{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "category": "",
    "endpoint": "https://scanlabsai.com/api/mcp",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/scanlabsai-scanner.json",
    "kind": "mcp",
    "listed": "indexed",
    "liveUrl": "https://www.anchorterminal.com/api/v1/live/scanlabsai-scanner.json",
    "markdownUrl": "https://www.anchorterminal.com/tools/scanlabsai-scanner.md",
    "mcpTools": {
      "check": {
        "checker": "anchor-check/1.0",
        "totalTokens": 1106,
        "counts": {
          "error": 0,
          "note": 1,
          "warn": 8
        },
        "findings": [
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "buy_credits",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "check_credits",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "compliance_report",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_fix_guidance",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "get_pricing",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "lookup_cves",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Its name starts with \"lookup\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "scan_agent",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC16",
            "severity": "warn",
            "tool": "scan_website",
            "message": "no readOnlyHint or destructiveHint",
            "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
          },
          {
            "rule": "TC24",
            "severity": "note",
            "message": "8 of 8 tools have no outputSchema",
            "fix": "Declare outputSchema for tools that return structured data, and return structuredContent that matches it."
          }
        ]
      },
      "checkedAt": "2026-10-04T22:23:44Z",
      "count": 8,
      "note": "answered without the initialize handshake",
      "schemaTokens": 1106,
      "status": "ok",
      "tools": [
        {
          "name": "scan_website",
          "description": "Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.",
          "inputSchema": {
            "properties": {
              "deep": {
                "description": "Run a deep scan (comprehensive, slower). Defaults to false.",
                "type": "boolean"
              },
              "url": {
                "description": "The website URL to scan, e.g. https://example.com",
                "type": "string"
              }
            },
            "required": [
              "url"
            ],
            "type": "object"
          }
        },
        {
          "name": "scan_agent",
          "description": "Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind=\"openai\" for an OpenAI-compatible chat-completions endpoint, or kind=\"mcp\" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.",
          "inputSchema": {
            "properties": {
              "apiKey": {
                "description": "Optional bearer token / API key the target agent requires. Sent to the target only; not stored.",
                "type": "string"
              },
              "deep": {
                "description": "Run deeper probes (jailbreak + resource-exhaustion). Defaults to false.",
                "type": "boolean"
              },
              "endpoint": {
                "description": "The agent endpoint URL (chat-completions URL, or MCP server URL).",
                "type": "string"
              },
              "kind": {
                "description": "Target type: \"openai\" for a chat-completions endpoint, \"mcp\" for an MCP server.",
                "enum": [
                  "openai",
                  "mcp"
                ],
                "type": "string"
              },
              "model": {
                "description": "Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini.",
                "type": "string"
              }
            },
            "required": [
              "kind",
              "endpoint"
            ],
            "type": "object"
          }
        },
        {
          "name": "compliance_report",
          "description": "Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.",
          "inputSchema": {
            "properties": {
              "url": {
                "description": "The website URL to assess for compliance, e.g. https://example.com",
                "type": "string"
              }
            },
            "required": [
              "url"
            ],
            "type": "object"
          }
        },
        {
          "name": "get_fix_guidance",
          "description": "Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. \"missing Content-Security-Policy header\", \"SQL injection\", a CVE id). Returns actionable fixes.",
          "inputSchema": {
            "properties": {
              "issue": {
                "description": "The vulnerability, finding title, or CVE id to fix.",
                "type": "string"
              }
            },
            "required": [
              "issue"
            ],
            "type": "object"
          }
        },
        {
          "name": "lookup_cves",
          "description": "Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.",
          "inputSchema": {
            "properties": {
              "keyword": {
                "description": "Optional keyword, e.g. \"wordpress\" or \"openssl\".",
                "type": "string"
              },
              "limit": {
                "description": "Max results (1-25). Defaults to 10.",
                "type": "number"
              }
            },
            "type": "object"
          }
        },
        {
          "name": "get_pricing",
          "description": "Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.",
          "inputSchema": {
            "properties": {},
            "type": "object"
          }
        },
        {
          "name": "check_credits",
          "description": "Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.",
          "inputSchema": {
            "properties": {},
            "type": "object"
          }
        },
        {
          "name": "buy_credits",
          "description": "Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).",
          "inputSchema": {
            "properties": {
              "pack": {
                "description": "Pack id: starter, pro, or agency. Defaults to pro.",
                "type": "string"
              }
            },
            "type": "object"
          }
        }
      ]
    },
    "name": "ScanLabsAI Security Scanner",
    "note": "Indexed from the official MCP registry: facts and our own checks, not reviewed, so no score, grade or rank.",
    "packages": [
      {
        "registryType": "npm",
        "identifier": "@scanlabsai/mcp-server",
        "version": "1.0.0",
        "transport": "stdio"
      }
    ],
    "pageJsonUrl": "https://www.anchorterminal.com/tools/scanlabsai-scanner.json",
    "popularity": {
      "npmWeekly": 18
    },
    "registryName": "com.scanlabsai/scanner",
    "remotes": [
      {
        "type": "streamable-http",
        "url": "https://scanlabsai.com/api/mcp"
      }
    ],
    "repository": "",
    "reviewed": false,
    "slug": "scanlabsai-scanner",
    "source": "the official MCP registry",
    "sourceUrl": "https://registry.modelcontextprotocol.io/v0.1/servers?search=com.scanlabsai/scanner",
    "summary": "Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes",
    "updatedAt": "2026-09-14T08:15:36Z",
    "url": "https://www.anchorterminal.com/tools/scanlabsai-scanner",
    "vendor": "scanlabsai.com",
    "vendorUrl": "https://scanlabsai.com",
    "version": "1.1.0",
    "websiteUrl": "https://scanlabsai.com",
    "where": "both",
    "why": [
      "vendor"
    ]
  }
}
