ScanLabsAI Security Scanner by scanlabsai.com
MCP server · indexed, not reviewed
HostedLocalvendor's own
Not reviewed
No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Facts
- MCP registry
com.scanlabsai/scanner· 1.1.0- Endpoint
https://scanlabsai.com/api/mcp- Packages
npm@scanlabsai/mcp-server stdio- Website
- scanlabsai.com
- npm / week
- 18
- Registry entry
- updated 14 Sep 2026
From the official MCP registry, the package registries and our own checks. JSON · Markdown
Why it's listed
- It's published in the registry under scanlabsai.com, a namespace the registry only gives to whoever proves they control that domain.
Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.
Tools it lists 8 · about 1,106 tokens of context · checked 13 minutes ago
| Tool | What it does | Hint |
|---|---|---|
scan_website | Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as… | |
scan_agent | Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown… | |
compliance_report | Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns… | |
get_fix_guidance | Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection", a CVE id). Returns actionable fixes. | |
lookup_cves | Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary. | |
get_pricing | Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs. | |
check_credits | Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp. | |
buy_credits | Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro… |
What https://scanlabsai.com/api/mcp answered to tools/list, asked without credentials. answered without the initialize handshake. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.
How its tools read to an agent 0 errors · 8 warnings · 1 note
- warnTC16buy_creditsno readOnlyHint or destructiveHint
- warnTC16check_creditsno readOnlyHint or destructiveHint
- warnTC16compliance_reportno readOnlyHint or destructiveHint
- warnTC16get_fix_guidanceno readOnlyHint or destructiveHint
- warnTC16get_pricingno readOnlyHint or destructiveHint
- warnTC16lookup_cvesno readOnlyHint or destructiveHint
- warnTC16scan_agentno readOnlyHint or destructiveHint
- warnTC16scan_websiteno readOnlyHint or destructiveHint
- noteTC24server8 of 8 tools have no outputSchema
The checks from /check and anchor check, run each day on the list above: about 1,106 tokens of definitions. Not part of the score yet. Check your own server.