Malinois

Check a live app you own for public databases, leaked keys and exposed files.

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
100%
Vollständigkeit des Schemas
100%
Qualität der Benennung
80%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~824Tokens (Tool-Definitionen)
~2.7 KBTypische Antwortgröße
Mittlere Auswirkung auf die Aufmerksamkeit (0.64% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "scan": {
      "url": "https://malinois.app/mcp"
    }
  }
}

Remote-Endpunkte

https://malinois.app/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (2)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟢scan_app(url, i_own_this, lang)

Runs a passive, outside-in security check of a live web app and returns a letter grade (A–F), each issue in plain language with fix steps, and a report link. Use when the user asks whether their deployed app is safe, before launch, or after a redeploy to confirm a fix. It checks for publicly readable Supabase/Firebase data, secret keys (Stripe, OpenAI, Supabase service_role…) in client JavaScript, downloadable .env/.git files, source maps, permissive CORS and missing security headers. Do not use it for apps the user does not own or is not authorized to test, for localhost or private addresses, or to review source code — it only sees what the public URL serves. Behavior: sends ordinary GET requests like a browser (no login, exploitation or load testing); takes about 10–30 seconds; saves the result as a report page on malinois.app, linked in the response; secrets appear only masked. Each app can be checked at most 20 times per hour.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "maxLength": 500,
      "description": "Public http(s) address of the deployed app, e.g. https://my-app.lovable.app (scheme optional)."
    },
    "i_own_this": {
      "type": "boolean",
      "description": "Must be true. Set it only after the user has explicitly confirmed they own this app or are authorized to test it; without it the check is refused."
    },
    "lang": {
      "type": "string",
      "enum": [
        "en",
        "ko",
        "es",
        "ja",
        "pt",
        "fr",
        "de",
        "zh"
      ],
      "description": "Language for the explanations (default: en)."
    }
  },
  "required": [
    "url",
    "i_own_this"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "properties": {
    "grade": {
      "type": "string",
      "description": "A (best) to F"
    },
    "score": {
      "type": "number",
      "description": "0–100"
    },
    "host": {
      "type": "string"
    },
    "platform": {
      "type": [
        "string",
        "null"
      ],
      "description": "Detected builder/host, e.g. lovable, replit"
    },
    "limited": {
      "type": "boolean",
      "description": "True when the app exposed little to a passive check; a good grade is then not proof of safety."
    },
    "report_url": {
      "type": "string"
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "rule_id": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "enum": [
              "critical",
              "high",
              "medium",
              "low",
              "info"
            ]
          },
          "title": {
            "type": "string"
          },
          "what_it_means": {
            "type": [
              "string",
              "null"
            ]
          },
          "what_to_do": {
            "type": [
              "string",
              "null"
            ]
          },
          "evidence": {
            "type": [
              "string",
              "null"
            ],
            "description": "Masked evidence; secrets are never returned in full."
          }
        },
        "required": [
          "rule_id",
          "severity",
          "title"
        ]
      },
      "description": "Most serious first."
    }
  },
  "required": [
    "grade",
    "score",
    "host",
    "limited",
    "report_url",
    "findings"
  ]
}
🟢explain_finding(rule_id, lang)

Returns the plain-language meaning and step-by-step fix for one Malinois finding. Use it while helping the user fix an issue reported by scan_app, or when they ask what a finding means. Pass the rule_id exactly as scan_app returned it. Read-only, no network, instant.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "rule_id": {
      "type": "string",
      "description": "The rule_id of a finding, e.g. supabase_missing_rls"
    },
    "lang": {
      "type": "string",
      "enum": [
        "en",
        "ko",
        "es",
        "ja",
        "pt",
        "fr",
        "de",
        "zh"
      ],
      "description": "Language for the explanations (default: en)."
    }
  },
  "required": [
    "rule_id"
  ],
  "additionalProperties": false
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet2 Tools
verifiziertVersion nicht aufgezeichnet2 Tools