ScanLabsAI Security Scanner by scanlabsai.com

MCP server · indexed, not reviewed

HostedLocalvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

What the official MCP registry says

Facts

MCP registry
com.scanlabsai/scanner · 1.1.0
Endpoint
https://scanlabsai.com/api/mcp
Packages
npm @scanlabsai/mcp-server stdio
npm / week
18
Registry entry
updated 14 Sep 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under scanlabsai.com, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 8 · about 1,106 tokens of context · checked 13 minutes ago

ToolWhat it doesHint
scan_websiteRun a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as…
scan_agentRed-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown…
compliance_reportGenerate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns…
get_fix_guidanceGet detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes.
lookup_cvesLook up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.
get_pricingGet ScanLabsAI pricing: the free-first-scan policy and AI credit packs.
check_creditsCheck the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.
buy_creditsGet a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro…

What https://scanlabsai.com/api/mcp answered to tools/list, asked without credentials. answered without the initialize handshake. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 8 warnings · 1 note

  • warnTC16buy_creditsno readOnlyHint or destructiveHint
  • warnTC16check_creditsno readOnlyHint or destructiveHint
  • warnTC16compliance_reportno readOnlyHint or destructiveHint
  • warnTC16get_fix_guidanceno readOnlyHint or destructiveHint
  • warnTC16get_pricingno readOnlyHint or destructiveHint
  • warnTC16lookup_cvesno readOnlyHint or destructiveHint
  • warnTC16scan_agentno readOnlyHint or destructiveHint
  • warnTC16scan_websiteno readOnlyHint or destructiveHint
  • noteTC24server8 of 8 tools have no outputSchema

The checks from /check and anchor check, run each day on the list above: about 1,106 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.