mcp-toolbelt

29 pay-per-call DNS, SEO, SSL, security, and dev tools for AI agents. x402, no API key.

¿Debería usar esto?

Calidad y seguridad

A
Calidad de la descripción
98%
Integridad del esquema
100%
Calidad de los nombres
81%
Riesgo de envenenamiento
100%
Coincidencia de permisos
100%
Cumplimiento del protocolo
100%

Hallazgos (2)

  • LOWTool 'redirect_chain_check' description lacks action verben redirect_chain_check
  • LOWTool 'ssl_cert_check' description lacks action verben ssl_cert_check

Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.

Costo de contexto

~3,419Tokens (definiciones de herramientas)
~547 BTamaño de respuesta típico
Impacto significativo en la atención (2.67% del contexto de 128k)

Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.

Instalar

Instalación con un clic

Agrega esto a tu archivo `claude_desktop_config.json`:

{
  "mcpServers": {
    "mcp-toolbelt": {
      "url": "https://papacasper.com/mcp"
    }
  }
}

Puntos de conexión remotos

https://papacasper.com/mcpstreamable-http

Qué puede hacer

Inventario de herramientas

Herramientas (29)

🟢 Solo lectura🟡 Escritura🔴 Eliminación⚪ Desconocido
🟢url_to_markdown(url)

Fetch a URL and return its main text content as clean, readable plain text/markdown-ish output. Strips scripts, styles, and HTML tags.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to fetch"
    }
  },
  "required": [
    "url"
  ]
}
🟢security_headers_audit(url)

Fetch a URL and audit its response for security-relevant HTTP headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy). Flags missing/misconfigured headers with a score.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to audit"
    }
  },
  "required": [
    "url"
  ]
}
🟢redirect_chain_check(url)

Follow a URL through every HTTP redirect hop and report the full chain, final destination, and issues like redirect loops, too many hops, or HTTPS-to-HTTP downgrades.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The starting URL to trace"
    }
  },
  "required": [
    "url"
  ]
}
🟢page_performance_check(url)

Fetch a URL and measure time-to-first-byte, total fetch time, and response size. Flags missing compression, missing Cache-Control, oversized payloads, and slow TTFB.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to measure"
    }
  },
  "required": [
    "url"
  ]
}
🟡cors_policy_check(url)

Send a probe request with a foreign Origin header to a URL and report its CORS response headers. Flags wildcard-origin + credentials combinations and arbitrary-origin reflection, both common CORS misconfigurations.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to probe"
    }
  },
  "required": [
    "url"
  ]
}
🟢structured_data_extract(url, selectors, attr)

Fetch a URL and extract structured data deterministically: JSON-LD blocks, OpenGraph/meta tags, and optional caller-supplied CSS-selector fields (e.g. { price: '.product-price', title: 'h1' }). No LLM involved — pure HTML parsing via CSS selectors, so results are exact matches only, not summarized or inferred.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to extract from"
    },
    "selectors": {
      "type": "object",
      "description": "Optional map of field name -> CSS selector (e.g. { price: '.product-price', headline: 'h1' }). Each field returns an array of matched, whitespace-normalized text values in document order.",
      "additionalProperties": {
        "type": "string"
      }
    },
    "attr": {
      "type": "string",
      "description": "Optional HTML attribute to extract instead of text content (e.g. 'href', 'src', 'content'). Applies to all selector fields in this call."
    }
  },
  "required": [
    "url"
  ]
}
🟢tech_stack_fingerprint(url)

Fetch a URL and fingerprint its likely tech stack from response headers (server, x-powered-by, x-generator) and HTML markers (generator meta tag, framework/CMS-specific script or class patterns). Best-effort — not exhaustive, no additional paths are probed.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to fingerprint"
    }
  },
  "required": [
    "url"
  ]
}
🟢ai_crawler_policy_check(url)

Check a site's robots.txt for explicit directives targeting known AI crawlers (GPTBot, ClaudeBot, CCBot, PerplexityBot, Google-Extended, Bytespider, Amazonbot, and others used for LLM training or AI search/answer products), and check for an llms.txt file. Useful for publishers deciding whether their content policy toward AI crawlers matches their intent, or for auditing a competitor's stance.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Any URL on the site to check (origin is derived from it)"
    }
  },
  "required": [
    "url"
  ]
}
🟢seo_audit(url)

Fetch a URL and run an SEO audit: title/meta description length, canonical tag, Open Graph + Twitter Card tags, html lang attribute, viewport meta, heading structure, image alt-text coverage, internal/external link counts and generic-anchor-text detection, robots meta (noindex/nofollow), structured data (JSON-LD) presence, and robots.txt/sitemap.xml presence.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to audit"
    }
  },
  "required": [
    "url"
  ]
}
🟢check_robots_sitemap(url)

Check whether a site has a valid robots.txt and sitemap.xml, and return their raw contents (truncated).

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Any URL on the site to check (origin is derived from it)"
    }
  },
  "required": [
    "url"
  ]
}
🟢broken_link_check(url, maxPages, checkExternal)

Crawl a site starting from a URL (same-origin pages only, bounded by maxPages) and check every linked URL for broken status codes. Returns broken links with the page(s) they were found on. Note: some external sites (e.g. social platforms) block automated HEAD/GET requests and may show up as false positives.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Starting URL to crawl"
    },
    "maxPages": {
      "type": "number",
      "description": "Max same-origin pages to crawl (default 20, capped at 50)"
    },
    "checkExternal": {
      "type": "boolean",
      "description": "Also check links pointing off-site (default true; crawling never follows off-site links)"
    }
  },
  "required": [
    "url"
  ]
}
🟢favicon_manifest_check(url)

Check a site for favicon, apple-touch-icon, web app manifest, and theme-color presence — a quick completeness check for browser/OS chrome and PWA metadata.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Any URL on the site to check (origin is derived from it)"
    }
  },
  "required": [
    "url"
  ]
}
🟢json_ld_schema_validator(url)

Fetch a URL, extract every JSON-LD (<script type="application/ld+json">) block, and validate basic structure — @context/@type presence plus required fields for common schema.org types (Article, Product, Organization, WebSite, LocalBusiness, BreadcrumbList, FAQPage). Reports per-block errors rather than failing the whole call on one bad block.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to check"
    }
  },
  "required": [
    "url"
  ]
}
🟢sitemap_url_validator(url)

Parse a site's sitemap.xml (following one level of sitemap-index nesting) and check the HTTP status of every listed URL. Concurrency-limited, capped at 200 URLs checked per call. Reports broken/redirecting URLs found in the sitemap.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "URL of the sitemap.xml to validate (or any page URL — /sitemap.xml on that origin is used)"
    }
  },
  "required": [
    "url"
  ]
}
🟢domain_health_check(domain)

Check a domain's registration expiry (via WHOIS) and DNS health: nameservers, A/AAAA, MX, SPF, and DMARC records. Flags common misconfigurations.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Bare domain to check, e.g. example.com (no scheme/path)"
    }
  },
  "required": [
    "domain"
  ]
}
🟢dns_propagation_check(domain, recordType)

Query a DNS record for a domain against several major public resolvers (Google, Cloudflare, Quad9, OpenDNS) in parallel and compare the answers. Flags mismatches, which usually mean propagation is still in progress after a DNS change.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Bare domain to query, e.g. example.com"
    },
    "recordType": {
      "type": "string",
      "description": "Record type: A, AAAA, MX, TXT, NS, or CNAME (default A)"
    }
  },
  "required": [
    "domain"
  ]
}
⚪ip_geolocation_asn_lookup(host)

Resolve a hostname to its IPv4 addresses and look up each one's ASN, network prefix, country code, and network owner via Team Cymru's DNS-based WHOIS service (no API key). Country-level only — not city/street geolocation.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string",
      "description": "Hostname or bare IPv4 address to look up"
    }
  },
  "required": [
    "host"
  ]
}
🟢email_deliverability_check(domain)

Deep-dive email deliverability check for a domain: MX records + reverse-DNS (PTR) on each MX host, common DKIM selector probing, SPF lookup-count (RFC 7208 caps at 10), DMARC policy strength, and DNSBL blacklist lookups (Spamhaus Zen, SpamCop, Barracuda) on MX IPs. Note: public-resolver DNSBL queries are frequently rate-limited or blocked by Spamhaus, so a `listed: null` result means "unknown", not "clean" — treat null results as inconclusive, not as a clean bill of health.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Bare domain to check, e.g. example.com"
    }
  },
  "required": [
    "domain"
  ]
}
🟢domain_availability_check(domain, checkSquats)

Check whether a domain is registered, plus scan common typo-squat variants (adjacent-key substitution, letter omission/doubling, transposition) across popular TLDs (.com, .net, .org, .io, .co, .ai, .app, .dev) for brand-protection or domain-flipping research. WHOIS-based; capped at 40 variants checked per call for latency.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Bare domain to check, e.g. example.com"
    },
    "checkSquats": {
      "type": "boolean",
      "description": "Also scan typo-squat variants (default true)"
    }
  },
  "required": [
    "domain"
  ]
}
🟢ssl_cert_check(hostname, port)

Connect to a host over TLS and report its certificate's expiry date, days remaining, issuer, and subject.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "hostname": {
      "type": "string",
      "description": "Hostname to check, e.g. papacasper.com (no scheme/path)"
    },
    "port": {
      "type": "number",
      "description": "TLS port to connect to (default 443)"
    }
  },
  "required": [
    "hostname"
  ]
}
🟢check_open_ports(host, ports)

TCP-connect scan a host for open ports. Defaults to a list of ~20 common service ports (SSH, HTTP/S, mail, DBs, etc.) if none are given. For checking your own infrastructure's exposure — capped at 100 ports per call.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "host": {
      "type": "string",
      "description": "Hostname or IP to scan (no scheme)"
    },
    "ports": {
      "type": "array",
      "items": {
        "type": "number"
      },
      "description": "Specific ports to check. Defaults to a common-ports list. Max 100 ports per call."
    }
  },
  "required": [
    "host"
  ]
}
🟢websocket_endpoint_check(url)

Test a WebSocket endpoint (ws:// or wss://): attempts the handshake, reports success/failure, time-to-open in ms, and close code/reason. Useful for verifying a WebSocket server is reachable and completes its upgrade handshake before you wire real traffic to it.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "WebSocket URL to test, e.g. wss://example.com/socket"
    }
  },
  "required": [
    "url"
  ]
}
🟢domain_report(domain)

Bundle: runs seo_audit, domain_health_check (WHOIS + DNS: nameservers, A/AAAA, MX, SPF, DMARC), and email_deliverability_check (DKIM, SPF lookup-count, DMARC strength, DNSBL) against a domain in one call, one charge. Cheaper than calling the three tools separately. Each sub-check reports independently, so a failure in one doesn't void the others.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Bare domain to report on, e.g. example.com (no scheme/path)"
    }
  },
  "required": [
    "domain"
  ]
}
🟢safe_browsing_check(url)

Check a URL against Google Safe Browsing's malware/phishing/unwanted-software/PUA blocklists. Requires GOOGLE_SAFE_BROWSING_API_KEY to be configured server-side (free Google Cloud API key).

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to check"
    }
  },
  "required": [
    "url"
  ]
}
🟢ssl_labs_grade(hostname)

Full SSL Labs-style TLS assessment: overall letter grade, protocol support (TLS 1.0-1.3), cipher strength, certificate chain issues, and known vulnerabilities (Heartbleed, POODLE, etc.) for each endpoint. Slower than ssl_cert_check (can take up to ~90s on a cold cache; SSL Labs caches results for 24h server-side).

Esquema de entrada

{
  "type": "object",
  "properties": {
    "hostname": {
      "type": "string",
      "description": "Hostname to assess, e.g. example.com (no scheme/path)"
    }
  },
  "required": [
    "hostname"
  ]
}
🟡pagespeed_insights(url, strategy)

Run Google's real PageSpeed Insights (Lighthouse + Chrome UX Report) against a URL: performance score, Core Web Vitals (LCP, CLS, INP/TBT), and real-user field data where available. Authoritative version of a local timing check — hits Google's own infrastructure. Works without an API key at low volume; set GOOGLE_PAGESPEED_API_KEY server-side for higher throughput.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The URL to test"
    },
    "strategy": {
      "type": "string",
      "enum": [
        "mobile",
        "desktop"
      ],
      "description": "Device strategy (default mobile)"
    }
  },
  "required": [
    "url"
  ]
}
🟢package_vulnerability_check(ecosystem, name, version)

Look up a package (optionally pinned to a version) against OSV.dev's aggregated vulnerability database (GitHub Advisories, PyPA, RustSec, Go vuln DB, etc.) for known CVEs/advisories. Supports npm, PyPI, crates.io, RubyGems, Go, Maven, NuGet, and Packagist ecosystems. Useful before adding a dependency.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "pypi",
        "cargo",
        "rubygems",
        "go",
        "maven",
        "nuget",
        "packagist"
      ],
      "description": "Package ecosystem"
    },
    "name": {
      "type": "string",
      "description": "Package name"
    },
    "version": {
      "type": "string",
      "description": "Optional exact version to check; omit to check the package generally"
    }
  },
  "required": [
    "ecosystem",
    "name"
  ]
}
🟢github_repo_health_check(owner, repo)

Check a GitHub repository's health signals: stars, forks, open issues, license, archived/disabled status, and days since last push. Flags likely-abandoned or unlicensed repos. Useful before depending on a repo.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "owner": {
      "type": "string",
      "description": "Repository owner (user or org)"
    },
    "repo": {
      "type": "string",
      "description": "Repository name"
    }
  },
  "required": [
    "owner",
    "repo"
  ]
}
🟢email_address_validate(email)

Validate a single email address: RFC syntax check, MX record lookup on the domain, disposable/temporary-email-provider detection, and role-account detection (info@, admin@, etc.). Per-address check — different from email_deliverability_check, which audits a whole domain's sending reputation (SPF/DKIM/DMARC/PTR/DNSBL).

Esquema de entrada

{
  "type": "object",
  "properties": {
    "email": {
      "type": "string",
      "description": "Email address to validate"
    }
  },
  "required": [
    "email"
  ]
}

Comunidad

Califica este servidor

Evidencia

Observaciones recientes

verificadoversión no registrada29 herramientas
verificadoversión no registrada29 herramientas
verificadoversión no registrada29 herramientas