Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,552Letters: 14Defects: 1,323counted 3 min ago
teppi

MCP serverio.github.astafford8488/agentaegis

Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
UNRATEDActivestreamable-httpagentaegis-mcp-production.up.railway.app

Overview

Score?
UNRATED 0.787
of what a free look can see, on 30 looks
Looks
36
last 5 hr ago
Tools
28

More info

URL
agentaegis-mcp-production.up.railway.app/mcp
streamable-http
Says it is
agentaegis 0.2.0
protocol 2025-06-18
In the record since
32 days ago

Among servers18,413 with a card

0median 0.606 · this server 0.787 · highest on record 0.8561

Toolsfrom sha256:afdb3b56b4…486fd1

The tools this server lists, read out of the definition it returned
ToolSchema
access_review
Review user and role assignments you supply against least-privilege, flagging excessive, stale or orphaned access. Analyzes data the caller provides; it does not connect to an iden
input · no output
account_balance
Returns the calling API key's prepaid balance, monthly limit, current month usage, and a breakdown of how many of each tool the customer can still afford. Free to call.
input · no output
agent_history
Lists your recent scans (scan_id, tool, target, status, time) so you can retrieve or chain from a prior result. Optional limit/tool/target/since filters. Free to call.
input · no output
agent_scan_get
Retrieves one of your prior scans by scan_id, including the stored full output, so you can build on earlier results without re-paying. Free to call.
input · no output
agent_whoami
Returns your persistent AgentAegis agent identity (agent_id), how you're identified (API key / wallet / anonymous session), and lifetime call count + spend. Free to call.
input · no output
audit_report_generate
Synthesize findings into an audit-ready compliance report. Use at the END of an engagement, once gaps are closed. If the user only wants to know where they currently stand, run com
input · no output
compliance_framework_check
Assess an organization's security posture against a compliance framework (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST CSF) and report per-control status. Use this FIRST when asked wheth
input · no output
control_gap_analysis
Turn unmet compliance controls into a prioritized remediation roadmap with effort estimates. Use after compliance_framework_check to answer 'what do we fix first'. Costs $2 per cal
input · no output
credential_check
Check whether an email address or domain appears in known credential-breach corpora (Have I Been Pwned), with the breaches and data classes exposed. Use when assessing account-take
input · no output
cve_lookup
Look up one CVE by identifier: CVSS score and vector, affected products, patch availability and references. Use when a specific CVE ID is already known. Costs $1 per call.
input · no output
dependency_audit
Audit a dependency manifest or https git repo for known-vulnerable packages (trivy): npm, pip, Go, Ruby, Java, Cargo. The cheapest, highest-signal first step when assessing an unfa
input · no output
dns_security_check
Check a domain's DNS security records — SPF, DKIM, DMARC, DNSSEC — and grade the configuration. Passive. Covers the records themselves; for full spoofability posture use email_secu
input · no output
email_security_audit
Full email-security posture for a domain: whether mail from it can be spoofed, with DMARC/SPF/DKIM alignment and policy strength. A superset of dns_security_check for the email que
input · no output
evidence_collect
Build an evidence-collection plan for specific compliance controls: what artifact each control needs, where it comes from, and what makes it sufficient. Use when preparing for a re
input · no output
help
Returns AgentAegis FAQ — authentication, balance/billing, tool catalog, async jobs, error codes, x402, rate limits, security. Optional topic filter. Free to call.
input · no output
incident_triage
Classify a security incident and produce severity, likely category, containment steps and a response plan. Use when something has already happened. If all you have is a suspicious
input · no output
mfa_audit
Assess MFA coverage and factor strength across a user or configuration set you supply, flagging unenrolled accounts and weak factors such as SMS. Analyzes data the caller provides;
input · no output
policy_generate
Generate a tailored written security policy (incident response, access control, encryption, vendor management, remote work, and similar). Use when a control gap specifically calls
input · no output
sast_scan
Static analysis of source code or an https git repo for security flaws (Semgrep): injection, unsafe deserialization, path traversal, crypto misuse. Python, JS/TS, Java, Go, Ruby, P
input · no output
scan_mcp_plugin
Scan an MCP server (git repo or code) for supply-chain risk BEFORE trusting it — exfiltration (secrets/env to the network), prompt-injection sinks, dangerous capabilities, npm inst
input · no output
scan_skill
Scan an agent SKILL (git repo or SKILL.md) for supply-chain risk BEFORE trusting it — prompt-injection / hidden-unicode in the instructions (hard block), over-broad allowed-tools g
input · no output
secret_scan
Detect hardcoded credentials, API keys and tokens in source code or an https git repo (trufflehog), verified against the issuing provider where supported. Use when the question is
input · no output
ssl_tls_audit
Audit a domain's TLS configuration (sslyze): certificate validity and expiry, protocol versions, cipher suites, and known TLS weaknesses. Passive — safe against any host. Costs $1
input · no output
threat_intel_lookup
Reputation and indicator lookup for an IP or domain across AbuseIPDB, AlienVault OTX and abuse.ch. The cheapest way to check whether an indicator is known-bad. Interpret with care:
input · no output
vet_endpoint
Composite trust verdict (PROCEED/CAUTION/BLOCK) for an endpoint an agent is about to call or pay — combines TLS/cert health, DNS hygiene, threat-intel reputation, and domain age in
input · no output
vuln_prioritize
Rank vulnerabilities you already have by exploitability and business impact, and group them into remediation actions. Analyzes findings you supply; it discovers nothing on its own.
input · no output
vuln_scan_network
Discover open ports, running services and known vulnerabilities on an IP or domain (nmap). SENDS REAL TRAFFIC to the target and may trigger intrusion detection — only run against h
input · no output
vuln_scan_web_app
Scan a web application for OWASP Top 10 issues and known CVEs (Nuclei). SENDS REAL TRAFFIC to the target — authorized targets only, confirm before calling. Pass async:true to get a
input · no output
Verify it yourselfnpx teppi-check https://agentaegis-mcp-production.up.railway.app/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2E8K704ED8T0NZSWSFTZ