ScanLabsAI Security Scanner
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Sollte ich dies verwenden
Qualität und Sicherheit
Befunde (2)
- HIGH
- MEDIUMin check_credits
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"scanner": {
"command": "npx",
"args": [
"@scanlabsai/mcp-server"
]
}
}
}Ausführbare Pakete
1.0.0stdioRemote-Endpunkte
https://scanlabsai.com/api/mcpstreamable-httpWas es kann
Tool-Inventar
Tools (8)
🟡scan_website(url, deep)
Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.
Eingabe-Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The website URL to scan, e.g. https://example.com"
},
"deep": {
"type": "boolean",
"description": "Run a deep scan (comprehensive, slower). Defaults to false."
}
},
"required": [
"url"
]
}⚪scan_agent(kind, endpoint, apiKey, model, deep)
Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind="openai" for an OpenAI-compatible chat-completions endpoint, or kind="mcp" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.
Eingabe-Schema
{
"type": "object",
"properties": {
"kind": {
"type": "string",
"enum": [
"openai",
"mcp"
],
"description": "Target type: \"openai\" for a chat-completions endpoint, \"mcp\" for an MCP server."
},
"endpoint": {
"type": "string",
"description": "The agent endpoint URL (chat-completions URL, or MCP server URL)."
},
"apiKey": {
"type": "string",
"description": "Optional bearer token / API key the target agent requires. Sent to the target only; not stored."
},
"model": {
"type": "string",
"description": "Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini."
},
"deep": {
"type": "boolean",
"description": "Run deeper probes (jailbreak + resource-exhaustion). Defaults to false."
}
},
"required": [
"kind",
"endpoint"
]
}⚪compliance_report(url)
Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.
Eingabe-Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The website URL to assess for compliance, e.g. https://example.com"
}
},
"required": [
"url"
]
}🟢get_fix_guidance(issue)
Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.
Eingabe-Schema
{
"type": "object",
"properties": {
"issue": {
"type": "string",
"description": "The vulnerability, finding title, or CVE id to fix."
}
},
"required": [
"issue"
]
}⚪lookup_cves(keyword, limit)
Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.
Eingabe-Schema
{
"type": "object",
"properties": {
"keyword": {
"type": "string",
"description": "Optional keyword, e.g. \"wordpress\" or \"openssl\"."
},
"limit": {
"type": "number",
"description": "Max results (1-25). Defaults to 10."
}
}
}🟢get_pricing
Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.
Eingabe-Schema
{
"type": "object",
"properties": {}
}🟡check_credits
Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.
Eingabe-Schema
{
"type": "object",
"properties": {}
}🟢buy_credits(pack)
Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).
Eingabe-Schema
{
"type": "object",
"properties": {
"pack": {
"type": "string",
"description": "Pack id: starter, pro, or agency. Defaults to pro."
}
}
}Community
Nachweis