DNS, WHOIS/RDAP, DMARC/SPF, LEI, sitemap, web extract, VAT, QR. Paid per call in USDC, no signup.
Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.
La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.
Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.
https://toolvend.dev/mcp11 herramientas · 287 msdnsDNS lookup over DoH. Common record types (A, AAAA, MX, TXT, NS, CAA, ...) as clean JSON. Paid per call: $0.005 in USDC via x402.DNS lookup over DoH. Common record types (A, AAAA, MX, TXT, NS, CAA, ...) as clean JSON. Paid per call: $0.005 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| name* | string | DNS name to resolve |
| type | string | Record type, default A |
email-authEmail authentication posture for a domain: DMARC + SPF records fetched, parsed, scored 0-100, with findings and fix recommendations. Paid per call: $0.01 in USDC via x402.Email authentication posture for a domain: DMARC + SPF records fetched, parsed, scored 0-100, with findings and fix recommendations. Paid per call: $0.01 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| domain* | string | Domain to analyse (path parameter) |
email-auth-analyzeEmail diagnosis bundle: exact-domain DMARC, SPF sending-IP evaluation, up to five supplied DKIM selectors and structured receiver evidence. Prioritized fixes, timestamped DNS sources and missing checks. No signature verification, inherited-policy discovery or inbox claims. Paid per call: $0.10 in U…Email diagnosis bundle: exact-domain DMARC, SPF sending-IP evaluation, up to five supplied DKIM selectors and structured receiver evidence. Prioritized fixes, timestamped DNS sources and missing checks. No signature verification, inherited-policy discovery or inbox claims. Paid per call: $0.10 in U…
| Parámetro | Tipo | Descripción |
|---|---|---|
| domain* | string | Author (visible From) domain; ASCII/punycode |
| sendingIp | string | Sending IPv4 or IPv6 address; never contacted |
| envelopeFromDomain | string | MAIL FROM domain for SPF; required to evaluate sendingIp |
| dkimSelectors | array | — |
| message | object | Structured results copied from a receiver you trust; treated as unverified caller evidence. No raw headers or message body. |
rdapDomain registration data (modern WHOIS) via RDAP: registrar, created/expiry dates, status, nameservers, DNSSEC. Paid per call: $0.005 in USDC via x402.Domain registration data (modern WHOIS) via RDAP: registrar, created/expiry dates, status, nameservers, DNSSEC. Paid per call: $0.005 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| domain* | string | Domain to look up (path parameter) |
leiGlobal legal-entity/KYB lookup by LEI: official identity, jurisdiction, addresses, registration and renewal standing, risk flags, and GLEIF data freshness. Paid per call: $0.008 in USDC via x402.Global legal-entity/KYB lookup by LEI: official identity, jurisdiction, addresses, registration and renewal standing, risk flags, and GLEIF data freshness. Paid per call: $0.008 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| lei* | string | 20-character Legal Entity Identifier (path parameter); checksum is verified before payment |
sitemapFetch and parse sitemap XML or gzip into JSON. For an index, follow the first N children with ?follow=N. Caps merged output at 500 URLs. Paid per call: $0.005 in USDC via x402.Fetch and parse sitemap XML or gzip into JSON. For an index, follow the first N children with ?follow=N. Caps merged output at 500 URLs. Paid per call: $0.005 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| url* | string | Public HTTP(S) sitemap URL, including .xml.gz, or a site origin to try /sitemap.xml |
| follow | integer | For a sitemap index, fetch and merge the first N children (default 0) |
robotsFetch and parse robots.txt (+ llms.txt if present) into structured JSON, including which AI crawlers are blocked. Paid per call: $0.005 in USDC via x402.Fetch and parse robots.txt (+ llms.txt if present) into structured JSON, including which AI crawlers are blocked. Paid per call: $0.005 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| url* | string | Public HTTP(S) site origin or URL |
extractFetch a web page and return structured content: title, meta/OpenGraph, canonical, headings, links, readable text (boilerplate stripped). Add ?render=true for JavaScript-rendered pages ($0.03). Paid per call: $0.01 ($0.03 Execute JavaScript with Cloudflare Browser Run before extracting content.) in…Fetch a web page and return structured content: title, meta/OpenGraph, canonical, headings, links, readable text (boilerplate stripped). Add ?render=true for JavaScript-rendered pages ($0.03). Paid per call: $0.01 ($0.03 Execute JavaScript with Cloudflare Browser Run before extracting content.) in…
| Parámetro | Tipo | Descripción |
|---|---|---|
| url* | string | Public HTTP(S) page URL to extract |
| includeLinks | boolean | Include outbound links (default true) |
| maxTextChars | number | Cap on extracted text length, default 20000 |
| render | string | Premium tier, charged more than the base price. true → $0.03: Execute JavaScript with Cloudflare Browser Run before extracting content. |
text-cleanClean text: strip HTML, normalise unicode/whitespace, dedupe lines. Returns cleaned text plus stats. Paid per call: $0.003 in USDC via x402.Clean text: strip HTML, normalise unicode/whitespace, dedupe lines. Returns cleaned text plus stats. Paid per call: $0.003 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| text* | string | Input text (max 500,000 characters) |
| options | object | — |
vatVAT calculator for EU-27 + UK: net→gross or gross→net at standard or reduced rate. Includes rates table snapshot date. Paid per call: $0.002 in USDC via x402.VAT calculator for EU-27 + UK: net→gross or gross→net at standard or reduced rate. Includes rates table snapshot date. Paid per call: $0.002 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| amount* | number | — |
| country* | string | ISO 3166-1 alpha-2, e.g. DE, FR, GB |
| direction | string | default net_to_gross |
| rate | string | default standard |
qrQR code generator. Returns a crisp SVG for text/URL payloads up to 2,048 UTF-8 bytes that fit the selected error-correction level. Paid per call: $0.003 in USDC via x402.QR code generator. Returns a crisp SVG for text/URL payloads up to 2,048 UTF-8 bytes that fit the selected error-correction level. Paid per call: $0.003 in USDC via x402.
| Parámetro | Tipo | Descripción |
|---|---|---|
| data* | string | Payload to encode (max 2,048 UTF-8 bytes; QR capacity is lower at Q/H error correction) |
| size | number | SVG width/height in px, default 256 |
| ecl | string | Error correction, default M |
11 de 11 herramientas publicaron una descripción.
Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.
DNS, WHOIS/RDAP, DMARC/SPF, LEI, sitemap, web extract, VAT, QR. Paid per call in USDC, no signup.
Los nombres enlazados abren el índice de Forge con todas las entradas que se observó que exponen esa herramienta. Ver todas las herramientas indexadas.
Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.