Official MCP RegistryListed
Presend MCP Server
Before an AI agent installs an npm/PyPI package: typosquat, vulnerability and existence checks.
First seen 2 Oct 2026. Evidence as of 2 Oct 2026.
40
Tools
From an anonymous probe
1
Source listings
Each with its own history
1
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| address_risk | Screens a crypto address against every OFAC SDN digital currency address list. EVM (0x...) and Bitcoin (bc1..., 1..., 3...) addresses are fully covered (sanctioned true or false, with the matching lists). Addresses of other chains are flagged when listed; Cosmos SDK bech32 addresses return sanctioned: null when not listed, as OFAC publishes none. A sanctions signal only, not a full risk score. | Read-only |
| ai_crawler_check | Fetches a domain's robots.txt and reports which known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot and others) are allowed or blocked, including wildcard rules. Reflects robots.txt only, not server-side blocking. | Read-only |
| base64 | Encodes text to Base64 or decodes a Base64 string back to text (action = encode or decode). | Read-only |
| color | Converts a color between hex, RGB and HSL. Provide exactly one of hex, rgb or hsl. | Read-only |
| csv_json | Converts CSV text to JSON or JSON to CSV (direction: csv-to-json or json-to-csv), for data passed inline. CSV must be comma-separated, with a header row and at least one data row; double-quoted fields may contain commas. Semicolon- or tab-separated input is not detected and comes back as a single column. JSON input must be an array of objects: the union of their keys becomes the CSV header and missing values are left empty. Returns result (the converted text), rows and cols. Max 500,000 characters. | Read-only |
| cve_lookup | Looks up a vulnerability by identifier (CVE, GHSA or other OSV ID) on OSV.dev: summary, CVSS severity, affected packages and versions, references. Use when you already have an ID; use vulnerability_check when you have a package name instead. | Read-only |
| dns_lookup | Returns DNS records for a domain via Cloudflare DNS-over-HTTPS: A, AAAA, CNAME, MX, TXT and NS in one call, or a single record type with 'type'. For registration data use whois_lookup; for SPF/DMARC/DKIM analysis use email_security. | Read-only |
| email_disposable | Checks only whether an email address uses a known disposable/temporary email domain. For syntax, MX, disposable and role-account checks in one call, use email_verify. | Read-only |
| email_security | Audits a domain's email anti-spoofing setup: SPF strength, DMARC policy and a best-effort DKIM lookup on common selectors. A missing DKIM match does not prove DKIM is absent. Checks a domain, not a single address. | Read-only |
| email_validate | Lightweight email check: syntax plus confirmation that the domain has an MX record. Does not detect disposable or role addresses; use email_verify for the combined check. | Read-only |
| email_verify | Most complete email check in one call: syntax, MX record, disposable-domain detection and role/generic account detection (e.g. info@, admin@). Prefer it over email_validate and email_disposable unless you need a single signal. Does not probe the mailbox. valid is null (not false) when the MX lookup could not be completed; retry later instead of treating the address as invalid. | Read-only |
| favicon | Returns the favicon URL a website declares: fetches the homepage and takes the first <link rel='icon'> (or 'shortcut icon') href, resolved to an absolute URL, which may be a data: URI when the page inlines its icon (source: declared). If no icon is declared, or the homepage cannot be fetched, returns the conventional https://<domain>/favicon.ico with source: default and a note, without checking that it exists. Use it to display a site icon; it does not download or validate the image. | Read-only |
| iban_validate | Validates an IBAN offline: ISO 7064 mod-97 checksum and country-specific length. Confirms the number is well-formed, not that the account exists. | Read-only |
| ip_reputation | Checks an IPv4 or IPv6 address against a curated list of netblocks known to be hijacked or run by spam/cyber-crime operations (IPv4-mapped IPv6 uses the IPv4 list). A narrow list-based signal: a clean result is not a safety guarantee. Includes list date and attribution. | Read-only |
| jwt_decode | Decodes a JWT's header and payload WITHOUT verifying its signature, so its claims must not be trusted on this basis alone. To check authenticity, use jwt_verify. | Read-only |
| jwt_verify | Cryptographically verifies a JWT signature (HS256/384/512, RS/PS256/384/512, ES256/384/512) and checks exp/nbf claims. Provide a secret for HS*, or a JWK or JWKS URL for RS/PS/ES. Use instead of jwt_decode whenever authenticity matters. | Read-only |
| link_metadata | Fetches a web page and extracts its title, description, canonical URL, Open Graph and Twitter Card tags and favicon (the data behind link previews). Follows redirects and returns final_url; favicon_source says whether the icon is declared by the page or only the /favicon.ico guess. To see each redirect hop, use redirect_trace. | Read-only |
| maintainer_change_check | npm only. Flags a previously unseen human publisher taking over a package after 180+ days of inactivity, within the last 365 days (the event-stream attack pattern). npm trusted publishing (verified OIDC identity, not just a bot-like account name), pre-release, and handovers to a publisher who already maintains another widely used package (100k+ weekly downloads) are reported but not flagged. Does not detect hijacked existing accounts; a heuristic for review, not proof. | Read-only |
| password | Generates a random password, with options for length, symbols, uppercase, numbers and excluding ambiguous characters. To evaluate an existing password, use password_check. | Read-only |
| password_breach | Checks whether a password appears in known data breaches (Have I Been Pwned) and how many times, using k-anonymity towards HIBP. Breach check only; password_check adds strength scoring and sends the password in a POST body. | Read-only |
| password_check | Scores a password's strength (length, character variety, entropy as an upper bound, repeated patterns; passphrases are estimated per word) and, with check_breach=true, also looks it up in Have I Been Pwned breach data via k-anonymity (only a hash prefix is sent); a password found in breaches is always rated very_weak. Use it to evaluate a password someone is choosing; use password_breach when you only need the breach count, and password to generate a new one. The password travels in a POST body, never in a URL. | Read-only |
| phone_verify | Validates and formats a phone number: validity, country, line type, E.164, international and national formats. Numbers without a leading + require 'country', since the end user's country cannot be inferred over MCP. | Read-only |
| redirect_trace | Follows a URL's full redirect chain (up to 15 hops) and returns every hop with its status code, plus whether the chain crossed domains. Use it to see where a short or tracking link really leads; check the final URL with url_reputation. | Read-only |
| repo_health_check | Maintenance signals for a GitHub repository given as owner/name: stars, forks, open issues, license, archived and fork flags, creation date and age, days since last push, topics. Use it to judge whether a dependency looks maintained or abandoned. For an npm or PyPI package whose repository you do not know, supply_chain_check resolves it from registry metadata and includes these signals. GitHub only; missing or private repositories return found: false. | Read-only |
| rpc_check | Read-only audit of a public CometBFT (Cosmos SDK) RPC endpoint: node status, health, peers, and whether unsafe admin methods (dial_seeds, dial_peers, unsafe_flush_mempool) are publicly exposed. Never calls an unsafe method; exposure is inferred from the node's route listing. | Read-only |
| security_headers | Audits the HTTP security headers of one URL (CSP, HSTS, X-Frame-Options, Permissions-Policy, cross-origin policies and others) and returns per-header findings with fix advice, a score and a letter grade. Use it when you need header hardening advice; security_scan runs this audit together with URL reputation and subdomain discovery in one call. | Read-only |
| security_scan | Combined website check in one call: security headers, URL reputation and passive subdomain discovery, run in parallel, with an overall score and verdict. Use the individual tools when you need a single signal. | Read-only |
| subdomains | Passive subdomain discovery from Certificate Transparency logs (crt.sh): finds hostnames that appeared in public TLS certificates, not every DNS record. crt.sh is occasionally slow or unavailable. | Read-only |
| supply_chain_check | Call this before installing or adding a package (npm install, pip install, a new entry in a manifest), especially one whose name you recalled or that a model suggested. One-call risk check: combines vulnerability_check (OSV.dev), typosquat_check, maintainer_change_check (npm only) and repo_health_check (when the GitHub repo can be resolved) into one overall verdict. A package that does not exist on npm or PyPI gets overall_risk 'package_not_found': the name may be invented, do not install it. Use the individual tools to investigate one signal. Vulnerabilities are checked for the given version, or the latest published one (version_checked, version_source). If a check could not run (rate limit, upstream error), it is listed in unavailable_checks and overall_risk is 'incomplete', never 'no_signals_found'. | Read-only |
| text_similarity | Near-duplicate detection with a 64-bit SimHash over word shingles: send 1 text to get its hash, or 2 texts to compare them. Detects paraphrased or lightly edited copies; unrelated texts score around 50%, not 0%. | Read-only |
| timestamp | Returns the current time, or converts between a Unix timestamp (seconds) and an ISO date. Provide unix or date, or neither for the current time. | Read-only |
| tx_decode | Decodes a raw signed Cosmos SDK transaction (base64 TxRaw bytes, as found in a CometBFT block's data.txs) into JSON: messages, fee, gas, signers and signatures. Bank, staking, gov and authz messages are fully decoded; other types are returned as type URL plus raw hex. | Read-only |
| typosquat_check | Call before installing a package whose name you typed or recalled. Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe. It does not check that the package exists: supply_chain_check does. | Read-only |
| url_clean | Removes 60+ known tracking parameters (utm_*, fbclid, gclid and similar) from a URL and returns the clean URL. Does not follow redirects; for that, use redirect_trace. | Read-only |
| url_reputation | Checks a URL against URLhaus (abuse.ch), a public database of known malware distribution URLs. A clean result only means the URL is not listed, not that it is safe. | Read-only |
| user_agent | Parses a User-Agent string into browser and version, operating system and version, device type, and whether it looks like a bot. | Read-only |
| uuid | Generates 1 to 100 random UUID v4 values. | Read-only |
| vat_validate | Checks an EU VAT number in real time against the European Commission's VIES service and, when valid, returns the registered company name and address. VIES is occasionally unavailable for some member states. | Read-only |
| vulnerability_check | Checks a package (optionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. Use cve_lookup when you already have a CVE/GHSA ID, or supply_chain_check for a combined verdict. | Read-only |
| whois_lookup | Domain registration data via RDAP (the modern WHOIS): registrar, creation and expiration dates, domain age in days, nameservers. For DNS records, use dns_lookup. | Read-only |
Change history
- Description changed (registry)
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | io.github.presendapp/presend-mcp | 2 Oct 2026 | 2 Oct 2026 | 2 |