Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Inferido de los transportes que declara este listado (streamable-http). Que un cliente no aparezca aquí no significa que se haya descartado: simplemente Forge no puede confirmarlo.
La verificación confirma la identidad del publicador (la propiedad del repo), no la seguridad del código. El análisis de seguridad cubre los CVE conocidos y los scripts de instalación sospechosos.
Leído de un handshake MCP real initialize → tools/list contra el endpoint declarado. No se invocó ninguna herramienta: tools/list es la llamada de introspección de solo lectura que el protocolo define para esto. Refleja lo que el servidor anunciaba en ese momento; un endpoint alojado no está fijado a ninguna versión y puede cambiar sin avisar.
https://scanlabsai.com/api/mcp8 herramientas · 152 msscan_websiteRun a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep…Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep…
url: Links to undeclared domain: example.com| Parámetro | Tipo | Descripción |
|---|---|---|
| url* | string | The website URL to scan, e.g. https://example.com |
| deep | boolean | Run a deep scan (comprehensive, slower). Defaults to false. |
scan_agentRed-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. T…Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. T…
| Parámetro | Tipo | Descripción |
|---|---|---|
| kind* | string | Target type: "openai" for a chat-completions endpoint, "mcp" for an MCP server. |
| endpoint* | string | The agent endpoint URL (chat-completions URL, or MCP server URL). |
| apiKey | string | Optional bearer token / API key the target agent requires. Sent to the target only; not stored. |
| model | string | Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini. |
| deep | boolean | Run deeper probes (jailbreak + resource-exhaustion). Defaults to false. |
compliance_reportGenerate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recom…Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recom…
url: Links to undeclared domain: example.com| Parámetro | Tipo | Descripción |
|---|---|---|
| url* | string | The website URL to assess for compliance, e.g. https://example.com |
get_fix_guidanceGet detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.
| Parámetro | Tipo | Descripción |
|---|---|---|
| issue* | string | The vulnerability, finding title, or CVE id to fix. |
lookup_cvesLook up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.
| Parámetro | Tipo | Descripción |
|---|---|---|
| keyword | string | Optional keyword, e.g. "wordpress" or "openssl". |
| limit | number | Max results (1-25). Defaults to 10. |
get_pricingGet ScanLabsAI pricing: the free-first-scan policy and AI credit packs.Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.
No se publicó ningún esquema de entrada para esta herramienta.
check_creditsCheck the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.
No se publicó ningún esquema de entrada para esta herramienta.
buy_creditsGet a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).
| Parámetro | Tipo | Descripción |
|---|---|---|
| pack | string | Pack id: starter, pro, or agency. Defaults to pro. |
8 de 8 herramientas publicaron una descripción.
Los nombres y descripciones de las herramientas los escribe el publicador y se muestran literalmente como texto inerte. Son las cadenas que un cliente MCP pasa al modelo, así que Forge las analiza en busca de patrones de inyección de prompts — cualquier hallazgo aparece junto al análisis de seguridad de arriba. «Privilegiada» es una coincidencia de palabra clave en el nombre de la herramienta, no una auditoría de lo que hace: un nombre inofensivo puede hacer cualquier cosa.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Los nombres enlazados abren el índice de Forge con todas las entradas que se observó que exponen esa herramienta. Ver todas las herramientas indexadas.
Esta entrada no publica ningún paquete de npm, así que Forge no tiene un árbol de dependencias para ella. Es una carencia de cobertura, no una afirmación de que no tenga dependencias.