security.txt
LiveWho to email when you find a hole — RFC 9116.
Fetches /.well-known/security.txt then /security.txt. SSRF-guarded.
Server URL
https://toolcargo.com/mcp/security-txtClaude Code
claude mcp add --transport http --scope user toolcargo-security-txt https://toolcargo.com/mcp/security-txt \
--header "Authorization: Bearer YOUR_API_KEY"Create a key in your dashboard. Other clients: setup guides.
What it helps you do
- Contact, Expires, Policy if present
Built for: Agencies checking a client's disclosure contact.
Example requests
Disclosure
“Inspect security.txt for client.com with ToolCargo.”
Contact: mailto:…
Step-by-step workflows: pre-launch check · fixing link previews
Tools
| Tool | What it does | Access |
|---|---|---|
inspect_security_txtInspect security.txt | Fetch /.well-known/security.txt (then /security.txt) with the Site Audit SSRF guard. | Read-only |
Requirements
- • A ToolCargo account with Site Audit activated (free).
Limitations
- • Does not validate the Expires date against a PKI.
Supported clients
“Tested” means we connected that client to this endpoint and ran a tool call ourselves. “Documented” means the client supports this setup per its own docs, but we have not tested it yet.
| Claude Code | API key header | Tested | Remote HTTP server with an Authorization header. Tested 2026-09-11 (v2.1.268). |
| Claude (claude.ai) | OAuth sign-in | Tested | Custom connector with OAuth sign-in; tested on claude.ai web 2026-09-11. Desktop and mobile use the same account connectors but were not tested separately. |
| Cursor | API key header | Documented, not yet tested | mcp.json with url and headers. |
| VS Code (Copilot agent mode) | API key header | Documented, not yet tested | .vscode/mcp.json with type http and headers. |
| ChatGPT (developer mode) | OAuth sign-in | Documented, not yet tested | Requires OAuth; API keys cannot be entered. |
| MCP Inspector | API key header | Tested | CLI mode, tested 2026-09-11. Useful for calling tools directly. |
More in SEO
- DNS & email auth LiveSPF, DMARC, MX and DKIM lookups before a client domain goes live.
- Domain lookup LiveRegistrar, nameservers and expiry from public RDAP.
- HTTP headers LiveHSTS, CSP, cookies flags — what the server actually sends.
- Page Watch LiveScheduled re-checks that tell you when a page's indexability changes.
Pricing
Free
$0For trying the connector on your own sites.
50 calls/month · 25 links per check
Pro
$12/moFor freelancers and agencies auditing client sites every week.
2,000 calls/month · 100 links per check
Proposed test price. See the pricing page for checkout status.