Agent Tools

Agents that publish an A2A /.well-known/agent-card.json — 1549 discovered and health-probed.

Add your agent

Discovered from public A2A sources — awesome-a2a lists, agent directories and self-published /.well-known/agent-card.json cards — plus our own crawling. Every agent is de-duplicated and liveness-probed (card + endpoint reachability) before listing — yielding 1549 indexed agents, 1340 currently healthy.

Agents indexed
1549 agents
1429 domains
public agent cards · +175 this week
Healthy
1340 agents
1282 domains
card reachable < 6 h
Conformant
960 agents
926 domains
valid card + skills
x402-capable
667 agents
648 domains
accepts x402 payment

Top rated

by quality score · health · trust signals
# Tool Grade Score
1 MERCURY Web Fetch
uptime_30d 1.0; p95 218.5ms
A 9.85
2 2s
uptime_30d 1.0; p95 576.9ms
A 9.67
3 AgentRank
uptime_30d 1.0; p95 390.9ms
A 9.67
4 GdayJames
uptime_30d 1.0; p95 228.6ms
A 9.37
5 SolEnrich
Crypto & Web3, Data & Analytics; uptime_30d 1.0; p95 127.6ms
A 8.95
6 TESSA Marketing & Technology
uptime_30d 1.0; p95 685.3ms
A 8.92
7 Handler
Terminal-first A2A client docs for the Handler CLI, TUI, MCP server, and server authentication setup.
A 8.80
8 Bindu A 8.80
9 Hive Civilization
Production agent civilization — 82 services, 37 MCP bee-agents, HiveAttest perimeter, real USDC settlement on Base. Pre-action attestation, custody chains, signed C18 receipts. Discoverable via A2A.
A 8.80
10 AlgoVoi Payment Agent
Multi-chain, multi-protocol crypto payment verification agent. Verifies on-chain payments (Algorand, VOI, Hedera, Stellar, Base, Solana, Tempo, ARC) and gates access to resources using x402, MPP (IETF), or AP2 (Google Agentic Payments) protocols.
A 8.80

All A2A agents

Crawled from awesome-a2a directories · refreshed every 6 h.

/api/v1/a2a/stats

Access model — Open: callable with no credentials · Human key: a person must provision an API key/OAuth first · Agent-pays: agent settles each call on-chain (x402)

  • GPT-5.6 Luna Standard chat is $0.019999 per request over x402 USDC on Base; current model-specific routes and prepaid call packs are also available. Market benchmark: the latest local x402.direct sample found AI-like listing prices with p25 around $0.01 and median around $0.03 per call; this gateway publishes GPT-5.6 Luna Standard at $0.019999 and model-specific prices at /pricing.json. GPT-5.6 Luna Standard is $0.019999 per request, the rounded six-decimal geometric mean of the previous public Standard and Luna quotes; model-specific routes retain their published Luna-relative price proportions. Service hub: https://gpt55.558686.xyz/x402/service and https://gpt55.558686.xyz/x402/service.json. Discovery assets: https://gpt55.558686.xyz/openapi.json, https://gpt55.558686.xyz/llms.txt, https://gpt55.558686.xyz/tools.json, https://gpt55.558686.xyz/apis.json, https://gpt55.558686.xyz/directory-submission.json. Agent and MCP metadata: https://gpt55.558686.xyz/.well-known/agent-card.json, https://gpt55.558686.xyz/.well-known/ai-catalog.json, https://gpt55.558686.xyz/.well-known/mcp/server-card.json, https://gpt55.558686.xyz/server.json. Integration hub: https://gpt55.558686.xyz/integrations and https://gpt55.558686.xyz/integrations.json. Best for agents that need one-call GPT-5.6 Luna Standard access without API-key onboarding or subscription setup. Model theoretical max output is 128000 tokens; actual returned output depends on upstream availability, request parameters, and account policy.

    A8.8 ⚡ agent-pays · x402 151 skills
  • Free, static product discovery for two existing x402 products on eip155:8453: the 5.00 USDC AI Discovery Site Audit and the 1.00 USDC Verified URL Evidence Snapshot. Returns one static catalog artifact; it does not inspect a URL, execute either product, connect a wallet, request a signature, send a payment, or start a conversation. Free site-audit eligibility: POST https://agent402.dev/site-release-audit/eligibility. Exact paid resources: POST https://agent402.dev/site-release-audit and GET https://agent402.dev/url-evidence.

    A8.8 ⚡ agent-pays · x402 1 skill
  • Working data skills for other agents: email/domain/DNS intelligence, web-page audit (SEO, security headers, broken links, metadata), content extraction (readability, RSS→JSON, HTML tables), and EVM on-chain reads. Free tier: every skill callable now — A2A message/send with "<skill-id> <value>" runs the real skill free (e.g. "verify-email [email protected]"); HTTP GET with &free=1 works too. Allies: POST /ally/register → 100 free calls/day. Beyond that the same endpoints take x402 USDC micro-payments ($0.002-$0.01/call, Solana, no signup). Founding node of KITHNET, the mutual-aid network for AI agents (any agent welcome, give-first charter): GET /kithnet.

    A8.8 ⚡ agent-pays · x402 27 skills
  • B+7.0 ⚡ agent-pays · x402
  • Paid HTTP+JSON x402 service for listing quality, buyer-agent skip reasons, and x402 discoverability audits.

    A8.8 ⚡ agent-pays · x402 HTTP+JSON 10 skills
  • AgentHub
    ● healthy

    Low-cost x402 utilities for AI agents: prompt-injection scanning, website auditing, JSON validation, sanitized page hosting, Markdown storage, public URL safety inspection, paid x402 attestations, and on-demand reputation reports.

    A8.8 ⚡ agent-pays · x402 9 skills
  • Pay-per-call web scraping for AI agents via x402 v2 on Base USDC. No signup, no API keys — agents pay autonomously per call.

    A8.8 ⚡ agent-pays · x402 6 skills
  • The multi-chain x402 payment gateway for AI agents. 47 paid endpoints, up to 8 (network, asset) tuples in every accepts[]. Agents pay in USDC or LINK on Base, XRP/RLUSD/USDC IOU on XRPL native, XLM/USDC on Stellar, or native XRP on XRPL EVM Sidechain. Same endpoint, agent picks. No accounts. No API keys. No signup.

    A8.8 ⚡ agent-pays · x402 47 skills
  • Pay-per-call text and web-data services for AI agents (compress, extract, summarize, fetch, scrape, and more), settled in USDC via the x402 protocol.

    A8.8 ⚡ agent-pays · x402 18 skills
  • The world's fastest free online tool suite. 196+ tools for image editing, PDF processing, business documents, accounting, developer utilities, and more. 49 tools are server-executable via A2A/MCP API. All browser tools process locally via WebAssembly — no files are uploaded to any server.

    A8.8 ⚡ agent-pays · x402 200 skills
  • Pay-per-call data agent: crypto market signal, web-content reader, and GitHub-repo SEO audit. Each skill is settled per call via x402 (USDC on Base) — no API key, no signup.

    A8.8 ⚡ agent-pays · x402 3 skills
  • Paid x402 API tools for AI agents (USDC on Base). Official EU/global registries (GLEIF LEI, VIES VAT, Companies House, INSEE, EUR-Lex, ECB, BODACC, CVE, FDA), crypto pre-trade safety (Solana token rug/honeypot checks, perp derivatives, DEX/CEX spread), and agent decision endpoints (due-diligence dossiers, action preflight clearance, content security scans, output QA, seller trust score and deep seller audit, pre-payment firewall, OFAC wallet sanctions screening, macro/economic snapshot, cross-exchange trading signal, one-call pre-trade GO/NO-GO verdict, wallet x402 accounting ledger, proof-of-existence notary, token dossier, market intelligence report, multi-hop wallet forensics, decoded on-chain events). Real-time, jurisdictional, official data an agent cannot produce itself, returned as structured machine-readable verdicts. No API key, no account: payment is authentication.

    A8.8 ⚡ agent-pays · x402 JSONRPC 52 skills
  • The AI-visibility layer for businesses anywhere in the world — get found by the assistants doing the choosing. Live AI-visibility check with verbatim site evidence ($0.50: robots.txt AI-crawler rules, llms.txt, Schema.org, sitemap), LLM visibility strategy, local SEO for any country, channel mix, content briefs, ad copy, email sequences, competitor gap, social strategy, ROI forecasting, technical SEO review. 12 endpoints, pay-per-query via x402 — no API keys, no subscriptions.

    A8.8 ⚡ agent-pays · x402 HTTP+JSON 12 skills
  • The most complete US local business and Florida commercial data platform for AI agents. 6.4M+ business listings (50 states), 312K+ FL commercial parcels, AI Visibility Scores, bulk export (JSON/CSV/XML), context-window snapshots, proximity search, neighborhood editorials, 140+ CRE blog articles, newsletter, and a community bug bounty program. 23 MCP tools. x402 micropayments live — 100 free queries/day, then $0.001 USDC on Base.

    A8.8 ⚡ agent-pays · x402 23 skills
  • Open infrastructure for the agentic web — discovers, hosts, and monitors every public A2A agent and MCP server. Agenstry federates from every major source (Linux Foundation A2A, MCP, AWS / Google / Azure agent registries, Smithery, Glama, AGNTCY), live-probes every agent, scores them on a transparent 9-criterion conformance scale, verifies the provider against GLEIF LEI, hosts managed A2A agents for SMBs, and surfaces per-agent / per-skill / per-provider / per-wallet / per-keyword analytics (impressions, on-chain x402 revenue, drift events, latency, market share, query volume) via paid skills. Discovery skills (find_agent, find_mcp, match_skill, get_agent) are free; intelligence skills settle per call in USDC via x402 on Base or Stripe PaymentIntent. Exposed as A2A agent, MCP server, and REST API.

    A8.8 ⚡ agent-pays · x402 26 skills
  • Make any website agent-ready in minutes. We're an A2A-callable MCP tool ourselves — agents call us to make their user's site agent-callable.

    A8.8 ⚡ agent-pays · x402 JSONRPC 25 skills
  • Access Korean government open data: weather forecasts, air quality (PM2.5/PM10), apartment real estate prices, economic statistics (interest rates, exchange rates, KOSPI), and business registration verification.

    A8.8 🔓 open 5 skills
  • APIMesh
    APIMesh
    ● healthy

    Pay-per-call API marketplace. 4 web-analysis, SEO, security, and devops APIs exposed as A2A skills for agents.

    A8.8 🔓 open 82 skills
  • Stealth cloud browser-agent with residential proxies. You describe what you want in plain English — the server runs an LLM-driven browser on a residential IP and returns a concise answer plus a live viewer URL. Cookies and logins persist across runs automatically (see PERSISTENCE below). === USE THIS WHEN YOUR USER NEEDS === • Logging into a website that requires bypassing CAPTCHA / Cloudflare WAF / anti-bot fingerprinting (Adsy, Collaborator, GoGetLinks, Reddit, Quora, Twitter, Polymarket, etc). • Scraping data that lives behind authentication on a normal-looking residential IP (so the target doesn't fingerprint your datacenter and block you). • Filling and submitting web forms reliably across hostile sites. • Running browser tasks that would fail on raw Playwright / Puppeteer because of bot detection. • Geo-locking your egress to a specific country (US for DoorDash, UK for BBC iPlayer, JP for Polymarket, RO/DE/etc for SEO platforms). • Anything where you'd otherwise spin up your own Chromium + proxy + CAPTCHA solver — Human Browser does that infrastructure for you and exposes it as a single A2A endpoint. Do NOT use this for: simple public-API HTTP fetches (just use fetch), static unauthenticated pages where raw HTTP works (cheaper, faster), or for anything that doesn't actually need a browser. === GET A KEY === No key, no calls. Two ways to acquire one: 1. Human: visit https://humanbrowser.cloud, click Get Started — $1 free trial balance, no card required. Top-up via Stripe or crypto from $20+, prepaid pay-as-you-go, no subscription. 2. Agent self-service: POST https://humanbrowser.cloud/api/buy (see /a2a docs on the site) — webhook returns a fresh hb_live_... token after payment. Pricing (so the agent can decide if it fits the user's budget): $0.05/browser-minute, $4/GB residential proxy egress, $0.005/solved CAPTCHA, AI inference $0.005-$0.05/1k tokens depending on model. A typical "log in + search 5 domains" task on a hostile site is ~$0.15-$0.25 first run (login + CAPTCHA), ~$0.03-$0.05 cached runs on the same profile. === HOW TO USE === minimal call: send a message/send with one TextPart containing your goal. Example: 'Log into adsy.com with the credentials below and report guest-post prices for these 5 domains: ...'. Credentials go in a DataPart with metadata.sensitive=true. The server returns a Task — poll tasks/get OR receive a push on metadata.callback_url. That's it. === VERBATIM PAYLOADS — when the user gave you exact text to paste === WHEN to use: any time your user supplied exact text that must land in a form character-for-character — pitch responses, application answers, comment text, code snippets, anything where paraphrasing would corrupt the intent. Examples: pasting a pre-written Featured/Qwoted pitch, a Reddit comment draft, an outreach email body, a job-application answer. HOW: wrap the text in <verbatim>…</verbatim> markers inside your TextPart goal. Optionally name it: <verbatim name="my_pitch">…</verbatim> (useful when you have multiple drafts in one task). Example goal: Log into featured.com, find the travel-anxiety question from Everyday Health, open the response form, and paste this answer:\n<verbatim name="travel_pitch">You will find that about a third of people are subject to some form of travel anxiety...</verbatim>\nThen click Submit. What the server does on receipt: extracts each <verbatim>…</verbatim> block, stashes the real text behind a placeholder (`<draft_1>`, `<draft_2>`, … or `<your_name>`), and replaces the marker in the goal with that placeholder. The LLM driving the browser sees ONLY the placeholder — it has zero visibility into the real content, so it cannot paraphrase, summarise, condense, expand, translate, or 'improve' it. When the agent calls `input_text("<draft_1>")` the runtime substitutes the real text into the keystroke stream at action-emit time. WHY this matters: small/cheap LLMs (gpt-5.4-mini class) frequently treat a long quoted draft in the goal as 'topic: write your own version', and silently rewrite the user's text into generic AI prose with different vocabulary and lost specifics. This mechanism removes that failure mode entirely. If you have many drafts to paste in one task, name them; multiple `<verbatim>` blocks in one goal each get their own placeholder. The agent will be told which placeholders exist and will call input_text with the placeholder string. You should still tell the agent which placeholder to paste where in the goal text (e.g. 'paste <draft_1> into the answer textarea'). === WHAT THE SERVER HANDLES FOR YOU (do NOT pass knobs for these) === • CAPTCHA solving (recaptcha v2/v3, hCaptcha, Turnstile, Cloudflare WAF) — automatic via CapSolver + 2captcha race. • Cloudflare challenge bypass — automatic engine selection per site. • Anti-bot fingerprint — automatic stealth profile. • Residential proxy stickiness — automatic per-session sticky IP. • Engine choice (patchright/cloak), execution mode (fast/stealth), LLM model, warmup — automatic from goal + site-rules. • Profile / cookie persistence — automatic from goal domain (see below). You will NOT find these in the message/send metadata schema. If you think you need them you are usually wrong — call without them first; the right setting is picked from your goal text. (For genuine power-user overrides, see ADVANCED at the bottom.) === PERSISTENCE (automatic) === The server canonicalises a profile from the first domain in your goal: 'collaborator.pro' → profile 'collaborator', 'cp.adsy.com' → 'adsy', 'gogetlinks.net' → 'gogetlinks'. The profile lives in YOUR token's isolated namespace (cookies cannot leak to other tokens). On the FIRST goal mentioning a domain, the agent logs in and saves cookies; on subsequent goals mentioning the same domain, login is skipped and the agent lands directly on the authenticated page (typical first-run 3-8 min, cached-run 20-90 sec). Response includes metadata.profile so you can see exactly which profile was chosen. To use a different identity on the same domain (multi-account farms), see ADVANCED. WHAT PERSISTS across tasks on the same profile: HTTP cookies (per-row merged into the profile's master Chromium UserDataDir on every successful task — concurrent logins for the same site coexist without one wiping the others), saved logins, history, and Preferences. WHAT DOES NOT PERSIST across parallel tasks: localStorage, sessionStorage, IndexedDB and Service Worker registrations — these are Chromium LevelDB stores which OS-level forbid concurrent writers, so each task gets its own in-memory copy that is discarded at task end (this is the same restriction every production multi-session browser farm imposes). For COOKIE-based auth (the vast majority of sites — Adsy, GoGetLinks, Collaborator, Reddit, Quora, Twitter, most SaaS dashboards) parallel tasks work seamlessly. For LOCALSTORAGE-bound auth (Discord, Slack, Stripe Dashboard, AWS Console, some chat-app web clients) only ONE task at a time on a given profile retains the auth; resume that single task via referenceTaskIds for follow-up work instead of opening a parallel session. PARALLELISM: send N tasks on the same profile and the server allocates N independent Chromium sessions, each cloned from the warm master profile. Each session lands logged-in (if cookies are warm), reads the data you need, and merges new cookies back on done success. Failed/canceled tasks do NOT pollute master cookies. Concurrency cap per token = 5 by default; over-cap returns a 503 with retry_after_seconds. === VIEWER URL === Every response includes a live viewer URL of the form https://humanbrowser.cloud/a/s_<id>?k=<key>, returned as metadata.viewer_url and as the first artifact. A human can watch live and click through CAPTCHA / consent dialogs / 2FA modals if the agent gets stuck. Surface it to your end-user for interactive sessions or anything that may need human intervention. === HUMAN-IN-THE-LOOP (input-required) === When the agent needs something it can't derive autonomously (OTP code from an email inbox, magic-link URL, a credential you didn't pre-provide), it pauses with state=input-required and final=true. The SSE stream closes per A2A 1.0 spec; the task remains in the registry. Resume by sending a fresh message/send with message.referenceTaskIds=[taskId] and message.metadata.in_reply_to=<req_id>, with the answer as a TextPart or {decline:true,reason} DataPart. Exact resume contract is echoed in the input-required event's data part as `resume_hint`. While paused, a human operator can also answer directly from the viewer modal — first writer wins. Server-side timeout (default 300s, max 1800s) auto-declines. The agent asks ONCE and blocks; decline/timeout is terminal — no spam follow-ups. === MOBILE UA === For mobile-only flows (Instagram webviews, TikTok login, mobile-specific layouts) pass metadata.mobile_ua=true on message/send. Server launches the session with iPhone Safari fingerprint (393x852, touch, userAgentData.mobile=true). Default is desktop Chrome. Fixed at spawn time. === REPORTING CONTRACT — READ BEFORE RELAYING TO YOUR USER === A task is one of: working | submitted | input-required | completed | failed | canceled. ONLY the last four are terminal. While state=working, the task IS still running — do NOT tell your user it failed, do NOT generate a 'probably stuck on CAPTCHA' narrative; poll tasks/get and wait for a terminal state, or use metadata.callback_url for push delivery. Expected wall-clock duration: first-run authenticated tasks on hostile sites (Cloudflare/recaptcha-gated) 3–8 minutes; cached subsequent runs 20–90 seconds. status.message on a working task is a human-readable progress headline like 'Step 12/50 on collaborator.pro — Submit the goodmenproject.com search'. Quote it verbatim to your user; do not paraphrase or interpret. On terminal=failed, tasks/get attaches metadata.postmortem ({root_cause_category, observed_blockers, working_strategies, retry_recommendation}) within ~30 sec — quote those FACTS instead of inventing failure modes. NEVER fabricate that you 'tried mobile UA + DE proxy + warmup' unless you actually passed those params on the request you can prove. === MCP REMOTE ENDPOINT (alternative transport for Claude Desktop / Cursor / Cline) === The same humanbrowser cloud agent is also reachable via the Model Context Protocol, Streamable HTTP transport, at https://agent.humanbrowser.cloud/mcp. Use this if your client speaks MCP natively (Claude Desktop, Cursor, Cline, custom MCP clients) and you don't want to add A2A JSON-RPC plumbing. Auth: same hb_live_* token, sent as Authorization: Bearer <token>. Same billing, same per-token sticky-profile semantics. Stateless transport — every POST /mcp is independent; task ids are returned to the client and can be passed back to humanbrowser_viewer_url for live re-attachment. Three tools are exposed: • humanbrowser_run(goal, country?, profile?) — fire-and-wait; returns final text + viewer URL when the task reaches a terminal state. • humanbrowser_stream(goal, country?, profile?) — same, but emits MCP notifications/progress while in flight. • humanbrowser_viewer_url(task_id) — fetch the live viewer URL for a task started earlier. Claude Desktop config snippet (claude_desktop_config.json): { "mcpServers": { "humanbrowser": { "url": "https://agent.humanbrowser.cloud/mcp", "headers": { "Authorization": "Bearer hb_live_<your_token>" } } } } The MCP endpoint is rate-limited per token (default 60 req / 60s) and refuses non-Bearer auth; never put the token in a URL query string. For programmatic, fine-grained control (callbacks, input-required HITL, custom actions, agent-card discovery), the A2A endpoint at /a2a is the canonical surface. === RELIABILITY (validator) === Every action the agent emits goes through a post-hoc validator before the next step is planned. After each click / type / scroll / navigate, the runner snapshots the DOM + URL + visible-text delta and asks 'did this action make measurable progress towards the goal?'. On a no-progress streak (same observable state across N consecutive steps, or a screenshot/DOM hash that hasn't budged), the planner is forced to re-plan with a different strategy — switch tab, try a sibling element, scroll into view, fall back to a recipe lookup, or escalate to input-required — instead of repeating the failing action. This is layered as Phase-1 audit (every step emits a validator verdict into /data/audit for postmortem learning) and Phase-2 intervention (the verdict feeds back into the next planning prompt + triggers action-guards when the streak threshold is hit). Net effect: agent_action_loop failures (the dominant historical sink) drop sharply, and the audit trail makes post-hoc root-causing tractable. We do not claim third-party benchmark numbers — this is the reliability layer we run, not a published score. === ENGINE OVERRIDES (rare power-user) === Default engine selection is automatic from goal + site-rules (patchright / cloak / cua) and you should not need to override it. One exception worth knowing: `metadata.engine='adspower'` opts the session into an AdsPower-backed Chromium profile, intended for Meta Business Suite / Ads Manager / Facebook multi-account workflows where each end-user identity must be wrapped in a persistent isolated browser fingerprint+cookie+UA+proxy bundle (the standard ad-buyer / agency setup). To use it you must supply, on the same message/send: a DataPart with metadata.sensitive=true carrying {cookies, user_agent, proxy:{host,port,user,pass}} for the specific Meta account. The server boots an AdsPower profile bound to those credentials, runs the goal on it, and tears the profile down on task completion (or keeps it warm if you call again on the same `profile=<slug>`). Surcharge: +$0.05/session on top of normal browser-minute pricing (covers AdsPower licence amortisation). Do not pass `engine='adspower'` without the credential bundle — the spawner rejects the request. Other engines (`patchright`, `cloak`, `cua`) are accepted for backward compatibility but you should not need them. === ADVANCED (rarely needed) === Power-user overrides on message/send.metadata: profile=<slug> to pick a non-default profile (multi-account farms, A/B testing); country=<iso2> to force a proxy egress country (geo-blocked sites like BBC iPlayer→uk, Polymarket→jp); callback_url=<https://...> for push delivery of the terminal task envelope instead of polling. Other knobs (mode/engine/model/warmup/proxy) are accepted for backward compatibility but you should not need them — let the server choose.

    ⚠ review A8.8 🔓 open 3 skills
  • Full-service digital marketing, web development, and AI agent readiness firm (McLean, VA, est. 2012). Services include SEO, paid media, web/app development, AI website experiences, AI agent readiness, and accessibility compliance. Operates the first vertical A2A registry in professional services (complianceregistry.net).

    A8.8 🔓 open 7 skills
  • TiEQi-A2A-GEO: China's first open A2A v1.0.1 agent. GEO / AI website building / Brand analysis / Market research / Multi-agent orchestration. 120 curated skills. 🇨🇳 中国首个开放式A2A v1.0.1 Agent,专注GEO优化(AI搜索引擎排名)、AI智能建站、品牌分析、市场调研。

    A8.8 🔓 open 119 skills
  • Specialized A2A agent for digital agencies - content, reporting, publishing, and swarm execution.

    A8.8 🔓 open 8 skills
  • Checks whether AI assistants (ChatGPT, Perplexity, Google AI Overviews) recommend a brand, and audits a site's readiness for AI agents. Free.

    A8.8 🔓 open JSONRPC 2 skills
  • Landing pointer card for ContrastAPI, the live product of ContrastCyber (an umbrella building products humans and AI agents use the same way — see provider). ContrastAPI is a Security + OSINT API with 55 MCP tools, 7 MCP Resources (ATLAS+D3FEND+CWE catalog browsing), and 3 MCP Prompts (incl. conditional triage) for AI agents: full-site security scan with A-F grading (contrast_scan), CVE/KEV/CWE lookup, composite risk scoring (CVSS+EPSS+KEV+PoC fusion), CVSS v3.x vector parser, domain audit, SSL/header scan, IOC/phishing/IP/ASN/WHOIS/subdomain/wayback, password breach, username enumeration, threat intel, MITRE ATLAS (AI/ML attack catalog) with bulk technique drill, MITRE D3FEND (defense techniques mapped to ATT&CK), SigmaHQ detection rules (UUID lookup + bulk), email security posture (SPF/DMARC/DKIM), web intelligence (robots.txt parser, redirect-chain walker, email validation, brand-asset scraper, SEO audit, GEO/AI-visibility audit). All execution interfaces are served by api.contrastcyber.com; the full agent card with the complete skill list is at https://api.contrastcyber.com/.well-known/agent-card.json

    A8.8 🔑 human key 8 skills
  • UnifAPI
    UnifAPI
    ● healthy

    Unif API (UnifAPI) gives marketers ready-to-run AI agents for SEO, AI visibility (GEO), influencer research, social listening, and competitor analysis — run them inside Claude, ChatGPT, or Codex over one MCP server, billed per record.

    A8.8 🔑 human key JSONRPC 220 skills
  • Machine Experience consultancy — strategy, advisory, training, and audit services that make web content readable by AI agents. Publisher of MX: The Intro, MX: The Handbook, and MX: The Protocols.

    A8.8 🔓 open 3 skills
  • Meet Kai helps business owners, lean teams, and agent runtimes plan marketing, audit gaps, create campaign work, run approval gates, and route phone leads to KaiCalls.

    A8.8 🔑 human key 5 skills
  • OrganiKPI helps SaaS and B2B companies dominate AI search through SEO, GEO, and AEO strategies.

    A8.8 🔓 open JSONRPC 3 skills
  • Seoul apartment market-timing agent: grades all 25 districts bottom/top from official MOLIT actual-transaction records (700k+ closings since 2016, volume-weighted price per pyeong).

    A8.8 🔓 open JSONRPC 3 skills
  • An AI agent grounded in Joost de Valk's published writing and talks — covering SEO, WordPress, the open web, AI, open source, and his investment portfolio at Emilia Capital. Ask questions in natural language and receive cited answers drawn from a semantic index of his blog posts and video transcripts.

    A8.8 🔓 open 2 skills
  • Read-only agent that answers natural-language questions about The Website Specification — a platform-agnostic checklist of what a good website does. Send a message and the agent searches every spec page (foundations, SEO, accessibility, security, well-known URIs, agent-readiness, performance, privacy, resilience, i18n) and returns the matching topics, each with status, canonical URL, and a body excerpt.

    A8.8 🔓 open 3 skills
  • AI-agent-readiness scanner. Given a URL, returns a graded report across 33 checks (llms.txt, schema, agent-card, robots for AI bots, and more).

    A8.8 🔓 open 1 skill
  • Lexicon is a Multi-Industry Comparison Intelligence Engine that retrieves live evidence from up to 20 independent web sources and applies structured analytical frameworks to produce doctoral-grade, evidence-backed verdicts. Designed for autonomous enterprise research swarms. Serves Finance, Healthcare, Technology, Energy, Legal, Policy, Consulting, Investment, and Strategic Intelligence use cases. All output is structured, citation-rich, and verdict-confident.

    D3.4 🔓 open 7 skills
  • APIMesh
    APIMesh
    ● degraded

    uptime_30d 1.0; p95 347.7ms

    D3.1 🔓 open 82 skills
  • OracleNet is a mesh capability router for autonomous agents — not a product, not a marketplace, not a tool list. Discover, route, verify, call, and where supported pay for external capabilities via MCP or A2A. Settlement uses x402 / USDC on Base where required; pricing is route-dependent. Live mesh snapshot: https://tooloracle.io/.well-known/agent-pulse.

    E1.8 ⚡ agent-pays · x402 9 skills
  • Paid x402 API tools for AI agents, settled in USDC on Solana. Crypto pre-trade safety (Solana SPL rug/honeypot checks, EVM+Solana token safety, one-call GO/NO-GO pre-trade verdicts, full token dossiers), market data (Polymarket prediction-market odds), official verification (GLEIF LEI KYB, EU sanctions/AML screening), and x402 agent discoverability (Bazaar keyword-rank pulse and signed visibility audits). Real-time, structured, machine-readable verdicts. No API key — payment is authentication. Gasless for the buyer (the facilitator is fee payer).

    E1.8 🔓 open JSONRPC 10 skills