mcpbeat Sign in

ScanLabsAI Security Scanner MCP Server

by scanlabsai Your server? Claim it
answering

ScanLabsAI Security Scanner is answering right now. Last checked 5 min ago. It exposes 8 tools.

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

Uptime history 25 days of history
25 days agonow
100.0%
Uptime 24h
91 of 91 checks
8
Tools
read from the server
293 ms
Response time
average over 24h
open, no key
Access
streamable-http

Nothing serious here today

Today is the operative word: we check ScanLabsAI Security Scanner every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 5 min ago.

run in your terminal
claude mcp add scanner --transport http https://scanlabsai.com/api/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "scanner": {
      "url": "https://scanlabsai.com/api/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.scanner]
url = "https://scanlabsai.com/api/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "scanner": {
      "url": "https://scanlabsai.com/api/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "scanner": {
      "url": "https://scanlabsai.com/api/mcp"
    }
  }
}

Available tools 8

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

scan
scan_agent
Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind="openai" for an OpenAI-compatible chat-completions endpoint, or kind="mcp" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.
scan_website
Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.
buy
buy_credits
Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).
compliance
compliance_report
Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.
credits
check_credits
Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.
fix
get_fix_guidance
Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.
lookup
lookup_cves
Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.
pricing
get_pricing
Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.

Endpoints

URLTransportStateLatencyChecked
https://scanlabsai.com/api/mcp streamable-http answering 311 ms 5 min ago

Alternatives to ScanLabsAI Security Scanner

same job, measured the same way
MCP Server Security Audit
by joepangallo

Scan websites for security vulnerabilities, headers, TLS, and email security.

33 installs/wk local only
middleBrick
by middlebrick

Scan APIs for OWASP Top 10, LLM, and GraphQL security vulnerabilities.

50 installs/wk local only
SecurityScan
by apisecurityscan

Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.

8 tools answering
MCPAmpel - MCP Security Scanner
by diemoeve

Scan installed MCP servers for security vulnerabilities with 16 detection engines.

72 installs/wk local only
Synapse Audit
by digidenone

AI-Powered Security Scanner for LLMs. Detects vulnerabilities and syncs with SynapseAudit.

50 installs/wk local only
A
Sitejar Web Compliance Scanner
by sitejar

Scan a web page for accessibility, security, privacy, quality and SEO issues, with fixes.

answering
mcp-scan
by codingselim

Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.

85 installs/wk local only
I
Agent Security Scanner
by mikehzp

Scan AI agents for tool-calling vulnerabilities: prompt leaks, hijacking, injections, and more.

144 installs/wk local only

ScanLabsAI Security Scanner — questions

Answers built from our own checks of this server.

What can ScanLabsAI Security Scanner do?
It exposes 8 tools, read directly from the server on our last check. Among them: buy_credits, check_credits, compliance_report, get_fix_guidance, get_pricing, lookup_cves and 2 more. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is ScanLabsAI Security Scanner working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 293 ms. The bar chart above shows every period we have measured.
How do I connect ScanLabsAI Security Scanner?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does ScanLabsAI Security Scanner need an API key?
No. ScanLabsAI Security Scanner completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 8 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is ScanLabsAI Security Scanner?
It answers our handshake in 293 ms on average, which is faster than 58% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.