DARINORCold Lab

// Utilities

Tools

Small, self-contained utilities. They run in your browser whenever possible — your data never touches our server.

35 / 35 utilities

Encoding & Hashing

Password Generator

Generate strong, random passwords with tunable character classes and an entropy estimate.

Use →
Encoding & Hashing

Hash Generator

Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 digests in hex and base64.

Use →
Web & Networking

QR Code Generator

Turn any text or URL into a scannable QR code and download it as a PNG.

Use →
Text & Markdown

Unix Timestamp Converter

Convert between Unix timestamps, ISO 8601, UTC, and local time.

Use →
Text & Markdown

Word & Character Counter

Count words, characters, sentences, paragraphs, and reading time live.

Use →
Text & Markdown

Number Base Converter

Convert numbers between binary, octal, decimal, and hexadecimal.

Use →
Text & Markdown

Text Diff Checker

Compare two blocks of text or code side by side, line by line.

Use →
JSON

JSON Formatter

Format, minify, and validate JSON with line-and-column errors.

Use →
JSON

JSON Schema Validator

Validate a JSON document against a JSON Schema, with every violation and its exact path.

Use →
JSON

JSON Diff

Compare two JSON documents semantically — every added, removed, or changed value with its exact path.

Use →
Text & Markdown

Cron Parser

Describe a cron expression in plain English and preview next run times.

Use →
Text & Markdown

Regex Tester

Test JavaScript regex patterns with live highlighting and capture groups.

Use →
Encoding & Hashing

UUID Generator

Generate UUID v4 identifiers in bulk, with case and format options.

Use →
Text & Markdown

PDF to Markdown

Convert a PDF file to Markdown right in your browser. No upload, no server.

Use →
Encoding & Hashing

JWT Decoder

Decode a JSON Web Token's header and payload, with a warning on unsigned alg: none tokens.

Use →
Encoding & Hashing

Encode / Decode Toolkit

Base64, URL, hex, and ROT13 — encoded and decoded side by side, plus an auto-decode chain for stacked/layered encoding.

Use →
Encoding & Hashing

Hash Identifier

Identify a hash by shape, or generate SHA-1/256/384/512 digests from text.

Use →
Security Analysis

CVSS Calculator

Compute a CVSS v3.1 base score, severity rating, and vector string.

Use →
Text & Markdown

Markdown Preview

Write CommonMark and see it rendered live, then copy the generated HTML.

Use →
Text & Markdown

Markdown to JSON

Parse Markdown into a structured JSON tree (mdast AST) of typed nodes.

Use →
MCP & Agents

MCP Tool Schema Linter

Check an MCP Tool definition against the spec — required fields, schema constraints, and annotation hints.

Use →
Security Analysis

Prompt Injection Tester

Audit a system prompt against six known prompt-injection technique categories, with hardening suggestions for every gap.

Use →
MCP & Agents

AI Agent Config Checker

Scan an agent config (.mcp.json, .claude/settings.json, system prompt) for leaked secrets, over-broad permissions, and injection-prone content.

Use →
MCP & Agents

MCP Server Probe

Send a standard MCP initialize handshake to an endpoint and see what it reveals: server identity, exposed tools, auth requirements.

Use →
MCP & Agents

MCP Config Generator

Paste an MCP server URL or package name and get ready-to-paste config blocks for Claude Desktop, Cursor, Cline, Zed, and Windsurf.

Use →
MCP & Agents

Agent Config Diff

Compare two versions of an agent config and see what drifted: added or removed MCP servers, version pin changes, permission changes, env additions.

Use →
MCP & Agents

MCP Supply Chain Checker

Scan an MCP config for unpinned versions, auto-install flags, mutable sources, secrets in env blocks, and standing authorizations.

Use →
Security Analysis

MITRE ATT&CK Explorer

Search and browse the MITRE ATT&CK Enterprise knowledge base — techniques, tactics, platforms, and sub-techniques.

Use →
Security Analysis

Subnet / CIDR Calculator

Calculate network address, broadcast address, usable host range, and subnet mask from an IPv4 CIDR block, and split a network into subnets.

Use →
Security Analysis

X.509 Certificate Decoder

Decode a PEM certificate's subject, issuer, validity, SANs, key usage, and fingerprints in your browser.

Use →
Security Analysis

Email Header Analyzer

Trace an email's Received hop chain and read its SPF, DKIM, and DMARC authentication results from raw headers.

Use →
JSON

YAML / TOML / JSON Converter

Convert between YAML, TOML, and JSON with auto-detected source format — for agent configs, CI files, and MCP manifests.

Use →
Security Analysis

CSP Header Analyzer

Audit a Content-Security-Policy header for unsafe-inline, unsafe-eval, wildcard sources, and missing hardening directives.

Use →
Security Analysis

IOC Extractor

Extract IPs, domains, hashes, emails, and CVEs from threat-intel text — free, in-browser, no upload.

Use →
Security Analysis

STRIDE Threat Model Worksheet

Model a design's components and get a per-element STRIDE checklist — Spoofing, Tampering, Repudiation, Info disclosure, DoS, and Elevation of privilege.

Use →

// More tools

Need more tools? toolsforweb.com — a side project with 50+ free browser utilities for everyday work: converters, calculators, encoders, formatters.