ScanLabsAI Security Scanner
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
¿Debería usar esto?
Calidad y seguridad
Hallazgos (2)
- HIGH
- MEDIUMen check_credits
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"scanner": {
"command": "npx",
"args": [
"@scanlabsai/mcp-server"
]
}
}
}Paquetes ejecutables
1.0.0stdioPuntos de conexión remotos
https://scanlabsai.com/api/mcpstreamable-httpQué puede hacer
Inventario de herramientas
Herramientas (8)
🟡scan_website(url, deep)
Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.
Esquema de entrada
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The website URL to scan, e.g. https://example.com"
},
"deep": {
"type": "boolean",
"description": "Run a deep scan (comprehensive, slower). Defaults to false."
}
},
"required": [
"url"
]
}⚪scan_agent(kind, endpoint, apiKey, model, deep)
Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind="openai" for an OpenAI-compatible chat-completions endpoint, or kind="mcp" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.
Esquema de entrada
{
"type": "object",
"properties": {
"kind": {
"type": "string",
"enum": [
"openai",
"mcp"
],
"description": "Target type: \"openai\" for a chat-completions endpoint, \"mcp\" for an MCP server."
},
"endpoint": {
"type": "string",
"description": "The agent endpoint URL (chat-completions URL, or MCP server URL)."
},
"apiKey": {
"type": "string",
"description": "Optional bearer token / API key the target agent requires. Sent to the target only; not stored."
},
"model": {
"type": "string",
"description": "Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini."
},
"deep": {
"type": "boolean",
"description": "Run deeper probes (jailbreak + resource-exhaustion). Defaults to false."
}
},
"required": [
"kind",
"endpoint"
]
}⚪compliance_report(url)
Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.
Esquema de entrada
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The website URL to assess for compliance, e.g. https://example.com"
}
},
"required": [
"url"
]
}🟢get_fix_guidance(issue)
Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.
Esquema de entrada
{
"type": "object",
"properties": {
"issue": {
"type": "string",
"description": "The vulnerability, finding title, or CVE id to fix."
}
},
"required": [
"issue"
]
}⚪lookup_cves(keyword, limit)
Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.
Esquema de entrada
{
"type": "object",
"properties": {
"keyword": {
"type": "string",
"description": "Optional keyword, e.g. \"wordpress\" or \"openssl\"."
},
"limit": {
"type": "number",
"description": "Max results (1-25). Defaults to 10."
}
}
}🟢get_pricing
Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.
Esquema de entrada
{
"type": "object",
"properties": {}
}🟡check_credits
Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.
Esquema de entrada
{
"type": "object",
"properties": {}
}🟢buy_credits(pack)
Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).
Esquema de entrada
{
"type": "object",
"properties": {
"pack": {
"type": "string",
"description": "Pack id: starter, pro, or agency. Defaults to pro."
}
}
}Comunidad
Evidencia