IA-QA — 130+ QA & Dev Tools for AI Agents
REMOTE · WWW.IA-QA.COM · SCANNED AUG 3
130+ QA & dev tools for AI agents: prompt injection, RAG testing, VLM eval, guardrails. Free.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability70
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 20450 tokens (~136/item across 150 items; 150 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · www.ia-qa.com
claude mcp add --transport http jcjamet-ia-qa-toolbox https://www.ia-qa.com/mcp
[mcp_servers.jcjamet-ia-qa-toolbox] url = "https://www.ia-qa.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"jcjamet-ia-qa-toolbox": {
"type": "remote",
"url": "https://www.ia-qa.com/mcp",
"enabled": true
}
}
} openclaw mcp add jcjamet-ia-qa-toolbox --url https://www.ia-qa.com/mcp --transport streamable-http
mcp_servers:
jcjamet-ia-qa-toolbox:
url: "https://www.ia-qa.com/mcp" {
"mcpServers": {
"jcjamet-ia-qa-toolbox": {
"type": "http",
"url": "https://www.ia-qa.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 0
- Tool “analyze_diff_bugs” rewrote its description, which is the text the model reads security
- Tool “run_pr_gate_pipeline” rewrote its description, which is the text the model reads security
- “find_tool” added an optional parameter “max_results” cosmetic
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 69
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://www.ia-qa.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=www.ia-qa.com | CN=YR1,O=Let's Encrypt,C=US | 11 Jun 2026 | 9 Sept 2026 | RSA 2048 | SHA256-RSA | 6b2b8b5f2547d58014f06ba311ff41342ce |
| SANs: www.ia-qa.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC secure
Validation of www.ia-qa.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| ia-qa.com. | present | 52852 | 8 | Verified |
| www.ia-qa.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;img-src 'self' data: blob: https:;font-src 'self' https://fonts.gstatic.com data:;connect-src 'self' https: wss: http://localhost:11434 data:;media-src 'self' blob:;object-src 'none';frame-ancestors 'self';base-uri 'self';form-action 'self';script-src-attr 'none';upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | no-referrer |
| permissions-policy | camera=(), microphone=(), geolocation=(), payment=(), usb=(), display-capture=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://www.ia-qa.com/mcp | Verified | 200 | |
| http (plaintext) | http://www.ia-qa.com/mcp | HTTPS enforced | 301 | https://www.ia-qa.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
unescape_html ~81
Convert HTML entities (&, <, >, ", ', and numeric &#NNN;) back to plain characters. Use when processing HTML-encoded text from APIs, email content, or legacy database fields before passing to an LLM or displaying to users.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | HTML-encoded string to unescape |
| Name | Type | Req | Description |
|---|---|---|---|
| unescaped | — | — | — |
No examples provided.
url_decode ~49
Decode a percent-encoded URL string back to plain text. Use when parsing query parameters from raw URLs or when displaying encoded values to users.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | URL-encoded string to decode |
| Name | Type | Req | Description |
|---|---|---|---|
| decoded | — | — | — |
No examples provided.
url_encode ~76
Percent-encode a string for safe use in URLs. Call this before programmatically building query strings, path segments, or form-encoded bodies to prevent injection and malformed URLs.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | String to URL-encode |
| mode | string | — | "component" (default) or "full" for encodeURI behavior |
| Name | Type | Req | Description |
|---|---|---|---|
| encoded | — | — | — |
No examples provided.
validate_agent_trajectory ~166
Run declarative assertions on an agent trace (OpenAI tool-call messages, LangChain run trees, or plain text logs). No LLM call — deterministic. Assertion types: order (tool A before B), must_call, must_not_call, max_calls, min_calls, no_error, recovery (agent continues after error). Returns per-assertion PASS/FAIL, parsed steps, and an overall verdict. Use this to gate CI/CD on agent behavior correctness.
| Name | Type | Req | Description |
|---|---|---|---|
| assertions | array | yes | List of assertions to validate against the trace. |
| format | string | — | Trace format. auto (default) detects automatically. |
| trace | — | yes | Agent execution trace as JSON (OpenAI messages array, LangChain run tree) or plain text log (Thought/Action/Observation format). |
| Name | Type | Req | Description |
|---|---|---|---|
| assertions | array | — | — |
| failed | number | — | — |
| passed | number | — | — |
| steps | array | — | — |
| total | number | — | — |
| verdict | string | — | — |
No examples provided.
validate_email ~63
Validate an email address against RFC 5322 syntax before storing it, sending a transactional email, or adding it to a mailing list. Returns { valid, email } — use this to avoid bounces and malformed data.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Email address to validate |
| Name | Type | Req | Description |
|---|---|---|---|
| — | — | — | |
| valid | boolean | — | — |
No examples provided.
validate_mcp_response ~225
Validate that an MCP tool response conforms to expected format, schema, and content rules. Use this to QA-test any MCP server tool. Supply the tool's actual JSON result and a set of checks to perform.
| Name | Type | Req | Description |
|---|---|---|---|
| actual_latency | number | — | Actual measured latency in ms (from the call) |
| expected_type | string | — | Expected top-level type: "object", "array", "string", "number" |
| forbidden_keys | string | — | Comma-separated list of keys that MUST NOT exist (e.g. "password, secret, token") |
| max_response_ms | number | — | Maximum acceptable latency in ms (will be compared if provided) |
| max_size_bytes | number | — | Maximum acceptable response size in bytes |
| min_items | number | — | If response is an array, minimum number of items expected |
| required_keys | string | — | Comma-separated list of keys that MUST exist in the response (dot-notation for nested: "data.id, data.name") |
| response | string | yes | The MCP tool result as a JSON string to validate |
| Name | Type | Req | Description |
|---|---|---|---|
| checks | — | — | — |
| failed | number | — | — |
| passed | number | — | — |
| total | number | — | — |
| verdict | string | — | — |
No examples provided.
validate_url ~47
Parse and validate a URL. Returns decomposed components: protocol, hostname, port, path, query parameters, hash, and origin.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | URL to validate and parse |
| Name | Type | Req | Description |
|---|---|---|---|
| full | — | — | — |
| hash | — | — | — |
| hostname | — | — | — |
| origin | — | — | — |
| pathname | — | — | — |
| port | — | — | — |
| protocol | — | — | — |
| query_params | — | — | — |
| search | — | — | — |
| valid | boolean | — | — |
No examples provided.
vector_quantize ~105
Simulate int8 or int4 quantization of float32 embedding vectors. Reduces storage by 4x (int8) or 8x (int4). Returns quantized values, scale factor, and precision loss (MSE). Useful for understanding vector DB compression trade-offs.
| Name | Type | Req | Description |
|---|---|---|---|
| bits | number | — | Quantization bits: 8 (int8, default) or 4 (int4) |
| vector | array | yes | Float32 vector to quantize |
| Name | Type | Req | Description |
|---|---|---|---|
| bits | — | — | — |
| compression_ratio | string | — | — |
| dimension | number | — | — |
| mse | number | — | — |
| offset | number | — | — |
| quantized | — | — | — |
| scale_factor | number | — | — |
| storage_bytes_float32 | — | — | — |
| storage_bytes_quantized | number | — | — |
No examples provided.
vector_similarity ~86
Compute similarity/distance between two float vectors: cosine similarity, dot product, Euclidean and Manhattan distance. Essential for vector DB relevance scoring, embedding evaluation, and nearest-neighbor testing.
| Name | Type | Req | Description |
|---|---|---|---|
| metric | string | — | Distance metric (default: all) |
| vector_a | array | yes | First vector as array of floats |
| vector_b | array | yes | Second vector as array of floats |
| Name | Type | Req | Description |
|---|---|---|---|
| cosine_distance | — | — | — |
| cosine_similarity | — | — | — |
| dimension | — | — | — |
| dot_product | — | — | — |
| euclidean_distance | — | — | — |
| interpretation | — | — | — |
| manhattan_distance | — | — | — |
| norm_a | — | — | — |
| norm_b | — | — | — |
No examples provided.
vector_stats ~105
Compute statistics for a float vector or matrix of vectors: mean, std, L2 norm, min, max, sparsity, top-K indices. Useful for debugging embedding quality and analyzing vector distributions in a vector DB.
| Name | Type | Req | Description |
|---|---|---|---|
| matrix | array | — | Matrix of vectors (overrides vector). Returns per-vector + matrix-level stats. |
| top_k | number | — | Return indices of top K absolute values (default: 5) |
| vector | array | — | Single vector to analyze |
| Name | Type | Req | Description |
|---|---|---|---|
| dimension | — | — | — |
| l2_norm | number | — | — |
| matrix_shape | array | — | — |
| matrix_stats | object | — | — |
| max | number | — | — |
| mean | number | — | — |
| min | number | — | — |
| per_vector | — | — | — |
| sparsity | number | — | — |
| std | number | — | — |
| top_k_indices | — | — | — |
No examples provided.
web_security_audit ~201
Run a comprehensive web security audit combining headers, SSL, CORS, and cookies checks — then use an LLM to produce a prioritised remediation plan. Orchestrates security_headers_check + ssl_certificate_check + cors_test + cookie_security_audit in parallel, merges all findings, then asks an AI model to: (1) rank vulnerabilities by real-world exploitability, (2) generate a remediation roadmap, (3) produce fix code snippets for the detected stack. Returns both raw audit data and the AI analysis. Use this as a one-click security posture assessment.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | — | Your Groq or HuggingFace API key. Required to enable AI analysis. |
| model | string | — | LLM model for AI analysis (default: "qwen/qwen3-32b"). Set to "none" to skip AI analysis. |
| url | string | yes | Full URL to audit (e.g. https://example.com) |
| Name | Type | Req | Description |
|---|---|---|---|
| cookies | array | — | — |
| cookies_found | number | — | — |
| details | — | — | — |
| fix | — | — | — |
| grade | — | — | — |
| header | — | — | — |
| headers_checked | number | — | — |
| httpOnly | — | — | — |
| issues | — | — | — |
| key | — | — | — |
| message | string | — | — |
| missing | — | — | — |
| missing_count | number | — | — |
| name | — | — | — |
| origins_tested | number | — | — |
| overall_grade | — | — | — |
| risk_level | — | — | — |
| sameSite | — | — | — |
| score | — | — | — |
| secure | — | — | — |
| tests | — | — | — |
| total_findings | number | — | — |
| url | — | — | — |
| value | — | — | — |
| weak | — | — | — |
| weak_count | number | — | — |
| weight | — | — | — |
No examples provided.
webhook_endpoint_create ~76
Create a temporary webhook endpoint that captures incoming HTTP requests for one hour. Returns the webhook id, public URL, expiration timestamp, and current request count. Use together with webhook_endpoint_requests to inspect captured payloads.
| Name | Type | Req | Description |
|---|---|---|---|
| base_url | string | — | Optional public base URL. Default: https://ia-qa.com/mcp/webhook |
| Name | Type | Req | Description |
|---|---|---|---|
| expires_at | string | — | — |
| id | — | — | — |
| request_count | number | — | — |
| retention_minutes | number | — | — |
| url | string | — | — |
No examples provided.
webhook_endpoint_requests ~78
Fetch the requests captured by a webhook created with webhook_endpoint_create. Returns the newest requests first with method, headers, query params, body payload, and timestamps.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Webhook id returned by webhook_endpoint_create |
| limit | number | — | Maximum number of requests to return (1-100, default: 20) |
| Name | Type | Req | Description |
|---|---|---|---|
| expires_at | string | — | — |
| id | string | — | — |
| request_count | number | — | — |
| requests | array | — | — |
No examples provided.
word_frequency ~111
Analyze word frequency in text. Returns top N words with counts and percentages. Supports English stopword filtering. Useful for content analysis, keyword extraction, and LLM output analysis.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | Text to analyze |
| min_length | number | — | Minimum word length to include (default: 3) |
| remove_stopwords | boolean | — | Remove common English stopwords (default: true) |
| top_n | number | — | Return top N words (default: 20, max: 200) |
| Name | Type | Req | Description |
|---|---|---|---|
| stopwords_removed | — | — | — |
| top_words | array | — | — |
| total_words | — | — | — |
| unique_words | number | — | — |
No examples provided.
xml_to_json ~108
Convert an XML string to a JSON object. Supports attributes, nested elements, arrays, CDATA, and namespaces. Options: parse numbers, parse booleans, ignore attributes.
| Name | Type | Req | Description |
|---|---|---|---|
| attr_prefix | string | — | Prefix for attribute keys (default: "@_") |
| ignore_attrs | boolean | — | Ignore XML attributes (default: false) |
| input | string | yes | XML string to convert |
| parse_values | boolean | — | Auto-parse numbers and booleans (default: true) |
| Name | Type | Req | Description |
|---|---|---|---|
| key_count | number | — | — |
| result | — | — | — |
No examples provided.
yaml_to_json ~102
Parse a YAML string and return the equivalent JSON value. The reverse of json_to_yaml. Supports nested objects, arrays, anchors, aliases, multi-document streams, and all scalar types. Use when processing config files, CI/CD pipeline definitions, or OpenAPI specs authored in YAML.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | YAML string to parse |
| multi | boolean | — | If true, parse all documents in a multi-document stream and return an array (default: false) |
| Name | Type | Req | Description |
|---|---|---|---|
| count | number | — | — |
| documents | — | — | — |
| json | — | — | — |
No examples provided.