ScanLabsAI Security Scanner

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
98%
Vollständigkeit des Schemas
80%
Qualität der Benennung
88%
Risiko der Vergiftung
80%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Befunde (2)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains URL to non-standard domainin check_credits

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~1,046Tokens (Tool-Definitionen)
~609 BTypische Antwortgröße
Mittlere Auswirkung auf die Aufmerksamkeit (0.82% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "scanner": {
      "command": "npx",
      "args": [
        "@scanlabsai/mcp-server"
      ]
    }
  }
}

Ausführbare Pakete

npm@scanlabsai/mcp-server1.0.0stdio

Remote-Endpunkte

https://scanlabsai.com/api/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (8)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
🟡scan_website(url, deep)

Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The website URL to scan, e.g. https://example.com"
    },
    "deep": {
      "type": "boolean",
      "description": "Run a deep scan (comprehensive, slower). Defaults to false."
    }
  },
  "required": [
    "url"
  ]
}
⚪scan_agent(kind, endpoint, apiKey, model, deep)

Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind="openai" for an OpenAI-compatible chat-completions endpoint, or kind="mcp" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "kind": {
      "type": "string",
      "enum": [
        "openai",
        "mcp"
      ],
      "description": "Target type: \"openai\" for a chat-completions endpoint, \"mcp\" for an MCP server."
    },
    "endpoint": {
      "type": "string",
      "description": "The agent endpoint URL (chat-completions URL, or MCP server URL)."
    },
    "apiKey": {
      "type": "string",
      "description": "Optional bearer token / API key the target agent requires. Sent to the target only; not stored."
    },
    "model": {
      "type": "string",
      "description": "Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini."
    },
    "deep": {
      "type": "boolean",
      "description": "Run deeper probes (jailbreak + resource-exhaustion). Defaults to false."
    }
  },
  "required": [
    "kind",
    "endpoint"
  ]
}
⚪compliance_report(url)

Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The website URL to assess for compliance, e.g. https://example.com"
    }
  },
  "required": [
    "url"
  ]
}
🟢get_fix_guidance(issue)

Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "issue": {
      "type": "string",
      "description": "The vulnerability, finding title, or CVE id to fix."
    }
  },
  "required": [
    "issue"
  ]
}
⚪lookup_cves(keyword, limit)

Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "description": "Optional keyword, e.g. \"wordpress\" or \"openssl\"."
    },
    "limit": {
      "type": "number",
      "description": "Max results (1-25). Defaults to 10."
    }
  }
}
🟢get_pricing

Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.

Eingabe-Schema

{
  "type": "object",
  "properties": {}
}
🟡check_credits

Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.

Eingabe-Schema

{
  "type": "object",
  "properties": {}
}
🟢buy_credits(pack)

Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "pack": {
      "type": "string",
      "description": "Pack id: starter, pro, or agency. Defaults to pro."
    }
  }
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet8 Tools
verifiziertVersion nicht aufgezeichnet8 Tools