com.scanlabsai/scanner

MCPcomunidaden línea
v1.0.0com.scanlabsaiUnknownActualizado hace 1 m

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

Estado del endpointen línea
comprobado hace 1 día · 324 ms
100 % de las últimas 6 comprobaciones llegaron a este endpoint
Funciona en
ClaudeCursorCopilotChatGPTGemini

Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.

Indexado automáticamente desde fuentes públicas. Aún sin verificar por su desarrollador en Forge.Reclamar este listado →
hace 1 mÚltima actualización
Paquete
Autorcom.scanlabsai
LicenciaUnknown
Versión1.0.0
Fuentemcp-registry
Estado de confianza
B
60/100Bueno
✓Listado en el índice de Forge+10/10
—Identidad del publicador verificada+0/30
→ Publicador: este listado no tiene ningún repositorio registrado, así que `forge publish` no puede verificar la propiedad de forma automática. Usa «Reclamar este listado» arriba — en Forge lo revisamos a mano.
—Verificación de dominio+0/10
→ Ahora mismo no está disponible para este tipo de listado: hoy la comprobación de dominio solo se ejecuta para paquetes publicados en npm, así que esta fila todavía no se puede conseguir aquí, sea lo que sea lo que haya alojado en el dominio.
✓Análisis de inyección de prompts · limpio+30/30
✓Análisis de ofuscación / exfiltración · limpio+20/20
EstadoIndexado por la comunidad
PublicadorSin verificar
FirmaSin firmar
Dominio—
Procedencia—
DependenciasSin auditar
Superficie de herramientas8 herramientas · ninguna privilegiada
Análisis de seguridad✓ Limpiovlive · hace 13 d¿Qué tan bien funciona este análisis?
PROMPTtool:scan_website#urlLinks to undeclared domain: example.com
PROMPTtool:compliance_report#urlLinks to undeclared domain: example.com
EvaluacionesNinguna
Indexado11 ago 2026

La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.

Herramientas

8 herramientas · ninguna privilegiada
Observado en vivo desde el endpoint del proveedor13d ago

Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.

  • https://scanlabsai.com/api/mcp8 herramientas · 152 ms
scan_websiteRun a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep…

Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep…

NOTAEn el parámetro url: Links to undeclared domain: example.com
ParámetroTipoDescripción
url*stringThe website URL to scan, e.g. https://example.com
deepbooleanRun a deep scan (comprehensive, slower). Defaults to false.
scan_agentRed-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. T…

Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. T…

ParámetroTipoDescripción
kind*stringTarget type: "openai" for a chat-completions endpoint, "mcp" for an MCP server.
endpoint*stringThe agent endpoint URL (chat-completions URL, or MCP server URL).
apiKeystringOptional bearer token / API key the target agent requires. Sent to the target only; not stored.
modelstringModel name for OpenAI-compatible endpoints, e.g. gpt-4o-mini.
deepbooleanRun deeper probes (jailbreak + resource-exhaustion). Defaults to false.
compliance_reportGenerate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recom…

Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recom…

NOTAEn el parámetro url: Links to undeclared domain: example.com
ParámetroTipoDescripción
url*stringThe website URL to assess for compliance, e.g. https://example.com
get_fix_guidanceGet detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.

Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.

ParámetroTipoDescripción
issue*stringThe vulnerability, finding title, or CVE id to fix.
lookup_cvesLook up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.

Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.

ParámetroTipoDescripción
keywordstringOptional keyword, e.g. "wordpress" or "openssl".
limitnumberMax results (1-25). Defaults to 10.
get_pricingGet ScanLabsAI pricing: the free-first-scan policy and AI credit packs.

Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.

No se publicó ningún esquema de entrada para esta herramienta.

check_creditsCheck the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.

Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.

No se publicó ningún esquema de entrada para esta herramienta.

buy_creditsGet a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).

Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).

ParámetroTipoDescripción
packstringPack id: starter, pro, or agency. Defaults to pro.

8 de 8 herramientas publicaron una descripción.

Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.

Acerca de

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

Palabras clave
mcp
Alternativas
Comparando superficies de herramientas…

Sin cobertura de dependencias

Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.

Temas

Relacionados en security