Index / Verified tools / Security and compliance

Security and compliance

Scanning, auditing, sanctions and vulnerability data. Every tool below was read from that server's own tools/list, so the name and arguments are what the server exposes, not what its description claims.

ToolServer
vulnerability_infoanswers
Get detailed information about a specific CVE. ## What this tool does Retrieves the full vulnerability record for a CVE from SecDB, including: - official description and summary - CVSS metrics (all versions available...
arguments: cve_id
ZEN SecDB
cloud.nttzen.secdb
vulnerability_scoreanswers
Get CVSS and current EPSS score for a specific CVE. ## What this tool does Returns a full risk snapshot for a CVE, including: - CVSS version - CVSS base score - CVSS severity - CVSS vector string - human-readable exp...
arguments: cve_id
ZEN SecDB
cloud.nttzen.secdb
vulnerability_searchanswers
Perform a full-text vulnerability search in SecDB. ## What this tool does Searches across: - CVE entries - Security advisories - Exploit references - Product and vendor vulnerability data Results are formatted in Ma...
arguments: query
ZEN SecDB
cloud.nttzen.secdb
compliance_edd_reportanswers
Build a paid enhanced due diligence memo for a wallet set using exact-match OFAC screening, sanctions evidence, and follow-up actions, returning structured JSON or an inline PDF/DOCX artifact. Use this for case handof...
arguments: subject_name, case_name, review_reason, jurisdiction, requested_by, reference_id
AurelianFlo
com.aurelianflo
cve_lookupanswers
Retrieve detailed CVE data by ID: description, CVSS v3.1 + vector, CVSS v2 (always emitted), EPSS score + percentile, CISA KEV status (expanded: due_date, required_action, ransomware flag, vendor_project, product, vul...
arguments: cve_id, include_affected_products, include_full_references, include_reference_tags, include_severity_breakdown
ContrastAPI
com.contrastcyber
cve_searchanswers
Search CVE database with filters: product/vendor, severity, published date range, EPSS score, CWE, CVSS range, CISA KEV status. Default response is SLIM per-result (cve_id, summary, severity, cvss_v3, cwe_id, epss, ke...
arguments: product, severity, published_after, published_before, kev, epss_min
ContrastAPI
com.contrastcyber
bulk_cve_lookupanswers
Batch query multiple CVEs (up to 50 per call, same for Free and Pro): retrieve full CVE details for all in 1 request instead of N. By default each CVE's affected_products is truncated to the first 20 entries (total_pr...
arguments: cve_ids, include_affected_products, include_full_references, include_reference_tags, include_severity_breakdown
ContrastAPI
com.contrastcyber
vessel_sanctionsanswers
SYNTHORA vessel-sanctions: screen any vessel (IMO or name) against the OFAC SDN sanctioned-vessels list (1,524 ships tracked) — the compliance check before touching tanker/shipping trades or chokepoint bets. List mode...
arguments: input
SYNTHORA x402 Intelligence Mesh
com.hergertsynthora
screen_sanctioned_nameanswers
Screen a counterparty name against a dated snapshot of the official EU Consolidated Financial Sanctions List. Returns ranked CANDIDATE designations with deterministic match scores, or 'clear'/'needs_review'/'possible_...
arguments: name, subjectType, country
Jithox EU Counterparty Sanctions Preflight
com.jithox
screen_sanctioned_identifieranswers
Deterministic EXACT match of an identifier (passport / national id / registration / other) against listed designations' identifiers — no fuzzy matching. 'match' / 'clear' / 'unavailable'. Screening evidence only; not ...
arguments: identifier, type
Jithox EU Counterparty Sanctions Preflight
com.jithox
get_sanctions_listinganswers
Return the full official listing detail (names, programme, legal basis, listing date, identifier types, countries) for a candidate logicalId surfaced by a prior screen, with provenance. 'found' / 'not_found' / 'unavai...
arguments: logicalId
Jithox EU Counterparty Sanctions Preflight
com.jithox
lion_compliance_bundleanswers
Full counterparty pack: OFAC + entity sanctions + domain + firmographics + signed receipt. Use instead of stacking wallet_screen + research. Needs an address. $0.05 Base USDC. [x402 paid: GET /api/x402/compliance-bund...
arguments: address, domain, token, name, receipt
LION - keyless attested data for AI agents
com.lionx402
package_vulnerability_checkanswers
Look up a package (optionally pinned to a version) against OSV.dev's aggregated vulnerability database (GitHub Advisories, PyPA, RustSec, Go vuln DB, etc.) for known CVEs/advisories. Supports npm, PyPI, crates.io, Rub...
arguments: ecosystem, name, version
mcp-toolbelt
com.papacasper
compliance_signalanswers
Compliance-status snapshot for a company: screens against Treasury OFAC SDN entries and SEC enforcement actions, and returns a 0-100 compliance score, tier, decision_hint (proceed / proceed_with_review / escalate / bl...
arguments: company, domain, ticker, buyer_profile
Ready APIs
com.readyapis
compliance_walletanswers
Screen a blockchain wallet address against sanctioned/blacklisted crypto addresses (OFAC SDN, USDT Blacklist, USDC Blacklist, Ransomwhere, OpenSanctions, UK OFSI). Costs $0.003 USDC via x402.
arguments: address, chain
SENTINEL Compliance Intelligence
io.github.injprotocol
compliance_wallet_entityanswers
Compound Web2+Web3 screen: wallet address + entity name in one call with convergence detection. Bridges blockchain wallets to traditional sanctions databases. Costs $0.003 USDC via x402.
arguments: address, name, chain, list
SENTINEL Compliance Intelligence
io.github.injprotocol
check_sanctionsanswers
Public compliance pre-flight: fuzzy-match a name against the OpenSanctions consolidated dataset (EU/US/UK/UA/UN sanctions + PEP + crime lists). Returns top-N hits with similarity 0..1. Use BEFORE signing a CartMandate...
arguments: query, country, topic, limit
Gemalli B2B Trade
com.gemalli
GET /security/advisories/cvrf/cve/{cve_id}answers
Used to obtain an advisory in CVRF format for a given Common Vulnerability Enumerator (CVE). The `cve_id` format is CVE-YYYY-NNNN. For more information about CVE visit http://cve.mitre.org/
Cisco PSIRT openVuln API
cisco.com
check_vulnerabilityanswers
Is this exact package (and version) vulnerable? FULL historical lookup across the entire OSV.dev corpus (Google) — every matching advisory + the versions that fix it. Use to check a dependency: "does lodash 4.17.10 ha...
arguments: package, version, ecosystem
ai.dynamicfeed/dynamic-feed
ai.dynamicfeed
compliance_screenanswers
OFAC sanctions screening: is this address on the US OFAC sanctioned-address list? Send { address }. Every agent moving money legally needs this pre-transaction check. [x402 paid tool — price $0.05; POST /api/complianc...
arguments: address
ai.firmbrain/x402-services
ai.firmbrain
compliance_riskanswers
Address risk score (0-100): OFAC status, interaction with sanctioned addresses, contract verification, and activity, with a risk level and flags. Send { address }. Chainalysis-lite risk in one call. [x402 paid tool — ...
arguments: address
ai.firmbrain/x402-services
ai.firmbrain
compliance_taintanswers
Tainted-funds tracing: does this wallet's incoming money trace back to a sanctioned address within N hops? Multi-hop fund-flow trace on Base. Send { address, hops? }. Screen incoming payments before accepting them. [x...
arguments: address, hops
ai.firmbrain/x402-services
ai.firmbrain
cve-intelanswers
PAID MCP TOOL — $0.136 USDC per successful call via native x402. Discovery is free. CVE vulnerability lookup via NVD NIST. Query by CVE ID, keyword, or severity. Returns CVSS score, attack vector, CWEs, and references...
arguments: query, severity, days, limit
The Stall
ai.intuitek.the-stall
sanctions-screeninganswers
PAID MCP TOOL — $0.165 USDC per successful call via native x402. Discovery is free. OFAC SDN sanctions screening — checks whether a person, company, vessel, or aircraft appears on the US Treasury Specially Designated ...
arguments: name, type, limit
The Stall
ai.intuitek.the-stall
lookup_vulnerabilityanswers
Given a vulnerability identifier such as a CVE, return what is held about it: the affected package and version range, the version that fixes it, severity, and whether it is recorded as known-exploited. Use this when y...
arguments: cve
Daystruct
ai.daystruct.api
compliance_profileanswers
Returns your current compliance configuration (regime, retention_days, export_formats, enabled) and the catalog of supported regimes (EU AI Act Art.12, DORA, NYDFS 500, HIPAA, PCI DSS, SOC 2, generic) and export forma...
TunnelMind Data API
ai.tunnelmind
compliance_configureanswers
Set the customizable knob: which regulatory regime your auditor maps to, how long to retain decision content, and which export formats to offer. Body: { enabled?, regime?, retention_days?, export_formats? }. retention...
arguments: enabled, regime, retention_days, export_formats
TunnelMind Data API
ai.tunnelmind
compliance_ledgeranswers
Returns your hash-chained decision records — one per verdict-bearing call (/v1/verify, /v1/explain, /v1/preflight, /v1/profile) made while compliance is enabled. Each entry carries its node, verdict, scores, receipt_i...
arguments: from, to, cursor, limit
TunnelMind Data API
ai.tunnelmind
compliance_exportanswers
Generates a signed export bundle of your ledger over an optional time window, mapped to your regime's field names and citation, with a manifest + chain-integrity proof + the latest signed checkpoint. Choose the format...
arguments: format, regime, from, to
TunnelMind Data API
ai.tunnelmind
compliance_verifyanswers
Recomputes your entire hash chain server-side and reports integrity ({ intact, entry_count, chain_head_hash } — plus reason + first_break_seq if a record was altered or deleted), alongside the most recent Ed25519 chec...
TunnelMind Data API
ai.tunnelmind
compliance_checkanswers
Analyze regulatory obligations for a company based on jurisdiction, size and sector. Returns applicable frameworks, risk level and priority actions.
arguments: jurisdiction, company_size, sector, processes_personal_data, uses_ai
StructureClerk
ca.structureclerk
compliance_roadmapanswers
Generate a phased compliance action plan with cost estimates adapted to SME budgets.
arguments: jurisdiction, company_size, sector, budget, timeline_months
StructureClerk
ca.structureclerk
algorithmic_compliance_assessmentanswers
Assess algorithmic compliance maturity for AI systems. Returns applicable frameworks (EU AI Act, Law 25, AIDA/C-27, ISO 42001, NIST AI RMF), sector-specific obligations and assessment dimensions.
arguments: jurisdiction, sector
StructureClerk
ca.structureclerk
validate_tempo_token_complianceanswers
Tempo Stablecoin Issuance Compliance: OpenChainGraph compute node (compliance_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for ...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
validate_deposit_token_complianceanswers
Deposit-Token Compliance Validator: OpenChainGraph compute node (compliance_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers for gp...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
run_carbon_compliance_fitanswers
Carbon & Climate Compliance Fit Diagnostic: OpenChainGraph compute node (agent_guardrail_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare W...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
run_sanctions_screening_fitanswers
Sanctions & Export-Control Screening Fit Diagnostic: OpenChainGraph compute node (agent_guardrail_mandate). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Clo...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
score_sanctions_screening_qualityanswers
Sanctions Screening-Program Quality Scorer: OpenChainGraph compute node (model_governance). Deterministic OpenChainGraph compute node. By default (compute:"auto") inputs are computed server-side on Cloudflare Workers ...
arguments: policy_parameters, compute, parent_hashes, parent_tool_ids
AINumbers Fintech Intelligence Suite
co.ainumbers
get_compliance_rulesanswers
Fetch LaunchTrust's sourced, founder-reviewed compliance rule snapshots, optionally filtered to one jurisdiction code (e.g. eu-ai-act-50, gdpr, ca-sb243). Compliance aid, not legal advice.
arguments: jurisdiction
LaunchTrust
co.launchtrust
get_compliance_by_stateanswers
Get the event staffing compliance summary for a US state. Returns minimum wage, overtime rules, and state-specific quirks. Perfect for 'What are the W-2 vs 1099 rules for event workers in [state]?', 'What's the minimu...
arguments: state
TempGuru Event Staffing
co.tempguru
assess_ai_complianceanswers
The compliance-report engine (deterministic, no LLM — cannot hallucinate) as a tool. Give a business profile; get the applicable AI-law obligations plus a reproducible 1–10 risk score with a named factor breakdown. `s...
arguments: state, sector, aiUse, ai_decision_impact, countries, bias_audit
AI Law Tracker
com.ai-law-tracker
generate_compliance_reportanswers
Generate the personalized, source-grounded AI-law COMPLIANCE REPORT for a business profile — the same deterministic engine behind the $79 report product (no LLM in the grounded path, so it cannot invent a statute, dea...
arguments: state, jurisdiction, sector, aiUse, ai_decision_impact, countries
AI Law Tracker
com.ai-law-tracker
compliance_exposure_forecastanswers
Forecast future OFAC wallet exposure for a wallet set using stored OFAC snapshot diffs when available, listedOn backfill when honest, or an explicit caller prior; returns current exact-match baseline, metadata-weighte...
arguments: addresses, address_metadata, asset, horizon_days, iterations, target
AurelianFlo
com.aurelianflo
compliance_queue_optimizeanswers
Optimize a compliance review queue using current OFAC exact matches, future exposure probabilities, exposure value, relationship tier, recency, and reviewer capacity. Use this when review_items and review_budget are k...
arguments: review_items, review_budget, objective, asset, horizon_days, iterations
AurelianFlo
com.aurelianflo
compliance_statusanswers
Company-level compliance posture rollup (pass rate, control compliance, mitigated counts, per-framework coverage). Suitable for a CI gate. Wraps the traceability company rollup.
arguments: scan_id, diagram_id
com.ayurak/aribot-mcp
com.ayurak
get_cloud_complianceanswers
Cloud security & compliance posture (Cloud Compliance): per connected cloud account, the latest CIS/NIST cloud-policy scan — compliance %, failing policies/records, status — plus a company rollup. Reads customers.Acco...
arguments: account_id
com.ayurak/aribot-mcp
com.ayurak
compliance_scananswers
Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.
arguments: scan_type, account_id, diagram_id, frameworks, severity_filter, simulation_mode
com.ayurak/aribot-mcp
com.ayurak
check_action_complianceanswers
Pre-flight regulatory check. Agent describes an intended action in natural language ("process EU resident biometric data", "transfer health records to a third-party AI vendor", "deploy autonomous trading model in Sing...
arguments: action, jurisdiction, limit
bidda-compliance
com.bidda
map_complianceanswers
Map scan findings to compliance frameworks: NIST 800-177, PCI DSS 4.0, SOC 2, CIS Controls. Shows pass/fail/partial status per control.
arguments: domain, force_refresh, format
com.blackveilsecurity/dns
com.blackveilsecurity
search_sanctionsanswers
Searches CitationSafe's database of real court sanctions/orders arising from AI-hallucinated legal citations, by court name, party/case name keyword, or free-text keyword. Read-only, public data — same dataset backing...
arguments: query, court
Citation Safe Verifier
com.citationsafe
kev_status_by_cveanswers
CISA Known Exploited Vulnerabilities status for one CVE: whether it is on the KEV catalog, the due date, required action and ransomware-campaign flag. $0.01 per call via x402 (USDC on Base); response includes a proven...
arguments: id, payment
Clink Forge
com.clinkforge
tech_stack_cve_auditanswers
Composite tech-stack + CVE audit (MCP-only, no REST endpoint). Detects technologies on the target domain, queries CVE database for known vulnerabilities per product, enriches top-10 CVE candidates with CISA KEV federa...
arguments: domain
ContrastAPI
com.contrastcyber
cve_leadinganswers
List CVEs indexed from MITRE/GHSA BEFORE NVD publication (early-warning, freshest data). By default each result is slim (no description, no cvss_breakdown, no affected_products list, no references) — pass include='ful...
arguments: limit, offset, include
ContrastAPI
com.contrastcyber
explore_compliance_frameworkanswers
Look up a compliance / regulatory framework by short id. Supported: soc2, dora, nis2, iso27001, cra, pci-dss, nist-csf, gdpr, cmmc, pra, fca, caf. Returns description, key articles/controls, applicability, and a canon...
arguments: framework_id
ContinueOps Public MCP
com.continueops
get_cveanswers
Full intelligence record for one CVE: per-scorer CVSS, EPSS, CISA KEV/ransomware/SSVC, four remote-detection modalities plus the Sigma log-detection layer, per-product fixed versions (fixed = first patched build; affe...
arguments: id
com.cve-security/cve-intelligence
com.cve-security
search_cvesanswers
Search the catalog. Free text (q) and/or structured filters: vendor (slug), cwe (CWE-nnn), year ("2024,2025"), sev ("critical,high"), kev (0|1), ransomware (0|1), detect (0|1 — detection content we track), fix (0|1 — ...
arguments: q, vendor, cwe, year, sev, kev
com.cve-security/cve-intelligence
com.cve-security
cve_lookupanswers
Look up a CVE by ID and get a compact summary: description, CVSS score & severity, vector, CWE weakness, publish date, and references. Source: NVD (NIST).
arguments: cve_id
security-intel-mcp
com.datakoot
security_fetch_cve_detailanswers
Fetch full detail for a specific CVE by ID. Read-only. No side effects. Idempotent. cve_id: CVE identifier in format CVE-YYYY-NNNNN e.g. CVE-2021-44228. Required. Returns description, CVSS base score, affected product...
arguments: cve_id
DataNexus MCP
com.datanexusmcp
security_fetch_cve_epssanswers
EPSS exploit probability score for a CVE — predicts likelihood of exploitation in the next 30 days. cve_id: CVE identifier e.g. "CVE-2021-44228". Returns: epss (float 0.0–1.0) and percentile (float 0.0–100.0). Thres...
arguments: cve_id
DataNexus MCP
com.datanexusmcp
compliance_fetch_npi_provideranswers
Fetch NPI registration details for a US healthcare provider by NPI number. Read-only. No side effects. Idempotent. US only. npi_number: 10-digit NPI number e.g. 1003000126. Required. Do not include dashes or spaces. R...
arguments: npi_number
DataNexus MCP
com.datanexusmcp
Showing 60 of 312 verified tools. Search the whole set, including full input schemas, at https://neuronto.com/tools?q=..., or connect an agent to https://neuronto.com/mcp and call find_tool. No key, no signup.

"Answers" means the endpoint responded to a handshake when last probed, and "auth required" means it demanded credentials. Both are statements about reachability, never about trustworthiness.

Other capabilities

Analytics and monitoring
3,515 verified tools
Files and storage
3,507 verified tools
Maps, location and weather
3,367 verified tools
Payments and billing
2,436 verified tools
GitHub and version control
2,373 verified tools
Calendar and scheduling
2,213 verified tools
Crypto and blockchain
1,969 verified tools
Images, audio and video
1,875 verified tools
HR and recruiting
1,432 verified tools