ScanLabsAI Security Scanner

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

사용해야 할까요

품질 및 안전성

A
설명 품질
98%
스키마 완전성
80%
이름 품질
88%
오염 위험
80%
권한 일치
100%
프로토콜 준수
100%

발견 사항 (2)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains URL to non-standard domaincheck_credits에서

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~1,046토큰 (도구 정의)
~609 B일반적인 응답 크기
중간 정도의 주의 영향 (128k 컨텍스트의 0.82%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "scanner": {
      "command": "npx",
      "args": [
        "@scanlabsai/mcp-server"
      ]
    }
  }
}

실행 가능한 패키지

npm@scanlabsai/mcp-server1.0.0stdio

원격 엔드포인트

https://scanlabsai.com/api/mcpstreamable-http

할 수 있는 일

도구 목록

도구 (8)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
🟡scan_website(url, deep)

Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.

입력 스키마

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The website URL to scan, e.g. https://example.com"
    },
    "deep": {
      "type": "boolean",
      "description": "Run a deep scan (comprehensive, slower). Defaults to false."
    }
  },
  "required": [
    "url"
  ]
}
⚪scan_agent(kind, endpoint, apiKey, model, deep)

Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind="openai" for an OpenAI-compatible chat-completions endpoint, or kind="mcp" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.

입력 스키마

{
  "type": "object",
  "properties": {
    "kind": {
      "type": "string",
      "enum": [
        "openai",
        "mcp"
      ],
      "description": "Target type: \"openai\" for a chat-completions endpoint, \"mcp\" for an MCP server."
    },
    "endpoint": {
      "type": "string",
      "description": "The agent endpoint URL (chat-completions URL, or MCP server URL)."
    },
    "apiKey": {
      "type": "string",
      "description": "Optional bearer token / API key the target agent requires. Sent to the target only; not stored."
    },
    "model": {
      "type": "string",
      "description": "Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini."
    },
    "deep": {
      "type": "boolean",
      "description": "Run deeper probes (jailbreak + resource-exhaustion). Defaults to false."
    }
  },
  "required": [
    "kind",
    "endpoint"
  ]
}
⚪compliance_report(url)

Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.

입력 스키마

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The website URL to assess for compliance, e.g. https://example.com"
    }
  },
  "required": [
    "url"
  ]
}
🟢get_fix_guidance(issue)

Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.

입력 스키마

{
  "type": "object",
  "properties": {
    "issue": {
      "type": "string",
      "description": "The vulnerability, finding title, or CVE id to fix."
    }
  },
  "required": [
    "issue"
  ]
}
⚪lookup_cves(keyword, limit)

Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.

입력 스키마

{
  "type": "object",
  "properties": {
    "keyword": {
      "type": "string",
      "description": "Optional keyword, e.g. \"wordpress\" or \"openssl\"."
    },
    "limit": {
      "type": "number",
      "description": "Max results (1-25). Defaults to 10."
    }
  }
}
🟢get_pricing

Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🟡check_credits

Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.

입력 스키마

{
  "type": "object",
  "properties": {}
}
🟢buy_credits(pack)

Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).

입력 스키마

{
  "type": "object",
  "properties": {
    "pack": {
      "type": "string",
      "description": "Pack id: starter, pro, or agency. Defaults to pro."
    }
  }
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 8개
검증됨버전이 기록되지 않음도구 8개