Malinois

Check a live app you own for public databases, leaked keys and exposed files.

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
100%
命名品質
80%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~824Token(工具定義)
~2.7 KB典型回應大小
中等的注意力影響(128k 上下文的 0.64%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "scan": {
      "url": "https://malinois.app/mcp"
    }
  }
}

遠端端點

https://malinois.app/mcpstreamable-http

它能做什麼

工具清單

工具(2)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢scan_app(url, i_own_this, lang)

Runs a passive, outside-in security check of a live web app and returns a letter grade (A–F), each issue in plain language with fix steps, and a report link. Use when the user asks whether their deployed app is safe, before launch, or after a redeploy to confirm a fix. It checks for publicly readable Supabase/Firebase data, secret keys (Stripe, OpenAI, Supabase service_role…) in client JavaScript, downloadable .env/.git files, source maps, permissive CORS and missing security headers. Do not use it for apps the user does not own or is not authorized to test, for localhost or private addresses, or to review source code — it only sees what the public URL serves. Behavior: sends ordinary GET requests like a browser (no login, exploitation or load testing); takes about 10–30 seconds; saves the result as a report page on malinois.app, linked in the response; secrets appear only masked. Each app can be checked at most 20 times per hour.

輸入結構描述

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "maxLength": 500,
      "description": "Public http(s) address of the deployed app, e.g. https://my-app.lovable.app (scheme optional)."
    },
    "i_own_this": {
      "type": "boolean",
      "description": "Must be true. Set it only after the user has explicitly confirmed they own this app or are authorized to test it; without it the check is refused."
    },
    "lang": {
      "type": "string",
      "enum": [
        "en",
        "ko",
        "es",
        "ja",
        "pt",
        "fr",
        "de",
        "zh"
      ],
      "description": "Language for the explanations (default: en)."
    }
  },
  "required": [
    "url",
    "i_own_this"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "properties": {
    "grade": {
      "type": "string",
      "description": "A (best) to F"
    },
    "score": {
      "type": "number",
      "description": "0–100"
    },
    "host": {
      "type": "string"
    },
    "platform": {
      "type": [
        "string",
        "null"
      ],
      "description": "Detected builder/host, e.g. lovable, replit"
    },
    "limited": {
      "type": "boolean",
      "description": "True when the app exposed little to a passive check; a good grade is then not proof of safety."
    },
    "report_url": {
      "type": "string"
    },
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "rule_id": {
            "type": "string"
          },
          "severity": {
            "type": "string",
            "enum": [
              "critical",
              "high",
              "medium",
              "low",
              "info"
            ]
          },
          "title": {
            "type": "string"
          },
          "what_it_means": {
            "type": [
              "string",
              "null"
            ]
          },
          "what_to_do": {
            "type": [
              "string",
              "null"
            ]
          },
          "evidence": {
            "type": [
              "string",
              "null"
            ],
            "description": "Masked evidence; secrets are never returned in full."
          }
        },
        "required": [
          "rule_id",
          "severity",
          "title"
        ]
      },
      "description": "Most serious first."
    }
  },
  "required": [
    "grade",
    "score",
    "host",
    "limited",
    "report_url",
    "findings"
  ]
}
🟢explain_finding(rule_id, lang)

Returns the plain-language meaning and step-by-step fix for one Malinois finding. Use it while helping the user fix an issue reported by scan_app, or when they ask what a finding means. Pass the rule_id exactly as scan_app returned it. Read-only, no network, instant.

輸入結構描述

{
  "type": "object",
  "properties": {
    "rule_id": {
      "type": "string",
      "description": "The rule_id of a finding, e.g. supabase_missing_rls"
    },
    "lang": {
      "type": "string",
      "enum": [
        "en",
        "ko",
        "es",
        "ja",
        "pt",
        "fr",
        "de",
        "zh"
      ],
      "description": "Language for the explanations (default: en)."
    }
  },
  "required": [
    "rule_id"
  ],
  "additionalProperties": false
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本2 個工具
已驗證未記錄版本2 個工具
已驗證未記錄版本2 個工具