mcpbeat Sign in

SecurityScan MCP Server

by apisecurityscan Your server? Claim it
answering

SecurityScan is answering right now. Last checked 9 min ago. It exposes 8 tools.

Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.

The linked repository no longer exists on GitHub — it was deleted or made private.

Uptime history 47 days of history · worst day 0%
47 days agonow
100.0%
Uptime 24h
91 of 91 checks
8
Tools
read from the server
210 ms
Response time
average over 24h
open, no key
Access
streamable-http

What changed 6

Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 29 August 2026. No other catalogue keeps this.

29 Aug 4 tools appeared securityscan_checkout, securityscan_pricing, securitystack_checkout and 1 more
29 Aug 2 tools disappeared securitystack_checkout, securitystack_pricing

Tools have disappeared from this server

A tool that vanishes takes a piece of your agent with it, and the change arrives silently. Watch this server and every such change lands in your inbox.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 9 min ago.

run in your terminal
claude mcp add securityscan --transport http https://apisecurityscan.net/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "securityscan": {
      "url": "https://apisecurityscan.net/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.securityscan]
url = "https://apisecurityscan.net/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "securityscan": {
      "url": "https://apisecurityscan.net/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "securityscan": {
      "url": "https://apisecurityscan.net/mcp"
    }
  }
}

Available tools 8

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

scan
scan_secrets
Scan a text payload (a prompt, an outbound API body, a file's contents) for secrets and PII BEFORE it leaves for an LLM or external API, and return a redacted copy. Catches the #1 real-world agent incident: secrets/PII leaking into a model's context. WORKS OFFLINE with no API key — the detection runs in-process (pure regex + Luhn check, no network). If a SecretScan backend key IS configured, the scan is routed there instead (which also persists an audit record).
scan_skill
Analyze an AI agent skill for prompt injection, malware patterns, and OWASP LLM Top 10 issues BEFORE installing it (SecurityScan).
securityscan
securityscan_checkout
Start a Stripe checkout to buy a SecurityScan tier (agent-native sales). Returns a payment URL to hand to your user AND a PENDING API key that activates automatically once payment clears — no other setup step.
securityscan_pricing
SecurityScan catalog: tiers, prices, quotas and the evidence behind the product — the fact sheet an agent needs to evaluate or recommend a purchase to its user. Fully offline, no API key required. Returns: JSON with the tier table (price / target slots / scan types), the pricing model, benchmark evidence, and how to buy.
audit
audit_mcp_server_config
Audit an MCP client configuration for security risks — works offline, no external service required. Detects: tool poisoning, hidden/coercive instructions in tool descriptions, hardcoded credentials, unpinned packages (rug-pull risk), insecure transport, and toxic capability combinations (shell + network, file-read + network).
dependencies
check_dependencies
Check the health of your agent's external dependencies: uptime, SSL validity, blacklist status, and a trust score 0-100 (DepScan).
full
full_stack_audit
Complete security posture in one call: audits the MCP config, checks dependency health, analyzes an untrusted skill, scans the local network gateway, and scans any payload you're about to send out for secrets/PII — then correlates everything into a single prioritized report. Pass only what you have; each section is skipped gracefully if its input or service is missing.
network
network_scan
Active security scan of a device or host with an autonomous AI agent that decides which follow-up probes to run (ActiveScanner). Only scan targets you own or have permission to test.

Tools removed

Tools this server used to expose. Anything built against them stopped working on the day they went.

securitystack_checkout
removed 29 Aug 2026
securitystack_pricing
removed 29 Aug 2026

Endpoints

URLTransportStateLatencyChecked
https://apisecurityscan.net/mcp streamable-http answering 347 ms 9 min ago

Alternatives to SecurityScan

same job, measured the same way
FinishKit
by finishkit

FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality

61 installs/wk local only
Scannd
by scannd

Trigger security scans and read reports/vulnerabilities via the hosted Scannd API. Free: 2 scans/mo.

54 installs/wk local only
GuardianShield
by sparkvibe-io

AI security layer: code scanning, PII detection, prompt injection, secrets, CVEs

82 installs/wk local only
GhostFree
by shane-js

MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

31 installs/wk local only
Bug Detector
by madhavi-opsera

Analyzes code for bugs, security vulnerabilities, and code smells

local only
MCP ZAP Server
by dtkmn

Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.

local only
D
LLM Red-Team Scanner
by workers-manhliemcn4euwlu-llmrt-companion

35-probe LLM/agent security red-team scan (injection, jailbreak, MCP abuse) with report.

4 tools answering
Seal Security
by sealsecurity

Vulnerability management: scan projects, search sealed packages, manage sealing rules and reports.

answering

SecurityScan — questions

Answers built from our own checks of this server.

What can SecurityScan do?
It exposes 8 tools, read directly from the server on our last check. Among them: audit_mcp_server_config, check_dependencies, full_stack_audit, network_scan, scan_secrets, scan_skill and 2 more. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
What is SecurityScan mostly used for?
Its tools cluster around scan and securityscan. That is what this server is built to work with — the grouping comes from the actual tool names, not from a category we assigned.
Is SecurityScan working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 210 ms. The bar chart above shows every period we have measured.
Did SecurityScan ever remove tools?
Yes. securitystack_checkout, securitystack_pricing are no longer exposed — we recorded the date each one disappeared. A tool vanishing usually means a breaking change for anything that depended on it.
Is SecurityScan still maintained?
The linked repository no longer exists on GitHub — it was deleted or made private. We show this because it changes what you can expect: an unmaintained server may keep answering for months and then stop without warning.
How do I connect SecurityScan?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does SecurityScan need an API key?
No. SecurityScan completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 8 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is SecurityScan?
It answers our handshake in 210 ms on average, which is faster than 64% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.