{
  "data": {
    "tool": {
      "category": "",
      "endpoint": "https://scanlabsai.com/api/mcp",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/scanlabsai-scanner.json",
      "kind": "mcp",
      "listed": "indexed",
      "liveUrl": "https://www.anchorterminal.com/api/v1/live/scanlabsai-scanner.json",
      "markdownUrl": "https://www.anchorterminal.com/tools/scanlabsai-scanner.md",
      "mcpTools": {
        "check": {
          "checker": "anchor-check/1.0",
          "totalTokens": 1106,
          "counts": {
            "error": 0,
            "note": 1,
            "warn": 8
          },
          "findings": [
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "buy_credits",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "check_credits",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "compliance_report",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_fix_guidance",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_pricing",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "lookup_cves",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"lookup\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "scan_agent",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "scan_website",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Set readOnlyHint: true if it only reads; otherwise set destructiveHint and idempotentHint."
            },
            {
              "rule": "TC24",
              "severity": "note",
              "message": "8 of 8 tools have no outputSchema",
              "fix": "Declare outputSchema for tools that return structured data, and return structuredContent that matches it."
            }
          ]
        },
        "checkedAt": "2026-10-04T22:23:44Z",
        "count": 8,
        "note": "answered without the initialize handshake",
        "schemaTokens": 1106,
        "status": "ok",
        "tools": [
          {
            "name": "scan_website",
            "description": "Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that you can analyse, act on, and the user can save as security-report.md. Checks OWASP Top 10, CVEs, SSL/TLS, security headers and DNS. Use deep=true for a comprehensive scan (40,000+ vectors, slower). Only scan sites the user is authorised to test.",
            "inputSchema": {
              "properties": {
                "deep": {
                  "description": "Run a deep scan (comprehensive, slower). Defaults to false.",
                  "type": "boolean"
                },
                "url": {
                  "description": "The website URL to scan, e.g. https://example.com",
                  "type": "string"
                }
              },
              "required": [
                "url"
              ],
              "type": "object"
            }
          },
          {
            "name": "scan_agent",
            "description": "Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency — mapped to the OWASP LLM Top 10, and return a Markdown report. This is agent-to-agent scanning: use it to assess another agent from here. Two target kinds are supported: kind=\"openai\" for an OpenAI-compatible chat-completions endpoint, or kind=\"mcp\" for an MCP server (its tool manifest is audited for tool-poisoning and over-broad capabilities). Requires a ScanLabsAI API key in the connection; each agent scan uses 5 AI credits. Probing is active and adversarial — only scan agents you own or are authorised to test.",
            "inputSchema": {
              "properties": {
                "apiKey": {
                  "description": "Optional bearer token / API key the target agent requires. Sent to the target only; not stored.",
                  "type": "string"
                },
                "deep": {
                  "description": "Run deeper probes (jailbreak + resource-exhaustion). Defaults to false.",
                  "type": "boolean"
                },
                "endpoint": {
                  "description": "The agent endpoint URL (chat-completions URL, or MCP server URL).",
                  "type": "string"
                },
                "kind": {
                  "description": "Target type: \"openai\" for a chat-completions endpoint, \"mcp\" for an MCP server.",
                  "enum": [
                    "openai",
                    "mcp"
                  ],
                  "type": "string"
                },
                "model": {
                  "description": "Model name for OpenAI-compatible endpoints, e.g. gpt-4o-mini.",
                  "type": "string"
                }
              },
              "required": [
                "kind",
                "endpoint"
              ],
              "type": "object"
            }
          },
          {
            "name": "compliance_report",
            "description": "Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility, PCI DSS 4.0 payment security and general standards. Returns an overall score, per-category scores and the failing/at-risk checks with recommendations, as Markdown. Requires a ScanLabsAI API key in the connection; costs 1 AI credit per report. Only run against sites you are authorised to assess.",
            "inputSchema": {
              "properties": {
                "url": {
                  "description": "The website URL to assess for compliance, e.g. https://example.com",
                  "type": "string"
                }
              },
              "required": [
                "url"
              ],
              "type": "object"
            }
          },
          {
            "name": "get_fix_guidance",
            "description": "Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. \"missing Content-Security-Policy header\", \"SQL injection\", a CVE id). Returns actionable fixes.",
            "inputSchema": {
              "properties": {
                "issue": {
                  "description": "The vulnerability, finding title, or CVE id to fix.",
                  "type": "string"
                }
              },
              "required": [
                "issue"
              ],
              "type": "object"
            }
          },
          {
            "name": "lookup_cves",
            "description": "Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.",
            "inputSchema": {
              "properties": {
                "keyword": {
                  "description": "Optional keyword, e.g. \"wordpress\" or \"openssl\".",
                  "type": "string"
                },
                "limit": {
                  "description": "Max results (1-25). Defaults to 10.",
                  "type": "number"
                }
              },
              "type": "object"
            }
          },
          {
            "name": "get_pricing",
            "description": "Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.",
            "inputSchema": {
              "properties": {},
              "type": "object"
            }
          },
          {
            "name": "check_credits",
            "description": "Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at https://scanlabsai.com/mcp.",
            "inputSchema": {
              "properties": {},
              "type": "object"
            }
          },
          {
            "name": "buy_credits",
            "description": "Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added automatically once payment completes. Packs: starter (5), pro (15), agency (50).",
            "inputSchema": {
              "properties": {
                "pack": {
                  "description": "Pack id: starter, pro, or agency. Defaults to pro.",
                  "type": "string"
                }
              },
              "type": "object"
            }
          }
        ]
      },
      "name": "ScanLabsAI Security Scanner",
      "note": "Indexed from the official MCP registry: facts and our own checks, not reviewed, so no score, grade or rank.",
      "packages": [
        {
          "registryType": "npm",
          "identifier": "@scanlabsai/mcp-server",
          "version": "1.0.0",
          "transport": "stdio"
        }
      ],
      "pageJsonUrl": "https://www.anchorterminal.com/tools/scanlabsai-scanner.json",
      "popularity": {
        "npmWeekly": 18
      },
      "registryName": "com.scanlabsai/scanner",
      "remotes": [
        {
          "type": "streamable-http",
          "url": "https://scanlabsai.com/api/mcp"
        }
      ],
      "repository": "",
      "reviewed": false,
      "slug": "scanlabsai-scanner",
      "source": "the official MCP registry",
      "sourceUrl": "https://registry.modelcontextprotocol.io/v0.1/servers?search=com.scanlabsai/scanner",
      "summary": "Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes",
      "updatedAt": "2026-09-14T08:15:36Z",
      "url": "https://www.anchorterminal.com/tools/scanlabsai-scanner",
      "vendor": "scanlabsai.com",
      "vendorUrl": "https://scanlabsai.com",
      "version": "1.1.0",
      "websiteUrl": "https://scanlabsai.com",
      "where": "both",
      "why": [
        "vendor"
      ]
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/scanlabsai-scanner",
    "json": "https://www.anchorterminal.com/tools/scanlabsai-scanner.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/scanlabsai-scanner.md",
    "slim": "https://www.anchorterminal.com/tools/scanlabsai-scanner.min.md"
  },
  "markdown": "# ScanLabsAI Security Scanner\n\n\u003e Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/\n\n- Kind: MCP server, by scanlabsai.com (https://scanlabsai.com)\n- Listed because: It's published in the registry under scanlabsai.com, a namespace the registry only gives to whoever proves they control that domain.\n- What the official MCP registry says: Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes\n\n## Facts\n\n- MCP registry: `com.scanlabsai/scanner` 1.1.0\n- Endpoint: https://scanlabsai.com/api/mcp (streamable HTTP)\n- Package: npm `@scanlabsai/mcp-server` (stdio)\n- Website: https://scanlabsai.com\n- npm downloads a week: 18\n- Registry entry updated: 2026-09-14\n\n## Tools\n\n- Tools it lists (8, about 1,106 tokens of context, `tools/list` without credentials, checked 2026-10-04 22:23 UTC):\n  - `scan_website`: Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that…\n  - `scan_agent`: Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency…\n  - `compliance_report`: Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility,…\n  - `get_fix_guidance`: Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. \"missing Content-Security-Policy header\", \"SQL injection\",…\n  - `lookup_cves`: Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary.\n  - `get_pricing`: Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs.\n  - `check_credits`: Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at…\n  - `buy_credits`: Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added…\n- How its tools read to an agent (0 errors, 8 warnings, 1 note, about 1,106 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score):\n  - warn TC16 buy_credits: no readOnlyHint or destructiveHint\n  - warn TC16 check_credits: no readOnlyHint or destructiveHint\n  - warn TC16 compliance_report: no readOnlyHint or destructiveHint\n  - warn TC16 get_fix_guidance: no readOnlyHint or destructiveHint\n  - warn TC16 get_pricing: no readOnlyHint or destructiveHint\n  - warn TC16 lookup_cves: no readOnlyHint or destructiveHint\n  - warn TC16 scan_agent: no readOnlyHint or destructiveHint\n  - warn TC16 scan_website: no readOnlyHint or destructiveHint\n  - note TC24 server: 8 of 8 tools have no outputSchema\n\n- JSON: https://www.anchorterminal.com/api/v1/tools/scanlabsai-scanner.json\n- Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Indexed",
        "url": "https://www.anchorterminal.com/indexed/"
      },
      {
        "name": "ScanLabsAI Security Scanner",
        "url": ""
      }
    ],
    "description": "ScanLabsAI Security Scanner, an MCP server by scanlabsai.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes",
    "facts": [
      "not reviewed",
      "not ranked",
      "facts only"
    ],
    "h1": "ScanLabsAI Security Scanner",
    "image": "https://www.anchorterminal.com/assets/og/indexed.png",
    "path": "/tools/scanlabsai-scanner",
    "published": "",
    "section": "indexed",
    "title": "ScanLabsAI Security Scanner, indexed from the official MCP registry",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/tools/scanlabsai-scanner"
  },
  "tokens": {
    "markdown": 1000,
    "slim": 930
  },
  "version": 1
}
