Malinois

Check a live app you own for public databases, leaked keys and exposed files.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
100%
命名质量
80%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~824token 数(工具定义)
~2.7 KB典型响应大小
对注意力有中等影响(占 128k 上下文窗口的 0.64%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "scan": {
      "url": "https://malinois.app/mcp"
    }
  }
}

远程端点

https://malinois.app/mcpstreamable-http

它能做什么

工具清单

工具(2)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢scan_app(url, i_own_this, lang)

Runs a passive, outside-in security check of a live web app and returns a letter grade (A–F), each issue in plain language with fix steps, and a report link. Use when the user asks whether their deployed app is safe, before launch, or after a redeploy to confirm a fix. It checks for publicly readable Supabase/Firebase data, secret keys (Stripe, OpenAI, Supabase service_role…) in client JavaScript, downloadable .env/.git files, source maps, permissive CORS and missing security headers. Do not use it for apps the user does not own or is not authorized to test, for localhost or private addresses, or to review source code — it only sees what the public URL serves. Behavior: sends ordinary GET requests like a browser (no login, exploitation or load testing); takes about 10–30 seconds; saves the result as a report page on malinois.app, linked in the response; secrets appear only masked. Each app can be checked at most 20 times per hour.

输入模式

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "maxLength": 500,
      "description": "Public http(s) address of the deployed app, e.g. https://my-app.lovable.app (scheme optional)."
    },
    "i_own_this": {
      "type": "boolean",
      "description": "Must be true. Set it only after the user has explicitly confirmed they own this app or are authorized to test it; without it the check is refused."
    },
    "lang": {
      "type": "string",
      "enum": [
        "en",
        "ko",
        "es",
        "ja",
        "pt",
        "fr",
        "de",
        "zh"
      ],
      "description": "Language for the explanations (default: en)."
    }
  },
  "required": [
    "url",
    "i_own_this"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "grade": {
      "type": "string",
      "description": "A (best) to F"
    },
    "score": {
      "type": "number",
      "description": "0–100"
    },
    "host": {
      "type": "string"
    },
    "platform": {
      "type": [
        "string",
        "null"
      ],
      "description": "Detected builder/host, e.g. lovable, replit"
    },
    "limited": {
      "type": "boolean",
      "description": "True when the app exposed little to a passive check; a good grade is then not proof of safety."
    },
    "report_url": {
      "type": "string"
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "rule_id": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "enum": [
              "critical",
              "high",
              "medium",
              "low",
              "info"
            ]
          },
          "title": {
            "type": "string"
          },
          "what_it_means": {
            "type": [
              "string",
              "null"
            ]
          },
          "what_to_do": {
            "type": [
              "string",
              "null"
            ]
          },
          "evidence": {
            "type": [
              "string",
              "null"
            ],
            "description": "Masked evidence; secrets are never returned in full."
          }
        },
        "required": [
          "rule_id",
          "severity",
          "title"
        ]
      },
      "description": "Most serious first."
    }
  },
  "required": [
    "grade",
    "score",
    "host",
    "limited",
    "report_url",
    "findings"
  ]
}
🟢explain_finding(rule_id, lang)

Returns the plain-language meaning and step-by-step fix for one Malinois finding. Use it while helping the user fix an issue reported by scan_app, or when they ask what a finding means. Pass the rule_id exactly as scan_app returned it. Read-only, no network, instant.

输入模式

{
  "type": "object",
  "properties": {
    "rule_id": {
      "type": "string",
      "description": "The rule_id of a finding, e.g. supabase_missing_rls"
    },
    "lang": {
      "type": "string",
      "enum": [
        "en",
        "ko",
        "es",
        "ja",
        "pt",
        "fr",
        "de",
        "zh"
      ],
      "description": "Language for the explanations (default: en)."
    }
  },
  "required": [
    "rule_id"
  ],
  "additionalProperties": false
}

社区

评价此服务器

证据

最近观测

已验证未记录版本2 个工具
已验证未记录版本2 个工具