DNS, RDAP, LEI, URL inspection, extraction, sitemaps, robots.txt, text, VAT and QR. x402 USDC.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://toolvend.dev/mcp11 tools · 287msdnsDNS lookup over DoH. Common record types (A, AAAA, MX, TXT, NS, CAA, ...) as clean JSON. Paid per call: $0.005 in USDC via x402.DNS lookup over DoH. Common record types (A, AAAA, MX, TXT, NS, CAA, ...) as clean JSON. Paid per call: $0.005 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| name* | string | DNS name to resolve |
| type | string | Record type, default A |
email-authEmail authentication posture for a domain: DMARC + SPF records fetched, parsed, scored 0-100, with findings and fix recommendations. Paid per call: $0.01 in USDC via x402.Email authentication posture for a domain: DMARC + SPF records fetched, parsed, scored 0-100, with findings and fix recommendations. Paid per call: $0.01 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| domain* | string | Domain to analyse (path parameter) |
email-auth-analyzeEmail diagnosis bundle: exact-domain DMARC, SPF sending-IP evaluation, up to five supplied DKIM selectors and structured receiver evidence. Prioritized fixes, timestamped DNS sources and missing checks. No signature verification, inherited-policy discovery or inbox claims. Paid per call: $0.10 in U…Email diagnosis bundle: exact-domain DMARC, SPF sending-IP evaluation, up to five supplied DKIM selectors and structured receiver evidence. Prioritized fixes, timestamped DNS sources and missing checks. No signature verification, inherited-policy discovery or inbox claims. Paid per call: $0.10 in U…
| Parameter | Type | Description |
|---|---|---|
| domain* | string | Author (visible From) domain; ASCII/punycode |
| sendingIp | string | Sending IPv4 or IPv6 address; never contacted |
| envelopeFromDomain | string | MAIL FROM domain for SPF; required to evaluate sendingIp |
| dkimSelectors | array | — |
| message | object | Structured results copied from a receiver you trust; treated as unverified caller evidence. No raw headers or message body. |
rdapDomain registration data (modern WHOIS) via RDAP: registrar, created/expiry dates, status, nameservers, DNSSEC. Paid per call: $0.005 in USDC via x402.Domain registration data (modern WHOIS) via RDAP: registrar, created/expiry dates, status, nameservers, DNSSEC. Paid per call: $0.005 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| domain* | string | Domain to look up (path parameter) |
leiGlobal legal-entity/KYB lookup by LEI: official identity, jurisdiction, addresses, registration and renewal standing, risk flags, and GLEIF data freshness. Paid per call: $0.008 in USDC via x402.Global legal-entity/KYB lookup by LEI: official identity, jurisdiction, addresses, registration and renewal standing, risk flags, and GLEIF data freshness. Paid per call: $0.008 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| lei* | string | 20-character Legal Entity Identifier (path parameter); checksum is verified before payment |
sitemapFetch and parse sitemap XML or gzip into JSON. For an index, follow the first N children with ?follow=N. Caps merged output at 500 URLs. Paid per call: $0.005 in USDC via x402.Fetch and parse sitemap XML or gzip into JSON. For an index, follow the first N children with ?follow=N. Caps merged output at 500 URLs. Paid per call: $0.005 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| url* | string | Public HTTP(S) sitemap URL, including .xml.gz, or a site origin to try /sitemap.xml |
| follow | integer | For a sitemap index, fetch and merge the first N children (default 0) |
robotsFetch and parse robots.txt (+ llms.txt if present) into structured JSON, including which AI crawlers are blocked. Paid per call: $0.005 in USDC via x402.Fetch and parse robots.txt (+ llms.txt if present) into structured JSON, including which AI crawlers are blocked. Paid per call: $0.005 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| url* | string | Public HTTP(S) site origin or URL |
extractFetch a web page and return structured content: title, meta/OpenGraph, canonical, headings, links, readable text (boilerplate stripped). Add ?render=true for JavaScript-rendered pages ($0.03). Paid per call: $0.01 ($0.03 Execute JavaScript with Cloudflare Browser Run before extracting content.) in…Fetch a web page and return structured content: title, meta/OpenGraph, canonical, headings, links, readable text (boilerplate stripped). Add ?render=true for JavaScript-rendered pages ($0.03). Paid per call: $0.01 ($0.03 Execute JavaScript with Cloudflare Browser Run before extracting content.) in…
| Parameter | Type | Description |
|---|---|---|
| url* | string | Public HTTP(S) page URL to extract |
| includeLinks | boolean | Include outbound links (default true) |
| maxTextChars | number | Cap on extracted text length, default 20000 |
| render | string | Premium tier, charged more than the base price. true → $0.03: Execute JavaScript with Cloudflare Browser Run before extracting content. |
text-cleanClean text: strip HTML, normalise unicode/whitespace, dedupe lines. Returns cleaned text plus stats. Paid per call: $0.003 in USDC via x402.Clean text: strip HTML, normalise unicode/whitespace, dedupe lines. Returns cleaned text plus stats. Paid per call: $0.003 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| text* | string | Input text (max 500,000 characters) |
| options | object | — |
vatVAT calculator for EU-27 + UK: net→gross or gross→net at standard or reduced rate. Includes rates table snapshot date. Paid per call: $0.002 in USDC via x402.VAT calculator for EU-27 + UK: net→gross or gross→net at standard or reduced rate. Includes rates table snapshot date. Paid per call: $0.002 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| amount* | number | — |
| country* | string | ISO 3166-1 alpha-2, e.g. DE, FR, GB |
| direction | string | default net_to_gross |
| rate | string | default standard |
qrQR code generator. Returns a crisp SVG for text/URL payloads up to 2,048 UTF-8 bytes that fit the selected error-correction level. Paid per call: $0.003 in USDC via x402.QR code generator. Returns a crisp SVG for text/URL payloads up to 2,048 UTF-8 bytes that fit the selected error-correction level. Paid per call: $0.003 in USDC via x402.
| Parameter | Type | Description |
|---|---|---|
| data* | string | Payload to encode (max 2,048 UTF-8 bytes; QR capacity is lower at Q/H error correction) |
| size | number | SVG width/height in px, default 256 |
| ecl | string | Error correction, default M |
11 of 11 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
DNS, RDAP, LEI, URL inspection, extraction, sitemaps, robots.txt, text, VAT and QR. x402 USDC.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.