MCP serverio.github.presendapp/presend-mcp
Before an AI agent installs an npm/PyPI package: typosquat, vulnerability and existence checks.
Overview
Score?
UNRATED 0.746
of what a free look can see, on 21 looks
Looks
23
last 4 hr ago
Tools
40
changed 1 day ago
More info
URL
presend.pages.dev/mcp
streamable-http
Says it is
presend-mcp 3.1.2
protocol 2025-06-18
In the record since
21 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.746 · highest on record 0.8561
Toolsfrom sha256:ba3bcebc07…d3f872 · +0 −0 1 day ago
| Tool | Schema |
|---|---|
| address_risk Screens a crypto address against every OFAC SDN digital currency address list. EVM (0x...) and Bitcoin (bc1..., 1..., 3...) addresses are fully covered (sanctioned true or false, w |
input · no output |
| ai_crawler_check Fetches a domain's robots.txt and reports which known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot and others) are allowed or blocked, including wildcard r |
input · no output |
| base64 Encodes text to Base64 or decodes a Base64 string back to text (action = encode or decode). |
input · no output |
| color Converts a color between hex, RGB and HSL. Provide exactly one of hex, rgb or hsl. |
input · no output |
| csv_json Converts CSV text to JSON or JSON to CSV (direction: csv-to-json or json-to-csv), for data passed inline. CSV must be comma-separated, with a header row and at least one data row; |
input · no output |
| cve_lookup Looks up a vulnerability by identifier (CVE, GHSA or other OSV ID) on OSV.dev: summary, CVSS severity, affected packages and versions, references. Use when you already have an ID; |
input · no output |
| dns_lookup Returns DNS records for a domain via Cloudflare DNS-over-HTTPS: A, AAAA, CNAME, MX, TXT and NS in one call, or a single record type with 'type'. For registration data use whois_loo |
input · no output |
| email_disposable Checks only whether an email address uses a known disposable/temporary email domain. For syntax, MX, disposable and role-account checks in one call, use email_verify. |
input · no output |
| email_security Audits a domain's email anti-spoofing setup: SPF strength, DMARC policy and a best-effort DKIM lookup on common selectors. A missing DKIM match does not prove DKIM is absent. Check |
input · no output |
| email_validate Lightweight email check: syntax plus confirmation that the domain has an MX record. Does not detect disposable or role addresses; use email_verify for the combined check. |
input · no output |
| email_verify Most complete email check in one call: syntax, MX record, disposable-domain detection and role/generic account detection (e.g. info@, admin@). Prefer it over email_validate and ema |
input · no output |
| favicon Returns the favicon URL a website declares: fetches the homepage and takes the first <link rel='icon'> (or 'shortcut icon') href, resolved to an absolute URL, which may be a data: |
input · no output |
| iban_validate Validates an IBAN offline: ISO 7064 mod-97 checksum and country-specific length. Confirms the number is well-formed, not that the account exists. |
input · no output |
| ip_reputation Checks an IPv4 or IPv6 address against a curated list of netblocks known to be hijacked or run by spam/cyber-crime operations (IPv4-mapped IPv6 uses the IPv4 list). A narrow list-b |
input · no output |
| jwt_decode Decodes a JWT's header and payload WITHOUT verifying its signature, so its claims must not be trusted on this basis alone. To check authenticity, use jwt_verify. |
input · no output |
| jwt_verify Cryptographically verifies a JWT signature (HS256/384/512, RS/PS256/384/512, ES256/384/512) and checks exp/nbf claims. Provide a secret for HS*, or a JWK or JWKS URL for RS/PS/ES. |
input · no output |
| link_metadata Fetches a web page and extracts its title, description, canonical URL, Open Graph and Twitter Card tags and favicon (the data behind link previews). Follows redirects and returns f |
input · no output |
| maintainer_change_check Publisher-change analysis is npm only. Also reports whether the package exists (found) and its age (first_published, package_age_days, new_package if first published less than 30 d |
input · no output |
| password Generates a random password, with options for length, symbols, uppercase, numbers and excluding ambiguous characters. To evaluate an existing password, use password_check. |
input · no output |
| password_breach Checks whether a password appears in known data breaches (Have I Been Pwned) and how many times, using k-anonymity towards HIBP. Breach check only; password_check adds strength sco |
input · no output |
| password_check Scores a password's strength (length, character variety, entropy as an upper bound, repeated patterns; passphrases are estimated per word) and, with check_breach=true, also looks i |
input · no output |
| phone_verify Validates and formats a phone number: validity, country, line type, E.164, international and national formats. Numbers without a leading + require 'country', since the end user's c |
input · no output |
| redirect_trace Follows a URL's full redirect chain (up to 15 hops) and returns every hop with its status code, plus whether the chain crossed domains. Use it to see where a short or tracking link |
input · no output |
| repo_health_check Maintenance signals for a GitHub repository given as owner/name: stars, forks, open issues, license, archived and fork flags, creation date and age, days since last push, topics. U |
input · no output |
| rpc_check Read-only audit of a public CometBFT (Cosmos SDK) RPC endpoint: node status, health, peers, and whether unsafe admin methods (dial_seeds, dial_peers, unsafe_flush_mempool) are publ |
input · no output |
| security_headers Audits the HTTP security headers of one URL (CSP, HSTS, X-Frame-Options, Permissions-Policy, cross-origin policies and others) and returns per-header findings with fix advice, a sc |
input · no output |
| security_scan Combined website check in one call: security headers, URL reputation and passive subdomain discovery, run in parallel, with an overall score and verdict. Use the individual tools w |
input · no output |
| subdomains Passive subdomain discovery from Certificate Transparency logs (crt.sh): finds hostnames that appeared in public TLS certificates, not every DNS record. crt.sh is occasionally slow |
input · no output |
| supply_chain_check Call this before installing or adding a package (npm install, pip install, a new entry in a manifest), especially one whose name you recalled or that a model suggested. One-call ri |
input · no output |
| text_similarity Near-duplicate detection with a 64-bit SimHash over word shingles: send 1 text to get its hash, or 2 texts to compare them. Detects paraphrased or lightly edited copies; unrelated |
input · no output |
| timestamp Returns the current time, or converts between a Unix timestamp (seconds) and an ISO date. Provide unix or date, or neither for the current time. |
input · no output |
| tx_decode Decodes a raw signed Cosmos SDK transaction (base64 TxRaw bytes, as found in a CometBFT block's data.txs) into JSON: messages, fee, gas, signers and signatures. Bank, staking, gov |
input · no output |
| typosquat_check Call before installing a package whose name you typed or recalled. Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-d |
input · no output |
| url_clean Removes 60+ known tracking parameters (utm_*, fbclid, gclid and similar) from a URL and returns the clean URL. Does not follow redirects; for that, use redirect_trace. |
input · no output |
| url_reputation Checks a URL against URLhaus (abuse.ch), a public database of known malware distribution URLs. A clean result only means the URL is not listed, not that it is safe. |
input · no output |
| user_agent Parses a User-Agent string into browser and version, operating system and version, device type, and whether it looks like a bot. |
input · no output |
| uuid Generates 1 to 100 random UUID v4 values. |
input · no output |
| vat_validate Checks an EU VAT number in real time against the European Commission's VIES service and, when valid, returns the registered company name and address. VIES is occasionally unavailab |
input · no output |
| vulnerability_check Checks a package (optionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. Use cve_lookup when you |
input · no output |
| whois_lookup Domain registration data via RDAP (the modern WHOIS): registrar, creation and expiration dates, domain age in days, nameservers. For DNS records, use dns_lookup. |
input · no output |
Verify it yourself
npx teppi-check https://presend.pages.dev/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M2CN5JJQGJSKV7JMRA5TC46D