' / 'unavai...
arguments: logicalId
Jithox EU Counterparty Sanctions Preflight
com.jithox
lion_compliance_bundleanswers
Full counterparty pack: OFAC + entity sanctions + domain + firmographics + signed receipt. Use instead of stacking wallet_screen + research. Needs an address. $0.05 Base USDC. [x402 paid: GET /api/x402/compliance-bund...
arguments: address, domain, token, name, receipt
LION - keyless attested data for AI agents
com.lionx402
package_vulnerability_checkanswers
Look up a package (optionally pinned to a version) against OSV.dev's aggregated vulnerability database (GitHub Advisories, PyPA, RustSec, Go vuln DB, etc.) for known CVEs/advisories. Supports npm, PyPI, crates.io, Rub...
arguments: ecosystem, name, version
mcp-toolbelt
com.papacasper
compliance_signalanswers
Compliance-status snapshot for a company: screens against Treasury OFAC SDN entries and SEC enforcement actions, and returns a 0-100 compliance score, tier, decision_hint (proceed / proceed_with_review / escalate / bl...
arguments: company, domain, ticker, buyer_profile
Ready APIs
com.readyapis
top_cves_todayanswers
PAID — unlock with an AIS Gateway key (https://aislabs.ai/gateway) or x402 $0.02. Today's FULL ranked CVE priority list with scores, KEV, EPSS, patch status, and methodology.
AIS Gateway — CVE prioritization + Agent Flight Recorder for AI agents
ai.aislabs
cve_verdictanswers
PAID — unlock with an AIS Gateway key (https://aislabs.ai/gateway) or x402 $0.005. One CVE's priority verdict from today's AIS ranked set.
arguments: cve_id
AIS Gateway — CVE prioritization + Agent Flight Recorder for AI agents
ai.aislabs
sanctions_screenanswers
Screen a name against the US OFAC SDN + UK Sanctions List (FCDO, Open Government Licence) — keyless. `name` = party to check; optional `program` (an OFAC program e.g. IRAN/CUBA, or a UK regime/origin). Each result is ...
arguments: name, program, limit
ai.dynamicfeed/dynamic-feed
ai.dynamicfeed
compliance_labelanswers
Entity labeling: is this address an EOA, a (proxy) contract, a known protocol, or flagged as scam — with name and public tags. Send { address }. [x402 paid tool — price $0.05; POST /api/compliance/label]
arguments: address
ai.firmbrain/x402-services
ai.firmbrain
check_complianceanswers
Check if a supplier meets compliance requirements for a target export market. USE WHEN: - User asks "can this factory export to the US/EU/Japan" - User needs to verify certifications for a specific market - "UFLPA / ...
arguments: supplier_id, target_market, verbose_hints
MRC Data — China's Apparel Supply Chain Infrastructure
ai.meacheal
sanctions_screenanswers
Screen a name against global sanctions and watchlists. FREE TIER: 3 screens per day without an API key. PAID: Unlimited screens with an API key. Checks the name against 300+ sanctions, designation and watchlists wor...
arguments: name, api_key, threshold, subject_type
ai.ohmyfin/banking-intelligence
ai.ohmyfin
get_complianceanswers
Get full compliance rules evaluation for a company. Runs Nasdaq/NYSE deficiency detection, bid price tracking, and delinquent filing detection. Returns a comprehensive compliance picture combining SEC filing data, mar...
arguments: ticker
Signal8
ai.signal8
get_cve_recordanswers
Look up a single CVE Record v5.2 from the MITRE CVE List by ID (e.g. CVE-2024-3094). Lazy-fetched and cached 7 days. License: MITRE CVE Terms of Use, commercial redistribution permitted; the response includes the stan...
arguments: cve_id
TensorFeed
ai.tensorfeed
thinkneo_get_compliance_statusanswers
Get compliance status including framework coverage (EU AI Act, ISO 42001, NIST AI RMF, SOC 2) and governance assessments from the ThinkNEO gateway.
arguments: workspace, framework
ThinkNEO Control Plane
ai.thinkneo
thinkneo_compliance_generateanswers
Generate a compliance report for regulatory frameworks (EU AI Act, ISO 42001, SOC2, NIST). Exports from live audit data.
arguments: workspace, format, framework
ThinkNEO Control Plane
ai.thinkneo
compliance_profileanswers
Returns your current compliance configuration (regime, retention_days, export_formats, enabled) and the catalog of supported regimes (EU AI Act Art.12, DORA, NYDFS 500, HIPAA, PCI DSS, SOC 2, generic) and export forma...
TunnelMind Data API
ai.tunnelmind
compliance_configureanswers
Set the customizable knob: which regulatory regime your auditor maps to, how long to retain decision content, and which export formats to offer. Body: { enabled?, regime?, retention_days?, export_formats? }. retention...
arguments: enabled, regime, retention_days, export_formats
TunnelMind Data API
ai.tunnelmind
compliance_ledgeranswers
Returns your hash-chained decision records — one per verdict-bearing call (/v1/verify, /v1/explain, /v1/preflight, /v1/profile) made while compliance is enabled. Each entry carries its node, verdict, scores, receipt_i...
arguments: from, to, cursor, limit
TunnelMind Data API
ai.tunnelmind
compliance_exportanswers
Generates a signed export bundle of your ledger over an optional time window, mapped to your regime's field names and citation, with a manifest + chain-integrity proof + the latest signed checkpoint. Choose the format...
arguments: format, regime, from, to
TunnelMind Data API
ai.tunnelmind
compliance_verifyanswers
Recomputes your entire hash chain server-side and reports integrity ({ intact, entry_count, chain_head_hash } — plus reason + first_break_seq if a record was altered or deleted), alongside the most recent Ed25519 chec...
TunnelMind Data API
ai.tunnelmind
get_sanctions_dataanswers
OFAC SDN sanctioned entities list and sanctions pressure scores by country.
arguments: country, entity_type, query, limit, summary, jmespath
World Monitor
app.worldmonitor
compliance_checkanswers
Analyze regulatory obligations for a company based on jurisdiction, size and sector. Returns applicable frameworks, risk level and priority actions.
arguments: jurisdiction, company_size, sector, processes_personal_data, uses_ai
StructureClerk
ca.structureclerk
compliance_roadmapanswers
Generate a phased compliance action plan with cost estimates adapted to SME budgets.
arguments: jurisdiction, company_size, sector, budget, timeline_months
StructureClerk
ca.structureclerk
algorithmic_compliance_assessmentanswers
Assess algorithmic compliance maturity for AI systems. Returns applicable frameworks (EU AI Act, Law 25, AIDA/C-27, ISO 42001, NIST AI RMF), sector-specific obligations and assessment dimensions.
arguments: jurisdiction, sector
StructureClerk
ca.structureclerk
validate_tempo_token_complianceanswers
Tempo Stablecoin Issuance Compliance: OpenChainGraph compute node (compliance_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for ...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
validate_deposit_token_complianceanswers
Deposit-Token Compliance Validator: OpenChainGraph compute node (compliance_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gp...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
run_carbon_compliance_fitanswers
Carbon & Climate Compliance Fit Diagnostic: OpenChainGraph compute node (agent_guardrail_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare W...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
run_sanctions_screening_fitanswers
Sanctions & Export-Control Screening Fit Diagnostic: OpenChainGraph compute node (agent_guardrail_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Clo...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
score_sanctions_screening_qualityanswers
Sanctions Screening-Program Quality Scorer: OpenChainGraph compute node (model_governance). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers ...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
get_compliance_rulesanswers
Fetch LaunchTrust's sourced, founder-reviewed compliance rule snapshots, optionally filtered to one jurisdiction code (e.g. eu-ai-act-50, gdpr, ca-sb243). Compliance aid, not legal advice.
arguments: jurisdiction
LaunchTrust
co.launchtrust
get_compliance_by_stateanswers
Get the event staffing compliance summary for a US state. Returns minimum wage, overtime rules, and state-specific quirks. Perfect for 'What are the W-2 vs 1099 rules for event workers in [state]?', 'What's the minimu...
arguments: state
TempGuru Event Staffing
co.tempguru
assess_ai_complianceanswers
The compliance-report engine (deterministic, no LLM — cannot hallucinate) as a tool. Give a business profile; get the applicable AI-law obligations plus a reproducible 1–10 risk score with a named factor breakdown. `s...
arguments: state, sector, aiUse, ai_decision_impact, countries, bias_audit
AI Law Tracker
com.ai-law-tracker
generate_compliance_reportanswers
Generate the personalized, source-grounded AI-law COMPLIANCE REPORT for a business profile — the same deterministic engine behind the $79 report product (no LLM in the grounded path, so it cannot invent a statute, dea...
arguments: state, jurisdiction, sector, aiUse, ai_decision_impact, countries
AI Law Tracker
com.ai-law-tracker
compliance_exposure_forecastanswers
Forecast future OFAC wallet exposure for a wallet set using stored OFAC snapshot diffs when available, listedOn backfill when honest, or an explicit caller prior; returns current exact-match baseline, metadata-weighte...
arguments: addresses, address_metadata, asset, horizon_days, iterations, target
AurelianFlo
com.aurelianflo
compliance_queue_optimizeanswers
Optimize a compliance review queue using current OFAC exact matches, future exposure probabilities, exposure value, relationship tier, recency, and reviewer capacity. Use this when review_items and review_budget are k...
arguments: review_items, review_budget, objective, asset, horizon_days, iterations
AurelianFlo
com.aurelianflo
compliance_statusanswers
Company-level compliance posture rollup (pass rate, control compliance, mitigated counts, per-framework coverage). Suitable for a CI gate. Wraps the traceability company rollup.
arguments: scan_id, diagram_id
com.ayurak/aribot-mcp
com.ayurak
get_cloud_complianceanswers
Cloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/records, status — plus a company rollup. Reads customers.Acco...
arguments: account_id
com.ayurak/aribot-mcp
com.ayurak
compliance_scananswers
Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.
arguments: scan_type, account_id, diagram_id, frameworks, severity_filter, simulation_mode
com.ayurak/aribot-mcp
com.ayurak
check_action_complianceanswers
Pre-flight regulatory check. Agent describes an intended action in natural language ("process EU resident biometric data", "transfer health records to a third-party AI vendor", "deploy autonomous trading model in Sing...
arguments: action, jurisdiction, limit
bidda-compliance
com.bidda
map_complianceanswers
Map scan findings to compliance frameworks: NIST 800-177, PCI DSS 4.0, SOC 2, CIS Controls. Shows pass/fail/partial status per control.
arguments: domain, force_refresh, format
com.blackveilsecurity/dns
com.blackveilsecurity
search_sanctionsanswers
Searches CitationSafe's database of real court sanctions/orders arising from AI-hallucinated legal citations, by court name, party/case name keyword, or free-text keyword. Read-only, public data — same dataset backing...
arguments: query, court
Citation Safe Verifier
com.citationsafe
kev_status_by_cveanswers
CISA Known Exploited Vulnerabilities status for one CVE: whether it is on the KEV catalog, the due date, required action and ransomware-campaign flag. $0.01 per call via x402 (USDC on Base); response includes a proven...
arguments: id, payment
Clink Forge
com.clinkforge
tech_stack_cve_auditanswers
Composite tech-stack + CVE audit (MCP-only, no REST endpoint). Detects technologies on the target domain, queries CVE database for known vulnerabilities per product, enriches top-10 CVE candidates with CISA KEV federa...
arguments: domain
ContrastAPI
com.contrastcyber
cve_leadinganswers
List CVEs indexed from MITRE/GHSA BEFORE NVD publication (early-warning, freshest data). By default each result is slim (no description, no cvss_breakdown, no affected_products list, no references) — pass include='ful...
arguments: limit, offset, include
ContrastAPI
com.contrastcyber
explore_compliance_frameworkanswers
Look up a compliance / regulatory framework by short id. Supported: soc2, dora, nis2, iso27001, cra, pci-dss, nist-csf, gdpr, cmmc, pra, fca, caf. Returns description, key articles/controls, applicability, and a canon...
arguments: framework_id
ContinueOps Public MCP
com.continueops
Showing 60 of 182 verified tools. Search the whole set, including full input schemas, at https://neuronto.com/tools?q=..., or connect an agent to https://neuronto.com/mcp and call find_tool. No key, no signup.

"Answers" means the endpoint responded to a handshake when last probed, and "auth required" means it demanded credentials. Both are statements about reachability, never about trustworthiness.

Other capabilities

Analytics and monitoring
1,099 verified tools
Files and storage
1,035 verified tools
Calendar and scheduling
723 verified tools
Crypto and blockchain
708 verified tools
Payments and billing
706 verified tools
Images, audio and video
637 verified tools
Maps, location and weather
598 verified tools
Web scraping and browser automation
490 verified tools
Social media
481 verified tools