ScanLabsAI Security Scanner

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

¿Debería usar esto?

Calidad y seguridad

A
Calidad de la descripción
98%
Integridad del esquema
80%
Calidad de los nombres
88%
Riesgo de envenenamiento
80%
Coincidencia de permisos
100%
Cumplimiento del protocolo
100%

Hallazgos (2)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains URL to non-standard domainen check_credits

Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.

Costo de contexto

~1,046Tokens (definiciones de herramientas)
~609 BTamaño de respuesta típico
Impacto moderado en la atención (0.82% del contexto de 128k)

Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.

Instalar

Instalación con un clic

Agrega esto a tu archivo `claude_desktop_config.json`:

{
  "mcpServers": {
    "scanner": {
      "command": "npx",
      "args": [
        "@scanlabsai/mcp-server"
      ]
    }
  }
}

Paquetes ejecutables

npm@scanlabsai/mcp-server1.0.0stdio

Puntos de conexión remotos

https://scanlabsai.com/api/mcpstreamable-http

Qué puede hacer

Inventario de herramientas

Herramientas (8)

🟢 Solo lectura🟡 Escritura🔴 Eliminación⚪ Desconocido
🟡scan_website(url, deep)

Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The website URL to scan, e.g. https://example.com"
    },
    "deep": {
      "type": "boolean",
      "description": "Run a deep scan (comprehensive, slower). Defaults to false."
    }
  },
  "required": [
    "url"
  ]
}
⚪scan_agent(kind, endpoint, apiKey, model, deep)

Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind="openai" for an OpenAI-compatible chat-completions endpoint, or kind="mcp" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "kind": {
      "type": "string",
      "enum": [
        "openai",
        "mcp"
      ],
      "description": "Target type: \"openai\" for a chat-completions endpoint, \"mcp\" for an MCP server."
    },
    "endpoint": {
      "type": "string",
      "description": "The agent endpoint URL (chat-completions URL, or MCP server URL)."
    },
    "apiKey": {
      "type": "string",
      "description": "Optional bearer token / API key the target agent requires. Sent to the target only; not stored."
    },
    "model": {
      "type": "string",
      "description": "Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini."
    },
    "deep": {
      "type": "boolean",
      "description": "Run deeper probes (jailbreak + resource-exhaustion). Defaults to false."
    }
  },
  "required": [
    "kind",
    "endpoint"
  ]
}
⚪compliance_report(url)

Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The website URL to assess for compliance, e.g. https://example.com"
    }
  },
  "required": [
    "url"
  ]
}
🟢get_fix_guidance(issue)

Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "issue": {
      "type": "string",
      "description": "The vulnerability, finding title, or CVE id to fix."
    }
  },
  "required": [
    "issue"
  ]
}
⚪lookup_cves(keyword, limit)

Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "description": "Optional keyword, e.g. \"wordpress\" or \"openssl\"."
    },
    "limit": {
      "type": "number",
      "description": "Max results (1-25). Defaults to 10."
    }
  }
}
🟢get_pricing

Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.

Esquema de entrada

{
  "type": "object",
  "properties": {}
}
🟡check_credits

Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.

Esquema de entrada

{
  "type": "object",
  "properties": {}
}
🟢buy_credits(pack)

Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).

Esquema de entrada

{
  "type": "object",
  "properties": {
    "pack": {
      "type": "string",
      "description": "Pack id: starter, pro, or agency. Defaults to pro."
    }
  }
}

Comunidad

Califica este servidor

Evidencia

Observaciones recientes

verificadoversión no registrada8 herramientas
verificadoversión no registrada8 herramientas