MCPサーバー

ScanLabsAI Security Scanner

com.scanlabsai/scanner
開発者向けツール セキュリティ 公開・接続可能 MCP 2026-07-28

このMCPでできること

Scans websites and AI agents for vulnerabilities, compliance issues, CVEs, configuration weaknesses, and remediation guidance.

buy_credits
Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).
入力スキーマ
{'type': 'object', 'properties': {'pack': {'type': 'string', 'description': 'Pack id: starter, pro, or agency. Defaults to pro.'}}}
check_credits
Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.
入力スキーマ
{'type': 'object', 'properties': {}}
compliance_report
Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.
入力スキーマ
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'The website URL to assess for compliance, e.g. https://example.com'}}}
get_fix_guidance
Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.
入力スキーマ
{'type': 'object', 'required': ['issue'], 'properties': {'issue': {'type': 'string', 'description': 'The vulnerability, finding title, or CVE id to fix.'}}}
get_pricing
Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.
入力スキーマ
{'type': 'object', 'properties': {}}
lookup_cves
Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.
入力スキーマ
{'type': 'object', 'properties': {'limit': {'type': 'number', 'description': 'Max results (1-25). Defaults to 10.'}, 'keyword': {'type': 'string', 'description': 'Optional keyword, e.g. "wordpress" or "openssl".'}}}
scan_agent
Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind="openai" for an OpenAI-compatible chat-completions endpoint, or kind="mcp" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.
入力スキーマ
{'type': 'object', 'required': ['kind', 'endpoint'], 'properties': {'deep': {'type': 'boolean', 'description': 'Run deeper probes (jailbreak + resource-exhaustion). Defaults to false.'}, 'kind': {'enum': ['openai', 'mcp'], 'type': 'string', 'description': 'Target type: "openai" for a chat-completions endpoint, "mcp" for an MCP server.'}, 'model': {'type': 'string', 'description': 'Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini.'}, 'apiKey': {'type': 'string', 'description': 'Optional bearer token / API key the target agent requires. Sent to the target only; not stored.'}, 'endpoint': {'type': 'string', 'description': 'The agent endpoint URL (chat-completions URL, or MCP server URL).'}}}
scan_website
Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.
入力スキーマ
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'The website URL to scan, e.g. https://example.com'}, 'deep': {'type': 'boolean', 'description': 'Run a deep scan (comprehensive, slower). Defaults to false.'}}}
追加
buy_credits
2026年9月17日12:37
追加
check_credits
2026年9月17日12:37
追加
get_pricing
2026年9月17日12:37
追加
lookup_cves
2026年9月17日12:37
追加
get_fix_guidance
2026年9月17日12:37
追加
compliance_report
2026年9月17日12:37
追加
scan_agent
2026年9月17日12:37
追加
scan_website
2026年9月17日12:37

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…