Mmcp.market

Malinois MCP server

by malinois.app·app.malinois/scan·v1.1.0

Check a live app you own for public databases, leaked keys and exposed files.

C69/100grade C
What users say
No reviews yet
Be the first
Safety scan
C69/100

full report

Adoption
New

Little public usage data yet

Reviews

Write one

Nobody has reviewed Malinois yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Malinois tools (2)

write = sends, deletes, buys or posts
  • explain_findingFree

    Returns the plain-language meaning and step-by-step fix for one Malinois finding. Use it while helping the user fix an issue reported by scan_app, or when they ask what a finding means. Pass the rule_id exactly as scan_app returned it. Read-only, no network, instant.

  • scan_appFree

    Runs a passive, outside-in security check of a live web app and returns a letter grade (A–F), each issue in plain language with fix steps, and a report link. Use when the user asks whether their deployed app is safe, before launch, or after a redeploy to confirm a fix. It checks for publicly readable Supabase/Firebase data, secret keys (Stripe, OpenAI, Supabase service_role…) in client JavaScript, downloadable .env/.git files, source maps, permissive CORS and missing security headers. Do not use it for apps the user does not own or is not authorized to test, for localhost or private addresses, or to review source code — it only sees what the public URL serves. Behavior: sends ordinary GET requests like a browser (no login, exploitation or load testing); takes about 10–30 seconds; saves the result as a report page on malinois.app, linked in the response; secrets appear only masked. Each app can be checked at most 20 times per hour.

Public scan report

scanner v0.1.4 · 2026-09-19 · same rubric, same numbers if you re-run it

1 low
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 836ms20/20
  • Tool poisoning2 tool descriptions checked15/15
  • Auth qualityopen endpoint, read-only tools10/15
  • Maintenanceno repository listed3/15
  • Maintainer identityverified namespace with website, no repo4/10

Findings (1)

  • lowNo source repository listedmaint.no-repo
Overall 69/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http scan https://malinois.app/mcp
Add to Cursor

Malinois: common questions

Is Malinois MCP server safe?
With care: it is graded C, so read the findings first (69/100). Read the Malinois safety report
How do I install Malinois?
It runs remotely at malinois.app. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does Malinois need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Malinois maintained?
The latest release is v1.1.0.
Is Malinois up?
100% of our last 1 checks got an answer. We check remote servers about four times a day.
What can I use instead of Malinois?
Servers from other publishers that do the same job: b/cited MCP server, MCP server and DNS Doctor MCP server. Compare all Malinois alternatives.

Alternatives to Malinois

Same job from other publishers: the closest match first, then the best rated.

All Malinois alternatives →
  • b/cited
    AEO tools: scan any URL for AI-citation readiness, read the public leaderboard and citation panel.
    B
  • MCP
    Client editing for sites you built: register, scan, publish, go live, invite the client.
    C
  • DNS Doctor
    Scan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.
    A
  • OpenQR
    Generate, edit and track dynamic (editable) QR codes with scan analytics. Hosted MCP and REST API.
    B
  • Security Headers Csp Lint
    Reads security headers and CSP line by line in your config file and names the lines that silently do
    A

More from malinois.app