MCP 服务器

SecScan

us.secscan/secscan
安全 公开且可连接 MCP 2025-11-25

此 MCP 可以做什么

Scans authorized web applications, reports vulnerabilities with evidence and fixes, verifies domains for active testing, and monitors sites for security and uptime issues.

add_monitor
Monitor a site
Put a site the user owns under continuous monitoring: hourly uptime checks, CVE matching, certificate alerts and regular rescans. Runs a full baseline scan straight away, which uses one of the user's scans exactly as in the app (free for plan holders). Returns the baseline scan_id for get_scan_status.
可访问外部资源
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 2048, 'minLength': 1, 'description': 'The site to monitor, e.g. https://example.com'}}, 'additionalProperties': False}
check_domain_verification
Check a domain verification
Check whether the file or DNS record from start_domain_verification is live. On success the domain is verified and its next scan includes active tests. DNS changes can take a few minutes.
可访问外部资源 幂等
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'The domain passed to start_domain_verification'}}, 'additionalProperties': False}
dismiss_finding
Dismiss a false positive
Mark a finding as a false positive for this site, so future scans of it stop reporting it — the same as Dismiss in the app, and undoable there. ONLY use this after the user has confirmed the finding is wrong; never dismiss a real problem to improve a grade.
可能执行破坏性操作
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['scan_id', 'finding_name'], 'properties': {'scan_id': {'type': 'string', 'description': 'The scan whose report contains the finding'}, 'finding_name': {'type': 'string', 'maxLength': 300, 'minLength': 1, 'description': "The finding's name exactly as get_report shows it"}}, 'additionalProperties': False}
get_account
Scans left and plan
How many scans the user can still run — free scans, plan scans and credits — and their plan. Check this before starting several scans.
只读
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
get_report
Read a scan report
The finished report for a scan: grade, what the scan tested and what it skipped (a clean grade says nothing about skipped areas, so say so), prioritised findings with fixes and evidence, and a fix prompt written for the user's AI editor. Findings come 25 per page, most severe first — pass offset for the next page, or min_severity (e.g. "high") to focus on what matters most.
只读
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['scan_id'], 'properties': {'limit': {'type': 'integer', 'maximum': 50, 'minimum': 1, 'description': 'Findings per page (default 25, max 50)'}, 'offset': {'type': 'integer', 'minimum': 0, 'description': 'Skip this many findings, for the next page'}, 'scan_id': {'type': 'string', 'description': 'The scan_id returned by scan_url or list_recent_scans'}, 'min_severity': {'enum': ['critical', 'high', 'medium', 'low', 'info'], 'type': 'string', 'description': 'Only findings at this severity or worse, e.g. "high"'}}, 'additionalProperties': False}
get_scan_status
Check a scan
Status of a scan (queued, scanning, analyzing, complete, failed). With wait_seconds (max 60) it waits for the scan to finish and returns the full report as soon as it does.
只读
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['scan_id'], 'properties': {'scan_id': {'type': 'string', 'description': 'The scan_id returned by scan_url'}, 'wait_seconds': {'type': 'integer', 'maximum': 60, 'minimum': 0, 'description': 'Wait up to this long for the scan to finish'}}, 'additionalProperties': False}
list_monitors
List monitored sites
Sites under continuous monitoring: latest grade, last and next scan, uptime check, CVE alerts, new problems in the last scan and certificate expiry. Use the monitor id with monitor_scan_now.
只读
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
list_recent_scans
List recent scans
The user's most recent scans with their status, newest first.
只读
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {'limit': {'type': 'integer', 'maximum': 25, 'minimum': 1}}, 'additionalProperties': False}
list_verified_domains
List verified domains
Domains the user has proved they own. Only these receive active testing (injection, XSS, SSRF, access control); others get passive checks. Verify more at https://secscan.us/domains.
只读
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'properties': {}}
monitor_scan_now
Rescan a monitored site now
Run a full scan of a monitored site now instead of waiting for its schedule — e.g. to confirm a fix. Free for plan holders; otherwise uses one of the user's scans, as in the app. Takes the monitor id from list_monitors.
可访问外部资源
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['monitor_id'], 'properties': {'monitor_id': {'type': 'string', 'description': 'The monitor id from list_monitors or add_monitor'}}, 'additionalProperties': False}
scan_url
Scan a website
Start a SecScan security scan of a web application the user owns or is authorised to test. Returns a scan_id; most scans finish in under a minute — then call get_scan_status with wait_seconds, or get_report. Active tests (injection, XSS, SSRF…) run only on domains the user has verified; others get passive checks. Optionally also reads a public GitHub repository for committed secrets (github_repo); that only contacts GitHub, never the site. Each scan uses one of the user's free scans, plan scans or credits.
可访问外部资源
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 2048, 'minLength': 1, 'description': 'The URL to scan, e.g. https://example.com'}, 'github_repo': {'type': 'string', 'maxLength': 300, 'description': 'Optional public GitHub repository to check for committed secrets, e.g. https://github.com/owner/repo. Public repositories only.'}}, 'additionalProperties': False}
start_domain_verification
Start verifying a domain
Begin proving the user owns a domain, which unlocks active tests (injection, XSS, SSRF, access control) on its scans. Returns a file to publish on the site, or a DNS TXT record — an editor can usually add the file to the codebase and deploy it. Then call check_domain_verification. Calling it again returns the same token, so a record already published stays valid.
输入模式
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'maxLength': 253, 'minLength': 1, 'description': 'The domain, e.g. example.com or https://example.com'}}, 'additionalProperties': False}
已更改
scan_url
2026年10月2日 02:41
已添加
dismiss_finding
2026年9月28日 02:40
已添加
monitor_scan_now
2026年9月28日 02:40
已添加
add_monitor
2026年9月28日 02:40
已添加
list_monitors
2026年9月28日 02:40
已添加
check_domain_verification
2026年9月28日 02:40
已添加
start_domain_verification
2026年9月28日 02:40
已添加
get_account
2026年9月28日 02:40
已添加
list_verified_domains
2026年9月28日 02:40
已添加
list_recent_scans
2026年9月28日 02:40
已添加
get_report
2026年9月28日 02:40
已添加
get_scan_status
2026年9月28日 02:40
已添加
scan_url
2026年9月28日 02:40