Skuuy MCP
13 privacy-first network, auth & web tools for AI agents — no API key, 60 req/min free.
- 1.0.0
- Version
- remote
- Transport
- 13
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 13 tools scanned
- metadata: scanned
No findings.
Tools (13)
skuuy_get_egress_ip
Returns the caller's public egress IP address with geolocation, ASN/ISP, and datacenter/proxy detection. Use to verify which IP and country your traffic exits from, or to confirm a VPN/proxy is active. No parameters needed.
skuuy_list_proxies
Lists tested-live public proxies (HTTP/HTTPS/SOCKS4/SOCKS5) across 150+ countries, refreshed every 30 minutes. Filter by protocol, country, anonymity tier (L1 Elite = no forwarding headers, L2 Anonymous, L3 Transparent), and max latency. Each entry includes last_checked so you can judge freshness. Free public proxies are inherently unreliable — always implement retry/fallback.
skuuy_generate_totp
Generates a time-based one-time password (RFC 6238 TOTP) from a base32 secret. PRIVACY: the secret is processed ephemerally in memory, never logged or stored. By sending the secret you opt in to server-side generation (the browser vault at 2fa.skuuy.com remains the zero-knowledge alternative). Compatible with Google Authenticator / Authy / Microsoft Authenticator secrets.
skuuy_create_temp_inbox
Creates a disposable email inbox for sign-ups and verifications. Inbox self-destructs after TTL (default 30 minutes). Pair with skuuy_read_inbox to poll incoming mail and auto-extracted OTP codes.
skuuy_read_inbox
Reads messages in a temp inbox created by skuuy_create_temp_inbox. Each message includes plain-text body and auto-extracted 4-8 digit OTP codes and action links (e.g. password-reset URLs) when detected. Poll this after triggering a verification email.
skuuy_resolve_dns
Resolves DNS records for a domain. Without 'locations', performs a single edge-resolver lookup. With 'locations', returns a propagation matrix across global edge PoPs (useful to verify DNS changes propagated worldwide). Supports A, AAAA, CNAME, MX, TXT, NS, SOA with DNSSEC validation status.
skuuy_check_ports
Checks whether common service ports are open (TCP connect) on a host. ABUSE GUARD: only a fixed allowlist of common ports may be tested (22 SSH, 80 HTTP, 443 HTTPS, 3306 MySQL, 5432 Postgres, 6379 Redis, 51820 WireGuard). Arbitrary port ranges are rejected. Strictly rate-limited. Intended for diagnosing your own deployments and firewall/NAT traversal — not for scanning third parties.
skuuy_check_security_headers
Audits a URL's security posture: security headers (HSTS, CSP, X-Frame-Options, Permissions-Policy, etc.), full redirect chain, and TLS certificate health (issuer, expiry, days remaining). Use for pre-deploy checks or auditing any site's hardening.
skuuy_read_url
Fetches any public URL and returns clean markdown (ads, cookie banners, nav chrome, and script tags stripped; JS-rendered pages rendered best-effort). Privacy: zero-log, the fetch is not associated with you. Honest scope: soft paywalls and JS pages handled best-effort; hard anti-bot challenges (interactive CAPTCHA) are not bypassed.
skuuy_create_webhook_bin
Creates an ephemeral webhook-catcher URL (bin.skuuy.com/w/<id>) that records incoming HTTP requests with full headers and body. Point a third-party callback (Stripe, GitHub, your own API) at it while debugging, then inspect with skuuy_get_bin_requests. Auto-deleted after TTL.
skuuy_get_bin_requests
Lists HTTP requests captured by a webhook bin created with skuuy_create_webhook_bin: method, headers, query params, and body (truncated at 1 MB). Poll this after triggering the callback you are debugging (allow ~3-5 seconds for edge KV propagation).
skuuy_hash_encode
One-shot hashing/encoding utilities: SHA-256, SHA-512, Base64 encode/decode, UUID v4, and cryptographically random password generation. (MD5 included for legacy checksum verification only — do not use for security.)
skuuy_search_public_apis
Searches the Skuuy public API catalog. Call this FIRST when you are unsure which Skuuy tool fits your task — it returns matching tools with their MCP tool name, HTTP endpoint, and parameter summary.