SiteGuardian

EU-hosted website monitoring + 17-framework compliance MCP. One anonymous tool, four authenticated.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
67%
命名质量
96%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~2,612token 数(工具定义)
~3.7 KB典型响应大小
对注意力有显著影响(占 128k 上下文窗口的 2.04%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "siteguardian": {
      "url": "https://mcp.siteguardian.io"
    }
  }
}

远程端点

https://mcp.siteguardian.iostreamable-http

它能做什么

工具清单

工具(5)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢scan_domain(domain)

Runs a free one-off security scan of the given domain and returns its grade (A–F), scan timestamp, and up to three top-priority issues with a permalink to the full report on siteguardian.io. Use this when the user asks for a quick security check of a domain that is NOT yet under SiteGuardian monitoring, or when they want a fresh assessment before subscribing. Results are cached for two hours, so repeated calls about the same domain return the same snapshot and mark it with cached=True. Do NOT use this for domains already under monitoring by the user — call get_domain_status instead for the account-scoped view with framework tags. Do NOT use this to batch-scan many domains as a competitive-intelligence tool; per-source-IP and per-target rate limits bound usage. This tool does not require authentication.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "grade": {
      "enum": [
        "A",
        "B",
        "C",
        "D",
        "F"
      ],
      "type": "string"
    },
    "score": {
      "maximum": 100,
      "minimum": 0,
      "type": "integer"
    },
    "scanned_at": {
      "format": "date-time",
      "type": "string"
    },
    "cached": {
      "description": "True when the result was served from the 2-hour ScanLog cache.",
      "type": "boolean"
    },
    "top_issues": {
      "description": "Up to 3 top-priority issues found. Sorted high → medium → low.",
      "items": {
        "description": "One security issue surfaced by a tool's output.\n\nCanonical shape used by ``scan_domain`` and ``get_domain_status``.\nThe ``id`` is stable across calls and locales — derived from the\nissue's stable ``code`` (see recommendation_view.py, P1 + P4).",
        "properties": {
          "id": {
            "description": "Stable 12-char hex id; use as the issue_id argument to get_fix_recommendations.",
            "type": "string"
          },
          "code": {
            "description": "Raw stable code (e.g. 'headers.sri_missing') — survives i18n translation.",
            "type": "string"
          },
          "severity": {
            "enum": [
              "critical",
              "high",
              "medium",
              "low",
              "info"
            ],
            "type": "string"
          },
          "title": {
            "description": "Short user-facing title, localised.",
            "type": "string"
          },
          "impact": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "default": null,
            "description": "One-sentence explanation of why it matters."
          },
          "category": {
            "anyOf": [
              {
                "enum": [
                  "website",
                  "email",
                  "dns",
                  "server",
                  "uncategorized"
                ],
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "default": null,
            "description": "Which product area this issue belongs to."
          }
        },
        "required": [
          "id",
          "code",
          "severity",
          "title"
        ],
        "type": "object"
      },
      "type": "array"
    },
    "report_url": {
      "description": "Permalink to the full scan report on siteguardian.io.",
      "type": "string"
    }
  },
  "required": [
    "domain",
    "grade",
    "score",
    "scanned_at",
    "cached",
    "top_issues",
    "report_url"
  ]
}
🟢list_monitored_domains

Returns the full list of domains under continuous SiteGuardian monitoring for the authenticated account. Each entry includes the domain, current security grade (A–F), timestamp of the last completed scan, and a relative dashboard URL. Use this when the user asks what they are monitoring, wants an inventory summary, or needs to look up a specific domain's exact spelling before calling get_domain_status / get_drift_events / get_fix_recommendations. The list is scoped entirely by the API key — there is no filter parameter to widen or narrow the result. Do NOT use this to enumerate domains the user does not own or monitor — it only returns their own inventory. Do NOT call it to trigger a scan (it does not); use scan_domain for one-off checks. Requires a valid API key.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "domains": {
      "items": {
        "properties": {
          "domain": {
            "type": "string"
          },
          "grade": {
            "anyOf": [
              {
                "enum": [
                  "A",
                  "B",
                  "C",
                  "D",
                  "F"
                ],
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "default": null
          },
          "last_scan_at": {
            "anyOf": [
              {
                "format": "date-time",
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "default": null
          },
          "dashboard_url": {
            "description": "Relative URL to the monitor detail page.",
            "type": "string"
          }
        },
        "required": [
          "domain",
          "dashboard_url"
        ],
        "type": "object"
      },
      "type": "array"
    }
  },
  "required": [
    "domains"
  ]
}
🟢get_domain_status(domain)

Returns the current security grade (A–F), last-scan timestamp, and list of active issues for a domain that is ALREADY under SiteGuardian monitoring by the authenticated account. Each issue carries a stable id, a severity, a short title, and an impact description. The response also includes a relative dashboard URL. Use this when the user asks about the current state of a specific monitored domain, wants to confirm a recent change landed, or needs issue ids to call get_fix_recommendations with a specific issue_id. Do NOT use this for domains not yet under monitoring — it will return a domain_not_monitored error; call scan_domain for one-off checks instead. Compliance framework tags (NIS2 / GDPR / DORA) are NOT included in v1; framework tagging on the monitored-domain path is tracked as a follow-up. Requires a valid API key.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "grade": {
      "anyOf": [
        {
          "enum": [
            "A",
            "B",
            "C",
            "D",
            "F"
          ],
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null
    },
    "last_scan_at": {
      "anyOf": [
        {
          "format": "date-time",
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null
    },
    "active_issues": {
      "items": {
        "description": "One security issue surfaced by a tool's output.\n\nCanonical shape used by ``scan_domain`` and ``get_domain_status``.\nThe ``id`` is stable across calls and locales — derived from the\nissue's stable ``code`` (see recommendation_view.py, P1 + P4).",
        "properties": {
          "id": {
            "description": "Stable 12-char hex id; use as the issue_id argument to get_fix_recommendations.",
            "type": "string"
          },
          "code": {
            "description": "Raw stable code (e.g. 'headers.sri_missing') — survives i18n translation.",
            "type": "string"
          },
          "severity": {
            "enum": [
              "critical",
              "high",
              "medium",
              "low",
              "info"
            ],
            "type": "string"
          },
          "title": {
            "description": "Short user-facing title, localised.",
            "type": "string"
          },
          "impact": {
            "anyOf": [
              {
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "default": null,
            "description": "One-sentence explanation of why it matters."
          },
          "category": {
            "anyOf": [
              {
                "enum": [
                  "website",
                  "email",
                  "dns",
                  "server",
                  "uncategorized"
                ],
                "type": "string"
              },
              {
                "type": "null"
              }
            ],
            "default": null,
            "description": "Which product area this issue belongs to."
          }
        },
        "required": [
          "id",
          "code",
          "severity",
          "title"
        ],
        "type": "object"
      },
      "type": "array"
    },
    "dashboard_url": {
      "type": "string"
    }
  },
  "required": [
    "domain",
    "active_issues",
    "dashboard_url"
  ]
}
🟢get_drift_events(domain, since, limit)

Returns recent configuration drift events for a domain under monitoring by the authenticated account — TLS changes, DNSSEC state changes, new or removed security headers, shifts in third-party JS hosts, new cookies. Each event carries its observed-at timestamp, a kind (tls/dnssec/cookies/js_hosts/headers), a severity classified centrally (high for tls/dnssec/headers, medium for cookies/js_hosts, otherwise low), a short summary, and a sanitised detail payload. Use this when the user asks 'what changed' on a domain, wants to audit recent posture shifts, or is diagnosing an unexpected issue. Pair it with get_domain_status to see the current state and get_drift_events to see how it got there. Do NOT use this for a domain that is not under monitoring — you'll get a domain_not_monitored error; monitoring has to be active for the drift history to accumulate. Optional since (ISO-8601) and limit (1..100) params narrow the window. Requires a valid API key.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "since": {
      "anyOf": [
        {
          "format": "date-time",
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null
    },
    "limit": {
      "default": 20,
      "type": "integer"
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "events": {
      "items": {
        "properties": {
          "observed_at": {
            "format": "date-time",
            "type": "string"
          },
          "kind": {
            "enum": [
              "tls",
              "dnssec",
              "cookies",
              "js_hosts",
              "headers"
            ],
            "type": "string"
          },
          "severity": {
            "description": "Classified by app/services/drift_severity.py — shared with future consumers.",
            "enum": [
              "critical",
              "high",
              "medium",
              "low",
              "info"
            ],
            "type": "string"
          },
          "summary": {
            "description": "Short human-readable summary of what changed.",
            "type": "string"
          },
          "detail": {
            "additionalProperties": true,
            "description": "Sanitized payload excerpt; fields vary by kind.",
            "type": "object"
          }
        },
        "required": [
          "observed_at",
          "kind",
          "severity",
          "summary",
          "detail"
        ],
        "type": "object"
      },
      "type": "array"
    }
  },
  "required": [
    "domain",
    "events"
  ]
}
🟢get_fix_recommendations(domain, issue_id)

Returns copy-paste-ready fix recommendations (nginx, Apache, DNS, shell) for the issues found on a domain the caller has already paid for — either an active Monitor/Compliance subscription covering the domain, OR a purchased one-off Report for the domain. Each recommendation carries a stable issue_id, a priority (high/medium/low), a title, prose instructions, one or more config snippets with the target domain already interpolated, a verify command, and a category tag. Use this when the user asks how to fix an issue, wants the exact config to apply, or needs to verify a fix worked. Pass the optional issue_id to scope the response to one specific finding. The response is read-only — this tool NEVER triggers a fresh scan; fixes are computed from the most recent stored scan (including the Report-included re-scan if that was used). Do NOT use this for domains the caller hasn't purchased coverage for — you'll get an upgrade_required error that links to the pricing page. Do NOT use this to run or trigger a scan; call scan_domain for anonymous checks. Requires a valid API key.

输入模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "issue_id": {
      "anyOf": [
        {
          "type": "string"
        },
        {
          "type": "null"
        }
      ],
      "default": null
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string"
    },
    "source": {
      "description": "Which purchased product backed this response — 'monitor' for a subscription, 'report' for a one-off Report.",
      "enum": [
        "monitor",
        "report"
      ],
      "type": "string"
    },
    "scanned_at": {
      "description": "Timestamp of the underlying scan the fixes were computed from.",
      "format": "date-time",
      "type": "string"
    },
    "recommendations": {
      "description": "Priority-sorted list of actionable fixes.",
      "items": {
        "properties": {
          "issue_id": {
            "type": "string"
          },
          "code": {
            "type": "string"
          },
          "title": {
            "type": "string"
          },
          "priority": {
            "enum": [
              "high",
              "medium",
              "low"
            ],
            "type": "string"
          },
          "instructions": {
            "type": "string"
          },
          "snippets": {
            "items": {
              "properties": {
                "platform": {
                  "enum": [
                    "nginx",
                    "apache",
                    "dns",
                    "shell",
                    "other"
                  ],
                  "type": "string"
                },
                "code": {
                  "description": "Copy-paste-ready config/command with {domain} interpolated.",
                  "type": "string"
                },
                "verify": {
                  "anyOf": [
                    {
                      "type": "string"
                    },
                    {
                      "type": "null"
                    }
                  ],
                  "default": null
                }
              },
              "required": [
                "platform",
                "code"
              ],
              "type": "object"
            },
            "type": "array"
          },
          "category": {
            "enum": [
              "website",
              "email",
              "dns",
              "server",
              "uncategorized"
            ],
            "type": "string"
          }
        },
        "required": [
          "issue_id",
          "code",
          "title",
          "priority",
          "instructions",
          "snippets",
          "category"
        ],
        "type": "object"
      },
      "type": "array"
    }
  },
  "required": [
    "domain",
    "source",
    "scanned_at",
    "recommendations"
  ]
}

社区

评价此服务器

证据

最近观测

已验证未记录版本5 个工具
已验证未记录版本5 个工具
已验证未记录版本5 个工具