
On-chain rug-pull & honeypot risk screen for ERC-20 tokens, providing a SAFE / CAUTION / HIGH-RISK verdict based on live public RPC reads.
Enables real-time email verification via MCP tools, checking syntax, MX, disposable domains, and optional SMTP probe to determine deliverability with a VALID/RISKY/INVALID verdict.
Scans npm, PyPI, and GitHub for typosquatting and brand impersonation, risk-scores findings, and drafts takedown notices.
Scans bank statements for zombie subscriptions and drafts cancellation, renegotiation, or data deletion letters.
Live multi-chain on-chain data: wallet portfolio, token info, gas and prices. MCP + x402.
Smart-contract security quick-scan: rug, honeypot & owner-power risk before you fund it.
Live email deliverability & DNS health: SPF, DKIM, DMARC, MX check with fixes — before you send.
Catch AI-hallucinated (slopsquatted) npm imports in generated code before npm install.
Live web health grade (A-F): TLS cert validity/expiry, TLS version, HTTPS redirect, security headers
Audit npm dependency licenses for copyleft/source-available/unlicensed conflicts before you ship.
Audit a package-lock.json for integrity tampering and risky install scripts before npm install.
npm supply-chain audit: known CVEs (OSV), typosquatting, malicious scripts — before npm install.
Scan code/diff for leaked secrets: API keys, private keys, tokens, conn strings, before you commit.
Live IP/domain reputation: ASN, type, reverse DNS, DNSBL blocklists & risk score from live DNS.