このMCPでできること
Passively scans a deployed web app for exposed databases, secrets, files, source maps, permissive CORS, and missing security headers, and explains findings.
ツール
入力スキーマ
{'type': 'object', 'required': ['rule_id'], 'properties': {'lang': {'enum': ['en', 'ko', 'es', 'ja', 'pt', 'fr', 'de', 'zh'], 'type': 'string', 'description': 'Language for the explanations (default: en).'}, 'rule_id': {'type': 'string', 'description': 'The rule_id of a finding, e.g. supabase_missing_rls'}}, 'additionalProperties': False}
入力スキーマ
{'type': 'object', 'required': ['url', 'i_own_this'], 'properties': {'url': {'type': 'string', 'maxLength': 500, 'description': 'Public http(s) address of the deployed app, e.g. https://my-app.lovable.app (scheme optional).'}, 'lang': {'enum': ['en', 'ko', 'es', 'ja', 'pt', 'fr', 'de', 'zh'], 'type': 'string', 'description': 'Language for the explanations (default: en).'}, 'i_own_this': {'type': 'boolean', 'description': 'Must be true. Set it only after the user has explicitly confirmed they own this app or are authorized to test it; without it the check is refused.'}}, 'additionalProperties': False}
出力スキーマ
{'type': 'object', 'required': ['grade', 'score', 'host', 'limited', 'report_url', 'findings'], 'properties': {'host': {'type': 'string'}, 'grade': {'type': 'string', 'description': 'A (best) to F'}, 'score': {'type': 'number', 'description': '0–100'}, 'limited': {'type': 'boolean', 'description': 'True when the app exposed little to a passive check; a good grade is then not proof of safety.'}, 'findings': {'type': 'array', 'items': {'type': 'object', 'required': ['rule_id', 'severity', 'title'], 'properties': {'title': {'type': 'string'}, 'rule_id': {'type': 'string'}, 'evidence': {'type': ['string', 'null'], 'description': 'Masked evidence; secrets are never returned in full.'}, 'severity': {'enum': ['critical', 'high', 'medium', 'low', 'info'], 'type': 'string'}, 'what_to_do': {'type': ['string', 'null']}, 'what_it_means': {'type': ['string', 'null']}}}, 'description': 'Most serious first.'}, 'platform': {'type': ['string', 'null'], 'description': 'Detected builder/host, e.g. lovable, replit'}, 'report_url': {'type': 'string'}}}
最近のツール変更
類似のMCPサーバー
osint-terminal
Provides keyless OSINT and reconnaissance tools for domains, DNS, IPs, breach exposure, threat intelligence, and related lookups.
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
BorealHost
Provides web hosting and infrastructure management, including site deployment, DNS, domains, containers, compute, backups, cachin…
Proof Holdings
Provides domain verification, identity and delegation proofs, human approval workflows, trusted-contact challenges, and controlle…
GoCreative Agent API
Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…