Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,071Paid calls: 1,549Letters: 14Defects: 1,323counted 4 min ago
teppi

Server definition

Hash
sha256:55d08d3e37dbff4d5fa41734329063f845b166e20fa2f6b2073ec880a4f8fab5
What it is
What a remote MCP server returned when asked what it offers: 12 tools

The blob, as servednamed by its sha256

{ "instructions": "SecScan scans a live web application from the outside and reports its security problems. Only scan applications the user owns or is authorised to test. Typical flow: scan_url -> get_scan_status with wait_seconds 60 (most scans finish in under a minute, and the call returns the report as soon as it does) -> for a large report, get_report with offset for more pages, or min_severity \"high\" to focus. Work through critical and high findings first, and use the fix prompt in the report — it is written for the user's editor. Active tests (injection, XSS, SSRF, access control) run only on domains listed by list_verified_domains; say so if a scan was passive-only. Each scan spends one of the user's free scans, plan scans or credits, so do not start a scan the user did not ask for. The same applies to add_monitor and monitor_scan_now; get_account says how many scans are left. To unlock active tests, use start_domain_verification, publish the file or DNS record it returns, then check_domain_verification. Only call dismiss_finding when the user has confirmed a finding is a false positive — never to improve a grade.", "tools": [ { "description": "Put a site the user owns under continuous monitoring: hourly uptime checks, CVE matching, certificate alerts and regular rescans. Runs a full baseline scan straight away, which uses one of the user's scans exactly as in the app (free for plan holders). Returns the baseline scan_id for get_scan_status.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "url": { "description": "The site to monitor, e.g. https://example.com", "maxLength": 2048, "minLength": 1, "type": "string" } }, "required": [ "url" ], "type": "object" }, "name": "add_monitor", "outputSchema": null }, { "description": "Check whether the file or DNS record from start_domain_verification is live. On success the domain is verified and its next scan includes active tests. DNS changes can take a few minutes.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "The domain passed to start_domain_verification", "maxLength": 253, "minLength": 1, "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "check_domain_verification", "outputSchema": null }, { "description": "Mark a finding as a false positive for this site, so future scans of it stop reporting it — the same as Dismiss in the app, and undoable there. ONLY use this after the user has confirmed the finding is wrong; never dismiss a real problem to improve a grade.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "finding_name": { "description": "The finding's name exactly as get_report shows it", "maxLength": 300, "minLength": 1, "type": "string" }, "scan_id": { "description": "The scan whose report contains the finding", "type": "string" } }, "required": [ "scan_id", "finding_name" ], "type": "object" }, "name": "dismiss_finding", "outputSchema": null }, { "description": "How many scans the user can still run — free scans, plan scans and credits — and their plan. Check this before starting several scans.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": {}, "type": "object" }, "name": "get_account", "outputSchema": null }, { "description": "The finished report for a scan: grade, what the scan tested and what it skipped (a clean grade says nothing about skipped areas, so say so), prioritised findings with fixes and evidence, and a fix prompt written for the user's AI editor. Findings come 25 per page, most severe first — pass offset for the next page, or min_severity (e.g. \"high\") to focus on what matters most.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "limit": { "description": "Findings per page (default 25, max 50)", "maximum": 50, "minimum": 1, "type": "integer" }, "min_severity": { "description": "Only findings at this severity or worse, e.g. \"high\"", "enum": [ "critical", "high", "medium", "low", "info" ], "type": "string" }, "offset": { "description": "Skip this many findings, for the next page", "minimum": 0, "type": "integer" }, "scan_id": { "description": "The scan_id returned by scan_url or list_recent_scans", "type": "string" } }, "required": [ "scan_id" ], "type": "object" }, "name": "get_report", "outputSchema": null }, { "description": "Status of a scan (queued, scanning, analyzing, complete, failed). With wait_seconds (max 60) it waits for the scan to finish and returns the full report as soon as it does.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "scan_id": { "description": "The scan_id returned by scan_url", "type": "string" }, "wait_seconds": { "description": "Wait up to this long for the scan to finish", "maximum": 60, "minimum": 0, "type": "integer" } }, "required": [ "scan_id" ], "type": "object" }, "name": "get_scan_status", "outputSchema": null }, { "description": "Sites under continuous monitoring: latest grade, last and next scan, uptime check, CVE alerts, new problems in the last scan and certificate expiry. Use the monitor id with monitor_scan_now.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": {}, "type": "object" }, "name": "list_monitors", "outputSchema": null }, { "description": "The user's most recent scans with their status, newest first.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "limit": { "maximum": 25, "minimum": 1, "type": "integer" } }, "type": "object" }, "name": "list_recent_scans", "outputSchema": null }, { "description": "Domains the user has proved they own. Only these receive active testing (injection, XSS, SSRF, access control); others get passive checks. Verify more at https://secscan.us/domains.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "properties": {}, "type": "object" }, "name": "list_verified_domains", "outputSchema": null }, { "description": "Run a full scan of a monitored site now instead of waiting for its schedule — e.g. to confirm a fix. Free for plan holders; otherwise uses one of the user's scans, as in the app. Takes the monitor id from list_monitors.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "monitor_id": { "description": "The monitor id from list_monitors or add_monitor", "type": "string" } }, "required": [ "monitor_id" ], "type": "object" }, "name": "monitor_scan_now", "outputSchema": null }, { "description": "Start a SecScan security scan of a web application the user owns or is authorised to test. Returns a scan_id; most scans finish in under a minute — then call get_scan_status with wait_seconds, or get_report. Active tests (injection, XSS, SSRF…) run only on domains the user has verified; others get passive checks. Optionally also reads a public GitHub repository for committed secrets (github_repo); that only contacts GitHub, never the site. Each scan uses one of the user's free scans, plan scans or credits.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "github_repo": { "description": "Optional public GitHub repository to check for committed secrets, e.g. https://github.com/owner/repo. Public repositories only.", "maxLength": 300, "type": "string" }, "url": { "description": "The URL to scan, e.g. https://example.com", "maxLength": 2048, "minLength": 1, "type": "string" } }, "required": [ "url" ], "type": "object" }, "name": "scan_url", "outputSchema": null }, { "description": "Begin proving the user owns a domain, which unlocks active tests (injection, XSS, SSRF, access control) on its scans. Returns a file to publish on the site, or a DNS TXT record — an editor can usually add the file to the codebase and deploy it. Then call check_domain_verification. Calling it again returns the same token, so a record already published stays valid.", "inputSchema": { "$schema": "http://json-schema.org/draft-07/schema#", "additionalProperties": false, "properties": { "domain": { "description": "The domain, e.g. example.com or https://example.com", "maxLength": 253, "minLength": 1, "type": "string" } }, "required": [ "domain" ], "type": "object" }, "name": "start_domain_verification", "outputSchema": null } ] }
Verify it yourselfcurl -s https://api.teppi.xyz/v1/evidence/sha256:55d08d3e37dbff4d5fa41734329063f845b166e20fa2f6b2073ec880a4f8fab5 | sha256sum