SimplyScan
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
我该使用它吗
质量与安全性
发现(2)
- LOW在 check_security_headers 中
- LOW在 check_exposed_files 中
基于对工具定义和协议合规性的自动分析。
上下文开销
这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。
安装
一键安装
将以下内容添加到你的 `claude_desktop_config.json` 文件中:
{
"mcpServers": {
"simplyscan": {
"url": "https://api.simplyscan.io/mcp"
}
}
}远程端点
https://api.simplyscan.io/mcpstreamable-http它能做什么
工具清单
工具(7)
🟢scan_website(url)
Run a free SimplyScan security & speed scan of a deployed web app URL. Returns a 0-100 score and findings (exposed secrets, missing Supabase RLS, frontend leaks, speed issues). Best for apps built with Lovable, Bolt, v0, Cursor, Replit, etc.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Full https URL to check"
}
},
"required": [
"url"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢check_security_headers(url)
Grade a URL's HTTP security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy, COOP, COEP) A-F.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Full https URL to check"
}
},
"required": [
"url"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢check_ai_visibility(url)
AEO check: whether AI answer engines (ChatGPT/GPTBot, Claude, Perplexity, Google-Extended, etc.) can crawl and cite the site, plus llms.txt and structured-data signals.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Full https URL to check"
}
},
"required": [
"url"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢check_seo(url)
On-page SEO audit of a URL: title, meta description, H1, canonical, indexability, Open Graph, structured data, image alt coverage, sitemap. Returns an A-F grade.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Full https URL to check"
}
},
"required": [
"url"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢check_ssl(domain)
Inspect a domain's SSL/TLS certificate: issuer, expiry, protocol, and flags for expiring/self-signed/mismatched certs.
输入模式
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"minLength": 1,
"description": "Domain, e.g. example.com"
}
},
"required": [
"domain"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢check_email_security(domain)
Check a domain's email authentication: SPF, DKIM (common selectors), and DMARC policy. Flags spoofable domains.
输入模式
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"minLength": 1,
"description": "Domain, e.g. example.com"
}
},
"required": [
"domain"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢check_exposed_files(url)
Probe a site for accidentally exposed high-risk files (.env, .git/config, backups, etc.). Reports HTTP status only, never file contents.
输入模式
{
"type": "object",
"properties": {
"url": {
"type": "string",
"format": "uri",
"description": "Full https URL to check"
}
},
"required": [
"url"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}社区
证据