Presend MCP Server

Free MCP server of security & dev API tools -- supply-chain, CVE, DNS, WHOIS, OFAC, Cosmos SDK.

我该使用它吗

质量与安全性

A
描述质量
97%
模式完整度
99%
命名质量
81%
投毒风险
100%
权限匹配度
90%
协议合规性
100%

发现(2)

  • LOWTool 'base64' description lacks action verb在 base64 中
  • LOWTool 'url_clean' suggests web access but openWorldHint=false在 url_clean 中

基于对工具定义和协议合规性的自动分析。

上下文开销

~6,269token 数(工具定义)
~729 B典型响应大小
对注意力有显著影响(占 128k 上下文窗口的 4.90%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "presend-mcp": {
      "url": "https://presend.pages.dev/mcp"
    }
  }
}

远程端点

https://presend.pages.dev/mcpstreamable-http

它能做什么

工具清单

工具(40)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢address_risk(address)

Screens a crypto address against every OFAC SDN digital currency address list. EVM (0x...) and Bitcoin (bc1..., 1..., 3...) addresses are fully covered (sanctioned true or false, with the matching lists). Addresses of other chains are flagged when listed; Cosmos SDK bech32 addresses return sanctioned: null when not listed, as OFAC publishes none. A sanctions signal only, not a full risk score.

输入模式

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "Address to screen: EVM (0x + 40 hex chars) or Bitcoin (bc1..., 1..., 3...), both fully covered. Addresses of other chains are matched against their lists too; bech32 addresses of other chains (e.g. cosmos1...) return sanctioned: null (unchecked, not clean) when not listed."
    }
  },
  "required": [
    "address"
  ]
}
🟢ai_crawler_check(domain)

Fetches a domain's robots.txt and reports which known AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot and others) are allowed or blocked, including wildcard rules. Reflects robots.txt only, not server-side blocking.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to check, e.g. example.com. robots.txt is fetched from https://<domain>/robots.txt."
    }
  },
  "required": [
    "domain"
  ]
}
🟢base64(action, text)

Encodes text to Base64 or decodes a Base64 string back to text (action = encode or decode).

输入模式

{
  "type": "object",
  "properties": {
    "action": {
      "type": "string",
      "description": "Either 'encode' or 'decode'."
    },
    "text": {
      "type": "string",
      "description": "Text to encode, or Base64 string to decode."
    }
  },
  "required": [
    "action",
    "text"
  ]
}
🟢color(hex, rgb, hsl)

Converts a color between hex, RGB and HSL. Provide exactly one of hex, rgb or hsl.

输入模式

{
  "type": "object",
  "properties": {
    "hex": {
      "type": "string",
      "description": "Hex color code, e.g. #ff0000 or ff0000. Provide exactly one of hex, rgb, or hsl."
    },
    "rgb": {
      "type": "string",
      "description": "RGB color, e.g. 255,0,0. Provide exactly one of hex, rgb, or hsl."
    },
    "hsl": {
      "type": "string",
      "description": "HSL color, e.g. 0,100%,50%. Provide exactly one of hex, rgb, or hsl."
    }
  },
  "required": []
}
🟢csv_json(direction, data)

Converts CSV text to JSON or JSON to CSV (direction: csv-to-json or json-to-csv), for data passed inline. CSV must be comma-separated, with a header row and at least one data row; double-quoted fields may contain commas. Semicolon- or tab-separated input is not detected and comes back as a single column. JSON input must be an array of objects: the union of their keys becomes the CSV header and missing values are left empty. Returns result (the converted text), rows and cols. Max 500,000 characters.

输入模式

{
  "type": "object",
  "properties": {
    "direction": {
      "type": "string",
      "description": "Either 'csv-to-json' or 'json-to-csv'."
    },
    "data": {
      "type": "string",
      "description": "The CSV or JSON text to convert, matching the chosen direction."
    }
  },
  "required": [
    "direction",
    "data"
  ]
}
🟢cve_lookup(id)

Looks up a vulnerability by identifier (CVE, GHSA or other OSV ID) on OSV.dev: summary, CVSS severity, affected packages and versions, references. Use when you already have an ID; use vulnerability_check when you have a package name instead.

输入模式

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "CVE, GHSA, or other OSV-native identifier, e.g. CVE-2021-44228."
    }
  },
  "required": [
    "id"
  ]
}
🟢dns_lookup(domain, type)

Returns DNS records for a domain via Cloudflare DNS-over-HTTPS: A, AAAA, CNAME, MX, TXT and NS in one call, or a single record type with 'type'. For registration data use whois_lookup; for SPF/DMARC/DKIM analysis use email_security.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to look up, e.g. example.com."
    },
    "type": {
      "type": "string",
      "description": "Narrow to a single record type. Omit to get all 6 at once."
    }
  },
  "required": [
    "domain"
  ]
}
🟢email_disposable(email)

Checks only whether an email address uses a known disposable/temporary email domain. For syntax, MX, disposable and role-account checks in one call, use email_verify.

输入模式

{
  "type": "object",
  "properties": {
    "email": {
      "type": "string",
      "description": "Email address to check against a list of known disposable/temporary email domains."
    }
  },
  "required": [
    "email"
  ]
}
🟢email_security(domain)

Audits a domain's email anti-spoofing setup: SPF strength, DMARC policy and a best-effort DKIM lookup on common selectors. A missing DKIM match does not prove DKIM is absent. Checks a domain, not a single address.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to check SPF, DKIM, and DMARC records for, e.g. example.com."
    }
  },
  "required": [
    "domain"
  ]
}
🟢email_validate(email)

Lightweight email check: syntax plus confirmation that the domain has an MX record. Does not detect disposable or role addresses; use email_verify for the combined check.

输入模式

{
  "type": "object",
  "properties": {
    "email": {
      "type": "string",
      "description": "Email address to validate for correct syntax and a resolvable domain."
    }
  },
  "required": [
    "email"
  ]
}
🟢email_verify(email)

Most complete email check in one call: syntax, MX record, disposable-domain detection and role/generic account detection (e.g. info@, admin@). Prefer it over email_validate and email_disposable unless you need a single signal. Does not probe the mailbox. valid is null (not false) when the MX lookup could not be completed; retry later instead of treating the address as invalid.

输入模式

{
  "type": "object",
  "properties": {
    "email": {
      "type": "string",
      "description": "Email address to run through combined syntax, disposable-domain, and MX-record checks."
    }
  },
  "required": [
    "email"
  ]
}
🟢favicon(domain)

Returns the favicon URL a website declares: fetches the homepage and takes the first <link rel='icon'> (or 'shortcut icon') href, resolved to an absolute URL, which may be a data: URI when the page inlines its icon (source: declared). If no icon is declared, or the homepage cannot be fetched, returns the conventional https://<domain>/favicon.ico with source: default and a note, without checking that it exists. Use it to display a site icon; it does not download or validate the image.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to fetch the favicon URL for, e.g. example.com."
    }
  },
  "required": [
    "domain"
  ]
}
🟢iban_validate(iban)

Validates an IBAN offline: ISO 7064 mod-97 checksum and country-specific length. Confirms the number is well-formed, not that the account exists.

输入模式

{
  "type": "object",
  "properties": {
    "iban": {
      "type": "string",
      "description": "IBAN to validate. Spaces are ignored."
    }
  },
  "required": [
    "iban"
  ]
}
🟢ip_reputation(ip)

Checks an IPv4 or IPv6 address against a curated list of netblocks known to be hijacked or run by spam/cyber-crime operations (IPv4-mapped IPv6 uses the IPv4 list). A narrow list-based signal: a clean result is not a safety guarantee. Includes list date and attribution.

输入模式

{
  "type": "object",
  "properties": {
    "ip": {
      "type": "string",
      "description": "IPv4 or IPv6 address to check (IPv4-mapped IPv6 such as ::ffff:1.2.3.4 is checked against the IPv4 list) against a curated list of known hijacked or cyber-crime-controlled netblocks."
    }
  },
  "required": [
    "ip"
  ]
}
🟢jwt_decode(token)

Decodes a JWT's header and payload WITHOUT verifying its signature, so its claims must not be trusted on this basis alone. To check authenticity, use jwt_verify.

输入模式

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string",
      "description": "The JWT to decode. Decodes header and payload only -- does not verify the signature (use /jwt-verify for that)."
    }
  },
  "required": [
    "token"
  ]
}
🟢jwt_verify(token, secret, jwk, jwks_url)

Cryptographically verifies a JWT signature (HS256/384/512, RS/PS256/384/512, ES256/384/512) and checks exp/nbf claims. Provide a secret for HS*, or a JWK or JWKS URL for RS/PS/ES. Use instead of jwt_decode whenever authenticity matters.

输入模式

{
  "type": "object",
  "properties": {
    "token": {
      "type": "string",
      "description": "The JWT to verify. Checks the cryptographic signature -- use /jwt-decode if you only need to read the header and payload."
    },
    "secret": {
      "type": "string",
      "description": "Required for HS256/384/512."
    },
    "jwk": {
      "type": "object",
      "description": "Public key in JWK format, for RS/PS/ES algorithms."
    },
    "jwks_url": {
      "type": "string",
      "description": "URL to a JWKS document; the key is matched by the token's \"kid\" header."
    }
  },
  "required": [
    "token"
  ]
}
🟢link_metadata(url)

Fetches a web page and extracts its title, description, canonical URL, Open Graph and Twitter Card tags and favicon (the data behind link previews). Follows redirects and returns final_url; favicon_source says whether the icon is declared by the page or only the /favicon.ico guess. To see each redirect hop, use redirect_trace.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "URL to extract title, description, and Open Graph / Twitter Card metadata from."
    }
  },
  "required": [
    "url"
  ]
}
🟢maintainer_change_check(ecosystem, package)

npm only. Flags a previously unseen human publisher taking over a package after 180+ days of inactivity, within the last 365 days (the event-stream attack pattern). npm trusted publishing (verified OIDC identity, not just a bot-like account name), pre-release, and handovers to a publisher who already maintains another widely used package (100k+ weekly downloads) are reported but not flagged. Does not detect hijacked existing accounts; a heuristic for review, not proof.

输入模式

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Currently only 'npm' is supported."
    },
    "package": {
      "type": "string",
      "description": "Package name, e.g. lodash"
    }
  },
  "required": [
    "ecosystem",
    "package"
  ]
}
🟢password(length, symbols, uppercase, numbers, exclude_ambiguous)

Generates a random password, with options for length, symbols, uppercase, numbers and excluding ambiguous characters. To evaluate an existing password, use password_check.

输入模式

{
  "type": "object",
  "properties": {
    "length": {
      "type": "string",
      "description": "Desired password length. Defaults to a reasonable secure length if omitted."
    },
    "symbols": {
      "type": "string",
      "description": "Whether to include symbol characters. 1 for yes, 0 for no."
    },
    "uppercase": {
      "type": "string",
      "description": "Whether to include uppercase letters. 1 for yes, 0 for no."
    },
    "numbers": {
      "type": "string",
      "description": "Whether to include numeric digits. 1 for yes, 0 for no."
    },
    "exclude_ambiguous": {
      "type": "string",
      "description": "Whether to exclude visually ambiguous characters (e.g. 0/O, 1/l). 1 for yes, 0 for no."
    }
  },
  "required": []
}
🟢password_breach(password)

Checks whether a password appears in known data breaches (Have I Been Pwned) and how many times, using k-anonymity towards HIBP. Breach check only; password_check adds strength scoring and sends the password in a POST body.

输入模式

{
  "type": "object",
  "properties": {
    "password": {
      "type": "string",
      "description": "Password to check against known data-breach corpora. Only a 5-character SHA-1 hash prefix is sent to HIBP (k-anonymity), but the password itself travels in this request's URL; for real passwords, prefer password_check, which takes it in a POST body."
    }
  },
  "required": [
    "password"
  ]
}
🟢password_check(password, check_breach)

Scores a password's strength (length, character variety, entropy, common patterns) and, with check_breach=true, also looks it up in Have I Been Pwned breach data via k-anonymity (only a hash prefix is sent). Use it to evaluate a password someone is choosing; use password_breach when you only need the breach count, and password to generate a new one. The password travels in a POST body, never in a URL.

输入模式

{
  "type": "object",
  "properties": {
    "password": {
      "type": "string",
      "description": "Password to evaluate for strength (length, character variety, common patterns)."
    },
    "check_breach": {
      "type": "boolean",
      "description": "Whether to also check the password against known data-breach corpora via k-anonymity. true or false."
    }
  },
  "required": [
    "password"
  ]
}
🟢phone_verify(number, country)

Validates and formats a phone number: validity, country, line type, E.164, international and national formats. Numbers without a leading + require 'country', since the end user's country cannot be inferred over MCP.

输入模式

{
  "type": "object",
  "properties": {
    "number": {
      "type": "string",
      "description": "Phone number to validate and format, ideally in E.164 format (e.g. +14155552671)."
    },
    "country": {
      "type": "string",
      "description": "ISO 3166-1 alpha-2 country code (e.g. US, FR). Required unless the number starts with +: over MCP the end user's country cannot be inferred."
    }
  },
  "required": [
    "number"
  ]
}
🟢redirect_trace(url)

Follows a URL's full redirect chain (up to 15 hops) and returns every hop with its status code, plus whether the chain crossed domains. Use it to see where a short or tracking link really leads; check the final URL with url_reputation.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "URL to follow the full redirect chain for, hop by hop."
    }
  },
  "required": [
    "url"
  ]
}
🟢repo_health_check(repo)

Maintenance signals for a GitHub repository given as owner/name: stars, forks, open issues, license, archived and fork flags, creation date and age, days since last push, topics. Use it to judge whether a dependency looks maintained or abandoned. For an npm or PyPI package whose repository you do not know, supply_chain_check resolves it from registry metadata and includes these signals. GitHub only; missing or private repositories return found: false.

输入模式

{
  "type": "object",
  "properties": {
    "repo": {
      "type": "string",
      "description": "GitHub repository in owner/name format, e.g. lodash/lodash."
    }
  },
  "required": [
    "repo"
  ]
}
🟢rpc_check(url)

Read-only audit of a public CometBFT (Cosmos SDK) RPC endpoint: node status, health, peers, and whether unsafe admin methods (dial_seeds, dial_peers, unsafe_flush_mempool) are publicly exposed. Never calls an unsafe method; exposure is inferred from the node's route listing.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Base URL of a CometBFT RPC endpoint to audit, e.g. https://rpc.cosmos.network:443."
    }
  },
  "required": [
    "url"
  ]
}
🟢security_headers(url)

Audits the HTTP security headers of one URL (CSP, HSTS, X-Frame-Options, Permissions-Policy, cross-origin policies and others) and returns per-header findings with fix advice, a score and a letter grade. Use it when you need header hardening advice; security_scan runs this audit together with URL reputation and subdomain discovery in one call.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "URL to audit HTTP security headers for (CSP, HSTS, X-Frame-Options, etc.)."
    }
  },
  "required": [
    "url"
  ]
}
🟢security_scan(url)

Combined website check in one call: security headers, URL reputation and passive subdomain discovery, run in parallel, with an overall score and verdict. Use the individual tools when you need a single signal.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "URL to run a combined security posture check against (headers, reputation, and related signals)."
    }
  },
  "required": [
    "url"
  ]
}
🟢subdomains(domain)

Passive subdomain discovery from Certificate Transparency logs (crt.sh): finds hostnames that appeared in public TLS certificates, not every DNS record. crt.sh is occasionally slow or unavailable.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to passively discover subdomains for via Certificate Transparency logs, e.g. example.com."
    }
  },
  "required": [
    "domain"
  ]
}
🟢supply_chain_check(ecosystem, package, version)

One-call risk check for a package: combines vulnerability_check (OSV.dev), typosquat_check, maintainer_change_check (npm only) and repo_health_check (when the GitHub repo can be resolved) into one overall verdict. Use before adding a dependency; use the individual tools to investigate one signal. Vulnerabilities are checked for the given version, or the latest published one (version_checked, version_source). If a check could not run (rate limit, upstream error), it is listed in unavailable_checks and overall_risk is 'incomplete', never 'no_signals_found'.

输入模式

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Package ecosystem, e.g. npm. maintainer-change-check only runs for npm."
    },
    "package": {
      "type": "string",
      "description": "Package name to check."
    },
    "version": {
      "type": "string",
      "description": "Exact version to check for known vulnerabilities. Optional: defaults to the latest published version (npm and PyPI)."
    }
  },
  "required": [
    "ecosystem",
    "package"
  ]
}
🟢text_similarity(texts)

Near-duplicate detection with a 64-bit SimHash over word shingles: send 1 text to get its hash, or 2 texts to compare them. Detects paraphrased or lightly edited copies; unrelated texts score around 50%, not 0%.

输入模式

{
  "type": "object",
  "properties": {
    "texts": {
      "type": "array",
      "description": "1 text (hash only) or 2 texts (compare). Max 200,000 characters each."
    }
  },
  "required": [
    "texts"
  ]
}
🟢timestamp(unix, date)

Returns the current time, or converts between a Unix timestamp (seconds) and an ISO date. Provide unix or date, or neither for the current time.

输入模式

{
  "type": "object",
  "properties": {
    "unix": {
      "type": "string",
      "description": "Unix timestamp (seconds since epoch) to convert to a human-readable date. Provide either unix or date, not both."
    },
    "date": {
      "type": "string",
      "description": "Date/time string to convert to a Unix timestamp. Provide either unix or date, not both."
    }
  },
  "required": []
}
🟢tx_decode(tx)

Decodes a raw signed Cosmos SDK transaction (base64 TxRaw bytes, as found in a CometBFT block's data.txs) into JSON: messages, fee, gas, signers and signatures. Bank, staking, gov and authz messages are fully decoded; other types are returned as type URL plus raw hex.

输入模式

{
  "type": "object",
  "properties": {
    "tx": {
      "type": "string",
      "description": "Base64-encoded Cosmos SDK TxRaw protobuf bytes, as returned by a chain's CometBFT RPC /block or /tx_search endpoints."
    }
  },
  "required": [
    "tx"
  ]
}
🟢typosquat_check(ecosystem, package)

Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe.

输入模式

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Package ecosystem, e.g. npm or PyPI."
    },
    "package": {
      "type": "string",
      "description": "Package name to check for likely typosquatting of a well-known package in the given ecosystem."
    }
  },
  "required": [
    "ecosystem",
    "package"
  ]
}
🟢url_clean(url)

Removes 60+ known tracking parameters (utm_*, fbclid, gclid and similar) from a URL and returns the clean URL. Does not follow redirects; for that, use redirect_trace.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "URL to strip tracking parameters from (utm_*, fbclid, gclid, and similar)."
    }
  },
  "required": [
    "url"
  ]
}
🟢url_reputation(url)

Checks a URL against URLhaus (abuse.ch), a public database of known malware distribution URLs. A clean result only means the URL is not listed, not that it is safe.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "URL to check against known phishing/malware URL databases."
    }
  },
  "required": [
    "url"
  ]
}
🟢user_agent(ua)

Parses a User-Agent string into browser and version, operating system and version, device type, and whether it looks like a bot.

输入模式

{
  "type": "object",
  "properties": {
    "ua": {
      "type": "string",
      "description": "User-Agent string to parse. Required over MCP: the server cannot see the end user's own User-Agent."
    }
  },
  "required": [
    "ua"
  ]
}
🟢uuid(count)

Generates 1 to 100 random UUID v4 values.

输入模式

{
  "type": "object",
  "properties": {
    "count": {
      "type": "string",
      "description": "Number of UUIDs (v4) to generate. Defaults to 1 if omitted."
    }
  },
  "required": []
}
🟢vat_validate(country, vat)

Checks an EU VAT number in real time against the European Commission's VIES service and, when valid, returns the registered company name and address. VIES is occasionally unavailable for some member states.

输入模式

{
  "type": "object",
  "properties": {
    "country": {
      "type": "string",
      "description": "2-letter EU country code (EL for Greece, XI for Northern Ireland). Optional if vat includes the prefix."
    },
    "vat": {
      "type": "string",
      "description": "VAT number, with or without the country prefix."
    }
  },
  "required": [
    "vat"
  ]
}
🟢vulnerability_check(ecosystem, package, version)

Checks a package (optionally a specific version) against OSV.dev for known vulnerabilities: npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist and NuGet. Use cve_lookup when you already have a CVE/GHSA ID, or supply_chain_check for a combined verdict.

输入模式

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "description": "Package ecosystem, e.g. npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist, or NuGet."
    },
    "package": {
      "type": "string",
      "description": "Package name to check against OSV.dev for known CVEs."
    },
    "version": {
      "type": "string",
      "description": "Omit to check all versions of the package."
    }
  },
  "required": [
    "ecosystem",
    "package"
  ]
}
🟢whois_lookup(domain)

Domain registration data via RDAP (the modern WHOIS): registrar, creation and expiration dates, domain age in days, nameservers. For DNS records, use dns_lookup.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Domain to look up registration details for via RDAP, e.g. example.com."
    }
  },
  "required": [
    "domain"
  ]
}

社区

评价此服务器

证据

最近观测

已验证未记录版本40 个工具
已验证未记录版本41 个工具
已验证未记录版本37 个工具