# ScanLabsAI Security Scanner (slim) > ScanLabsAI Security Scanner, an MCP server by scanlabsai.com, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes - Full: https://www.anchorterminal.com/tools/scanlabsai-scanner.md (~1,000 tokens) · this version ~930 tokens · JSON https://www.anchorterminal.com/tools/scanlabsai-scanner.json · canonical https://www.anchorterminal.com/tools/scanlabsai-scanner - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 # ScanLabsAI Security Scanner > Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/ - Kind: MCP server, by scanlabsai.com (https://scanlabsai.com) - Listed because: It's published in the registry under scanlabsai.com, a namespace the registry only gives to whoever proves they control that domain. - What the official MCP registry says: Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes ## Facts - MCP registry: `com.scanlabsai/scanner` 1.1.0 - Endpoint: https://scanlabsai.com/api/mcp (streamable HTTP) - Package: npm `@scanlabsai/mcp-server` (stdio) - Website: https://scanlabsai.com - npm downloads a week: 18 - Registry entry updated: 2026-09-14 ## Tools - Tools it lists (8, about 1,106 tokens of context, `tools/list` without credentials, checked 2026-10-04 22:23 UTC): - `scan_website`: Run a ScanLabsAI security scan against a website and return a full Markdown vulnerability report (grouped by severity, with descriptions and remediation) that… - `scan_agent`: Red-team an AI agent for security weaknesses — prompt injection, system-prompt leakage, sensitive-data disclosure, unsafe output handling and excessive agency… - `compliance_report`: Generate a website compliance report — the same automated assessment the ScanLabsAI agency portal runs — covering GDPR/CCPA privacy, WCAG 2.1 AA accessibility,… - `get_fix_guidance`: Get detailed, step-by-step remediation guidance for a specific vulnerability or security issue (e.g. "missing Content-Security-Policy header", "SQL injection",… - `lookup_cves`: Look up recent CVEs from the NIST NVD feed, optionally filtered by keyword. Returns id, severity, score and summary. - `get_pricing`: Get ScanLabsAI pricing: the free-first-scan policy and AI credit packs. - `check_credits`: Check the signed-in account's AI credit balance. Requires a ScanLabsAI API key in the MCP connection (Authorization: Bearer slai_...). Create one at… - `buy_credits`: Get a secure Stripe checkout link to buy an AI credit pack for the signed-in account. Requires a ScanLabsAI API key in the MCP connection. Credits are added… - How its tools read to an agent (0 errors, 8 warnings, 1 note, about 1,106 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score): - warn TC16 buy_credits: no readOnlyHint or destructiveHint - warn TC16 check_credits: no readOnlyHint or destructiveHint - warn TC16 compliance_report: no readOnlyHint or destructiveHint - warn TC16 get_fix_guidance: no readOnlyHint or destructiveHint - warn TC16 get_pricing: no readOnlyHint or destructiveHint - warn TC16 lookup_cves: no readOnlyHint or destructiveHint - warn TC16 scan_agent: no readOnlyHint or destructiveHint - warn TC16 scan_website: no readOnlyHint or destructiveHint - note TC24 server: 8 of 8 tools have no outputSchema - JSON: https://www.anchorterminal.com/api/v1/tools/scanlabsai-scanner.json - Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming