
ScanLabsAI Security Scanner MCP server
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
96 downloads/wk
Reviews
Write oneNobody has reviewed ScanLabsAI Security Scanner yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
ScanLabsAI Security Scanner tools (8, 2 write)
write = sends, deletes, buys or postsbuy_creditswrite actionFreeGet a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).
check_creditsFreeCheck the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.
compliance_reportFreeGenerate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.
get_fix_guidanceFreeGet detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.
get_pricingFreeGet ScanLabsAI pricing: the free-first-scan policy and AI credit packs.
lookup_cvesFreeLook up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.
scan_agentFreeRed-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind="openai" for an OpenAI-compatible chat-completions endpoint, or kind="mcp" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.
scan_websitewrite actionFreeRun a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
- Code scan2 source files scanned25/25
- Live reliabilityremote reachable in 532ms20/20
- Tool poisoning8 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 2 write-action tools with no auth3/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (1)
- highWrite-action tools reachable without authentication
auth.open-write
Install directly
claude mcp add --transport http scanner https://scanlabsai.com/api/mcp
ScanLabsAI Security Scanner: common questions
- Is ScanLabsAI Security Scanner MCP server safe?
- Mostly: it is graded B (70/100). Read the ScanLabsAI Security Scanner safety report
- How do I install ScanLabsAI Security Scanner?
- It runs remotely at scanlabsai.com. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does ScanLabsAI Security Scanner need an API key?
- Yes. The registry entry asks for
SCANLABS_API_KEY. - Is ScanLabsAI Security Scanner maintained?
- The latest release is v1.1.0.
- Is ScanLabsAI Security Scanner up?
- 100% of our last 1 checks got an answer. We check remote servers about four times a day.
- What can I use instead of ScanLabsAI Security Scanner?
- Servers from other publishers that do the same job: DNS Doctor MCP server, Trent MCP server and Security Headers Csp Lint MCP server. Compare all ScanLabsAI Security Scanner alternatives.
Alternatives to ScanLabsAI Security Scanner
Same job from other publishers: the closest match first, then the best rated.
DNS DoctorScan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.not reviewedGrowingA
TrentSecurity reviews, threat models over a repo or website, and remediation tracking, in your editor.not reviewedGrowingA- Security Headers Csp LintReads security headers and CSP line by line in your config file and names the lines that silently donot reviewedGrowingA
MCP Security & Vulnerability AuditorStatic AST security scanner detecting command injection, leaked secrets, and SSRF in MCP tools.not reviewedGrowingB- OutilsIA — Conseiller IA localeRead-only local AI advice, shared reports and website audits. No PC scan or local actions.not reviewedNewC