nel-veil-mcp
Free passive security scanning for AI agents. Check any domain for email spoofing (DMARC/SPF/DKIM), TLS, security headers, exposed files, and subdomain takeover risk — using public information only, no intrusive probing.
npm · fingerprint 8859a560e8cbdf9f0ebe196c · repository · RSS
9 tools
1 recorded versions
13h tracked
tracking started
What changed Nothing, since tracking began. That is the good outcome, and it is what most servers look like.
Current tools
Show all 9 tool fingerprints
check_compliance
cf1ad2c564969634
check_email_spoofing
e664ce8dfcc3690c
check_exposed_files
31e9c13afc587fc1
check_security_headers
29496369ef0e247f
check_subdomain_takeover
d99845f727eaf0cf
check_tls
a017502d7b917cfb
get_scan_report
71c6cc7971a57b4f
list_compliance_frameworks
e2d2f6592734a875
scan_domain
cab2efe0e71273bd
Watch this server yourself
If you run this server, put the proxy in front of it. It pins these exact
fingerprints on first connect and stops the session if they move.
npx --yes mcp-pin@0.1.0 -- <your nel-veil-mcp command>
Or subscribe to this page's RSS feed
to be told when it changes.
Badge
The badge states one fact about time and nothing else. It never claims a
server is safe.
[](https://mcp-pin.gautamkhosla.com/servers/fb1286580b3b56f3.html)
mcp-pin keeps a public, append-only record of MCP tool definitions. Every entry is hash linked and every head is signed, so you can download the log and check it yourself with npx --yes mcp-pin@0.1.0 verify-log. You do not have to trust whoever runs this.
Crawling is one tools/list per server per day. No tool is ever called. To opt out, add your server to OPTOUT.txt or open an issue. Honoured on the next crawl, no justification needed.
Run by Gautam Khosla as an independent open-source project. Not affiliated with
Anthropic, the Model Context Protocol project, or any server listed here.
About this project, and how to contact me .
MIT licensed. Source on GitHub .