Cyber Swiss Army Knife — Recipe Builder
Chain encoding, hashing, cipher, and analysis operations into a live recipe — a private, in-browser CyberChef alternative. Your data never leaves your device.
Know before you connect. Scan any Model Context Protocol server for a free A–F security grade — tool poisoning, prompt injection, auth and TLS, in seconds.
Live from the directory
The newest Model Context Protocol servers to pass through the scanner — grade, category and transport, newest first.
| Server | Grade | Scanned | ||
|---|---|---|---|---|
| Data360 MCP ServerSTREAMABLE_HTTP | Fgrade | STREAMABLE_HTTP | ||
| execution-evidence-labSTREAMABLE_HTTP | Fgrade | STREAMABLE_HTTP | ||
| mcp.careclinic.io/mcpSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| helpmyagentSTREAMABLE_HTTP | Cgrade | STREAMABLE_HTTP | ||
| LangSmith Traced OpenAI AgentSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| huggingface.co/mcpSTREAMABLE_HTTP | Fgrade | STREAMABLE_HTTP | ||
| IP Geolocation — Country, City, ISP, VPN DetectionSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| livedatalinkSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP |
Trending Now
Inspect and security-scan any Model Context Protocol server — the tools every AI agent now plugs into. Free, in-browser, no install.
Chain encoding, hashing, cipher, and analysis operations into a live recipe — a private, in-browser CyberChef alternative. Your data never leaves your device.
The research behind the grades
Verified 0-day research, CVE disclosures, and bug bounty after-actions — the independent security work that stands behind every grade we publish.
| Date | Finding | Signal | |
|---|---|---|---|
| Bug bounty | Stored XSS in Reporting PortalBug bounty | Severity: medium | |
| Research | Security Posture of Modern SPA RoutingResearch |
Interactive Suite
High-performance client-side security tools, encoders, and forensic utilities. Instant, offline-capable, and account-free.
Encode text to Base64 and Base64URL, and decode Base64 back to readable text with a hex view of the raw bytes — both directions, in your browser.
Turn an IPv4 CIDR block into network, broadcast, mask, host range, and usable host count.
Caesar, ROT13, Atbash, and Vigenère transforms plus letter-frequency analysis for CTF and puzzle solving.
Translate a cron expression into plain English and see the next run times, so you can verify a schedule before it ships.
Decode a PKCS#10 Certificate Signing Request (CSR) to verify its subject, public-key algorithm, and signature before you submit it to a CA.
Parse a CVSS 3.1 or 4.0 vector, expand every metric in plain English, and compute the 3.1 base score.

Syed Abrar — Cybersecurity Researcher, Penetration Tester & Full-Stack Engineer. Founder of AndraxPentester and builder of the SentinelReign ecosystem.
Technical Analysis
In-depth methodology teardowns, defense architecture, and threat intelligence.
Azure Blob Storage security checklist 2026 — Entra ID, RBAC, Shared Key hardening. Defensive guide from Andrax Pentester.
CTF writeup guide 2026 — write reasoning-first walkthroughs that teach, not flag dumps. From Andrax Pentester.
OSINT beginner guide 2026 — a legal, ethics-first methodology for open-source intelligence. From Andrax Pentester.
Andrax Pentester is not Android ANDRAX — we are a cybersecurity education site and MCP security grader at andraxpentester.in. Clear the name collision…
Tradecraft & Labs
Guided offensive walkthroughs calibrated with realistic time and bench difficulty.
Deep-dive technical tutorial on defeating multi-layered Android native anti-analysis mechanisms: from hooking libc file reads (/proc/self/maps) to ARM…
A masterclass on Windows kernel driver exploitation, IOCTL dispatching, BYOVD tradecraft, DKOM token stealing, and EDR callback array unhooking under…
Learn how to build and deploy an enterprise-grade Zero-Trust Sandbox Firewall for Model Context Protocol (MCP) servers in TypeScript. Prevent Indirect…
Taxonomy
Platform Vision
Continuous attack surface monitoring, AI-augmented vulnerability discovery, and automated triage.
Automated asset and service discovery
Web application security analysis workflows
API spec parsing and security checks
Professional security report generation
Scheduled and event-driven security workflows
Multi-user workspaces and role-based access