Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Dedotto dai trasporti dichiarati da questo annuncio (streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Letto da un vero handshake MCP initialize → tools/list verso l’endpoint dichiarato. Nessuno strumento è stato invocato — tools/list è la chiamata di introspezione in sola lettura che il protocollo prevede a questo scopo. Riflette ciò che il server annunciava in quel momento; un endpoint ospitato non è vincolato ad alcuna versione e può cambiare senza preavviso.
https://scanlabsai.com/api/mcp8 strumenti · 152 msscan_websiteRun a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep…Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep…
url: Links to undeclared domain: example.com| Parametro | Tipo | Descrizione |
|---|---|---|
| url* | string | The website URL to scan, e.g. https://example.com |
| deep | boolean | Run a deep scan (comprehensive, slower). Defaults to false. |
scan_agentRed-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. T…Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. T…
| Parametro | Tipo | Descrizione |
|---|---|---|
| kind* | string | Target type: "openai" for a chat-completions endpoint, "mcp" for an MCP server. |
| endpoint* | string | The agent endpoint URL (chat-completions URL, or MCP server URL). |
| apiKey | string | Optional bearer token / API key the target agent requires. Sent to the target only; not stored. |
| model | string | Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini. |
| deep | boolean | Run deeper probes (jailbreak + resource-exhaustion). Defaults to false. |
compliance_reportGenerate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recom…Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recom…
url: Links to undeclared domain: example.com| Parametro | Tipo | Descrizione |
|---|---|---|
| url* | string | The website URL to assess for compliance, e.g. https://example.com |
get_fix_guidanceGet detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.
| Parametro | Tipo | Descrizione |
|---|---|---|
| issue* | string | The vulnerability, finding title, or CVE id to fix. |
lookup_cvesLook up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.
| Parametro | Tipo | Descrizione |
|---|---|---|
| keyword | string | Optional keyword, e.g. "wordpress" or "openssl". |
| limit | number | Max results (1-25). Defaults to 10. |
get_pricingGet ScanLabsAI pricing: the free-first-scan policy and AI credit packs.Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.
Per questo strumento non è stato pubblicato alcuno schema di input.
check_creditsCheck the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.
Per questo strumento non è stato pubblicato alcuno schema di input.
buy_creditsGet a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).
| Parametro | Tipo | Descrizione |
|---|---|---|
| pack | string | Pack id: starter, pro, or agency. Defaults to pro. |
8 strumenti su 8 hanno pubblicato una descrizione.
I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
I nomi collegati aprono l’indice Forge di tutte le voci osservate esporre quello strumento. Sfoglia tutti gli strumenti indicizzati.
Questa voce non pubblica alcun pacchetto npm, quindi Forge non ha un albero delle dipendenze per essa. È una lacuna di copertura, non l'affermazione che non abbia dipendenze.