22 utility tools (x402 USDC on Base): currency, PDF, image, GDPR. Free health.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://swiss.api.ainode.tech/mcp23 tools · 566mshealthHealth check. Returns server status and optional echo.Health check. Returns server status and optional echo.
| Parameter | Type | Description |
|---|---|---|
| echo | string | Optional string to echo back |
json_to_csvConvert JSON array of objects to RFC 4180 CSV.Convert JSON array of objects to RFC 4180 CSV.
| Parameter | Type | Description |
|---|---|---|
| input* | string | JSON array string |
csv_to_jsonConvert CSV string to JSON array of objects.Convert CSV string to JSON array of objects.
| Parameter | Type | Description |
|---|---|---|
| input* | string | CSV string |
encode_base64Encode a UTF-8 string to Base64.Encode a UTF-8 string to Base64.
| Parameter | Type | Description |
|---|---|---|
| input* | string | UTF-8 string to encode |
decode_base64Decode a Base64 string to UTF-8.Decode a Base64 string to UTF-8.
| Parameter | Type | Description |
|---|---|---|
| input* | string | Base64 string to decode |
generate_hashGenerate MD5, SHA-256, or SHA-512 hex digest.Generate MD5, SHA-256, or SHA-512 hex digest.
| Parameter | Type | Description |
|---|---|---|
| input* | string | String to hash |
| algorithm* | string | Hash algorithm: md5, sha256, or sha512 |
generate_uuidGenerate one or more UUID v4 values.Generate one or more UUID v4 values.
| Parameter | Type | Description |
|---|---|---|
| count | number | Number of UUIDs to generate (1-100, default 1) |
html_to_textStrip HTML tags and decode entities to plain text.Strip HTML tags and decode entities to plain text.
| Parameter | Type | Description |
|---|---|---|
| input* | string | HTML string to convert |
markdown_to_htmlConvert Markdown to HTML.Convert Markdown to HTML.
| Parameter | Type | Description |
|---|---|---|
| input* | string | Markdown string to convert |
extract_url_metadataExtract Open Graph metadata from a URL.Extract Open Graph metadata from a URL.
| Parameter | Type | Description |
|---|---|---|
| url* | string | URL to extract metadata from |
convert_timezoneConvert a datetime between IANA timezones.Convert a datetime between IANA timezones.
| Parameter | Type | Description |
|---|---|---|
| datetime* | string | Datetime in ISO format (YYYY-MM-DDTHH:mm:ss) |
| from_timezone* | string | Source IANA timezone (e.g. America/New_York) |
| to_timezone* | string | Target IANA timezone (e.g. Europe/Lisbon) |
parse_cronParse a cron expression and return next run times.Parse a cron expression and return next run times.
| Parameter | Type | Description |
|---|---|---|
| expression* | string | Cron expression (e.g. '0 9 * * 1-5') |
| count | number | Number of next runs to return (1-20, default 5) |
test_regexTest a regex pattern against an input string.Test a regex pattern against an input string.
| Parameter | Type | Description |
|---|---|---|
| pattern* | string | Regular expression pattern |
| input* | string | Input string to test against |
| flags | string | Regex flags (g, i, m, s, u, y) |
convert_currencyConvert an amount between currencies using cached ECB exchange rates.Convert an amount between currencies using cached ECB exchange rates.
| Parameter | Type | Description |
|---|---|---|
| amount* | number | Amount to convert |
| from* | string | Source currency code (ISO 4217) |
| to* | string | Target currency code (ISO 4217) |
extract_pdf_textExtract text content from a base64-encoded PDF document.Extract text content from a base64-encoded PDF document.
| Parameter | Type | Description |
|---|---|---|
| pdf* | string | Base64-encoded PDF document |
resize_imageResize and compress a base64-encoded image.Resize and compress a base64-encoded image.
| Parameter | Type | Description |
|---|---|---|
| image* | string | Base64-encoded image data |
| width* | integer | Target width in pixels |
| height* | integer | Target height in pixels |
| format | string | Output format |
| quality | integer | JPEG quality (1-100) |
validate_nifValidate Portuguese NIF/NIPC tax identification number (mod-11 check digit).Validate Portuguese NIF/NIPC tax identification number (mod-11 check digit).
| Parameter | Type | Description |
|---|---|---|
| nif* | string | Portuguese NIF or NIPC (9 digits) |
validate_ibanValidate IBAN (ISO 13616 mod-97) with SEPA BIC lookup for Portuguese banks.Validate IBAN (ISO 13616 mod-97) with SEPA BIC lookup for Portuguese banks.
| Parameter | Type | Description |
|---|---|---|
| iban* | string | IBAN string (with or without spaces) |
verify_eu_vatVerify EU VAT number via VIES (European Commission free API).Verify EU VAT number via VIES (European Commission free API).
| Parameter | Type | Description |
|---|---|---|
| country_code* | string | ISO 3166-1 alpha-2 country code (e.g. PT, DE, FR) |
| vat_number* | string | VAT number without country prefix |
classify_gdprDetect GDPR PII categories in text (email, phone, IP, name, location). Returns categories only, never actual PII values.Detect GDPR PII categories in text (email, phone, IP, name, location). Returns categories only, never actual PII values.
| Parameter | Type | Description |
|---|---|---|
| text* | string | Text to scan for PII categories |
generate_cspGenerate Content-Security-Policy header from structured directives input.Generate Content-Security-Policy header from structured directives input.
| Parameter | Type | Description |
|---|---|---|
| directives | object | CSP directives map, e.g. { 'script-src': ['self', 'nonce-abc123'] } |
| report_uri | string | Report URI for CSP violations |
| report_only | boolean | Use Content-Security-Policy-Report-Only header |
validate_corsValidate CORS policy against security best practices. Reports issues by severity.Validate CORS policy against security best practices. Reports issues by severity.
| Parameter | Type | Description |
|---|---|---|
| allow_origin* | — | Access-Control-Allow-Origin value(s) |
| allow_methods | array | Allowed HTTP methods |
| allow_headers | array | Allowed request headers |
| allow_credentials | boolean | Access-Control-Allow-Credentials |
| max_age | number | Access-Control-Max-Age in seconds |
| expose_headers | array | Access-Control-Expose-Headers |
detect_secretsDetect hardcoded secrets, API keys, and credentials in text using pattern matching and entropy analysis.Detect hardcoded secrets, API keys, and credentials in text using pattern matching and entropy analysis.
| Parameter | Type | Description |
|---|---|---|
| text* | string | Text, code, or configuration to scan for secrets |
23 of 23 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
22 utility tools (x402 USDC on Base): currency, PDF, image, GDPR. Free health.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.