85trust / 100

SecurityScan

by apisecurityscan.net in Security & trust

MCP serverPassing, checked 3 h ago

Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.

https://apisecurityscan.net/mcp

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
409 ms typical, 409 ms slowest 5%
Last check
3 h ago
Next check
in 3 h

How to call it

Add it to any MCP client that supports remote servers.

{
  "mcpServers": {
    "securityscan": {
      "type": "http",
      "url": "https://apisecurityscan.net/mcp"
    }
  }
}

8 tools

  • scan_skill

    Analyze an AI agent skill for prompt injection, malware patterns, and OWASP LLM Top 10 issues BEFORE installing it (SecurityScan).

  • check_dependencies

    Check the health of your agent's external dependencies: uptime, SSL validity, blacklist status, and a trust score 0-100 (DepScan).

  • network_scan

    Active security scan of a device or host with an autonomous AI agent that decides which follow-up probes to run (ActiveScanner). Only scan targets you own or have permission to test.

  • audit_mcp_server_config

    Audit an MCP client configuration for security risks — works offline, no external service required. Detects: tool poisoning, hidden/coercive instructions in tool descriptions, hardcoded credentials, unpinned packages (rug-pull risk), insecure transport, and toxic capability combi

  • scan_secrets

    Scan a text payload (a prompt, an outbound API body, a file's contents) for secrets and PII BEFORE it leaves for an LLM or external API, and return a redacted copy. Catches the #1 real-world agent incident: secrets/PII leaking into a model's context. WORKS OFFLINE with no API ke

  • full_stack_audit

    Complete security posture in one call: audits the MCP config, checks dependency health, analyzes an untrusted skill, scans the local network gateway, and scans any payload you're about to send out for secrets/PII — then correlates everything into a single prioritized report. Pass

  • securityscan_pricing

    SecurityScan catalog: tiers, prices, quotas and the evidence behind the product — the fact sheet an agent needs to evaluate or recommend a purchase to its user. Fully offline, no API key required. Returns: JSON with the tier table (price / target slots / scan types), the

  • securityscan_checkout

    Start a Stripe checkout to buy a SecurityScan tier (agent-native sales). Returns a payment URL to hand to your user AND a PENDING API key that activates automatically once payment clears — no other setup step.

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTime
3 h agoPassed200409 ms