Cyber Swiss Army Knife — Recipe Builder
Chain encoding, hashing, cipher, and analysis operations into a live recipe — a private, in-browser CyberChef alternative. Your data never leaves your device.
Know before you connect. Scan any Model Context Protocol server for a free A–F security grade — tool poisoning, prompt injection, auth and TLS, in seconds.
Explore the work
Brand note: Andrax Pentester vs Android ANDRAX — same name, different projects.
Live from the directory
The newest Model Context Protocol servers to pass through the scanner — grade, category and transport, newest first.
| Server | Grade | Scanned | ||
|---|---|---|---|---|
| pinescriptSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| Financial ServicesSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| titan-storeSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| Data ConverterSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| squeezeosSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| HORIZON SHIELD KIRASTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| toolzy-mcpSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP | ||
| AEO ToolSTREAMABLE_HTTP | Agrade | STREAMABLE_HTTP |
Trending Now
Inspect and security-scan any Model Context Protocol server — the tools every AI agent now plugs into. Free, in-browser, no install.
Chain encoding, hashing, cipher, and analysis operations into a live recipe — a private, in-browser CyberChef alternative. Your data never leaves your device.
The research behind the grades
Verified 0-day research, CVE disclosures, and bug bounty after-actions — the independent security work that stands behind every grade we publish.
| Date | Finding | Signal | |
|---|---|---|---|
| Bug bounty | Stored XSS in Reporting PortalBug bounty | Severity: medium | |
| Research | Security Posture of Modern SPA RoutingResearch |
Interactive Suite
High-performance client-side security tools, encoders, and forensic utilities. Instant, offline-capable, and account-free.
Encode text to Base64 and Base64URL, and decode Base64 back to readable text with a hex view of the raw bytes — both directions, in your browser.
Turn an IPv4 CIDR block into network, broadcast, mask, host range, and usable host count.
Caesar, ROT13, Atbash, and Vigenère transforms plus letter-frequency analysis for CTF and puzzle solving.
Translate a cron expression into plain English and see the next run times, so you can verify a schedule before it ships.
Decode a PKCS#10 Certificate Signing Request (CSR) to verify its subject, public-key algorithm, and signature before you submit it to a CA.
Parse a CVSS 3.1 or 4.0 vector, expand every metric in plain English, and compute the 3.1 base score.

Syed Abrar — Cybersecurity Researcher, Penetration Tester & Full-Stack Engineer. Founder of AndraxPentester and builder of the SentinelReign ecosystem.
Technical Analysis
In-depth methodology teardowns, defense architecture, and threat intelligence.
Where Guard fits next to MCPGrade: grade vs gate, protocol-native enforcement for MCP tool calls, and how Andrax points to guard.sentinelreign.com wit…
Comprehensive 2026 hands-on security guide and pentesting masterclass on auditing OAuth 2.0 and OpenID Connect (OIDC) implementations. Learn PKCE bypa…
Point-in-time MCP grades find risk; runtime firewalls enforce policy on tool calls. Andrax mcpgrade-1.4.0 vs Guard mcpgrade-2.0.0 — no score equating.
Azure Blob Storage security checklist 2026 — Entra ID, RBAC, Shared Key hardening. Defensive guide from Andrax Pentester.
Tradecraft & Labs
Guided offensive walkthroughs calibrated with realistic time and bench difficulty.
Hands-on red team guide to auditing and exploiting AI agents in 2026. Covers indirect prompt injection, EchoLeak markdown exfiltration, MCP tool descr…
Master Cross-Site WebSocket Hijacking (CSWSH) in 2026. Explore HTTP/1.1 upgrade mechanics, Origin header bypasses, token leakage via query params, wea…
Master production eBPF kernel security programming in C and Rust. Learn BPF CO-RE, LSM hooks, ring buffers, libbpf loaders, Aya, and anti-evasion tech…
Taxonomy
Platform Vision
Continuous attack surface monitoring, AI-augmented vulnerability discovery, and automated triage.
Automated asset and service discovery
Web application security analysis workflows
API spec parsing and security checks
Professional security report generation
Scheduled and event-driven security workflows
Multi-user workspaces and role-based access