MCP servercom.scanmalware.mcp/scanmalware-mcp
MCP server for ScanMalware.com URL scanning, malware detection, and analysis.
Overview
Score?
UNRATED 0.813
of what a free look can see, on 31 looks
Looks
36
last 4 hr ago
Tools
128
changed 1 day ago
More info
URL
mcp.scanmalware.com/mcp
streamable-http
Says it is
ScanMalware MCP 1.30.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.813 · highest on record 0.8561
Toolsfrom sha256:5033374c95…abd14b · +0 −0 1 day ago
| Tool | Schema |
|---|---|
| find_js_fingerprint_similar_by_hash Find similar JS fingerprints by hash. |
input · output |
| get_ai_analysis Get AI analysis for a scan_id (if available). |
input · output |
| get_analyzer_results Get analyzer results for a scan_id. |
input · output |
| get_analyzer_stats Get analyzer statistics overview. |
input · output |
| get_api_root Get API root metadata. |
input · output |
| get_bot_protection Get bot-protection detection for a scan_id. |
input · output |
| get_capabilities_by_date Get capability stats by date. |
input · output |
| get_clipboard_events Get clipboard events for a scan_id. |
input · output |
| get_clipboard_stats Get clipboard statistics. |
input · output |
| get_cpe_by_scan Get CPEs for a scan_id. |
input · output |
| get_cpe_stats Get CPE statistics. |
input · output |
| get_ct_certificates Get certificate transparency data for a domain. |
input · output |
| get_ct_dns_records Get CT DNS records for a domain. |
input · output |
| get_ct_domains_by_ip Find CT domains on an IP address. |
input · output |
| get_ct_similar_domains Find similar CT domains for a domain. |
input · output |
| get_ct_timeline Get CT certificate timeline for a domain. |
input · output |
| get_domain_history Get historical scans for a domain (paginated). |
input · output |
| get_domain_scans Get recent scans for a domain. |
input · output |
| get_domain_stats Get summary statistics for a domain. |
input · output |
| get_favicon Get the favicon for a scan_id: size, hashes, and the image itself base64-encoded. Use the md5 with search_by_favicon to pivot. |
input · output |
| get_favicon_stats Get favicon statistics. This aggregate query can take up to 90 seconds by default. |
input · output |
| get_health Get API health status. |
input · output |
| get_ids_alerts Get IDS alerts for a scan_id. |
input · output |
| get_ip_stats Get IP statistics (paginated). |
input · output |
| get_jarm_signatures Get JARM signatures for a scan_id. |
input · output |
| get_jarm_stats Get JARM statistics. |
input · output |
| get_js_fingerprinter2 Get JS Fingerprinter2 results for a scan_id. |
input · output |
| get_js_fingerprinter2_coverage Get JS Fingerprinter2 fingerprint coverage. |
input · output |
| get_js_fingerprinter2_health Get JS Fingerprinter2 health check. |
input · output |
| get_js_fingerprinter2_stats Get JS Fingerprinter2 stats. |
input · output |
| get_js_fingerprints Get JavaScript fingerprints for a scan_id. |
input · output |
| get_js_library_inventory Get JS fingerprint library inventory. |
input · output |
| get_js_segments_by_scan Get JS segments for a scan_id. |
input · output |
| get_js_segments_suspicious Get suspicious JS segments for a scan_id. |
input · output |
| get_js_segments_unknown Get unknown JS segments for a scan_id. |
input · output |
| get_jsfingerprint Get JS fingerprint by ID. |
input · output |
| get_jsfingerprint_bundle_stats Get JS fingerprint bundle statistics. |
input · output |
| get_jsfingerprint_hash_prevalence Get JS fingerprint hash prevalence for a scan_id. |
input · output |
| get_jsfingerprint_library_stats Get JS fingerprint library statistics. |
input · output |
| get_jsfingerprint_similar Find similar JS fingerprints. |
input · output |
| get_jsfingerprint_similarity_counts Get JS fingerprint similarity counts. |
input · output |
| get_jsfingerprint_source Get JS fingerprint source. |
input · output |
| get_latest_capabilities Get latest capability stats. |
input · output |
| get_malware_by_scan Get malware details for a scan_id. |
input · output |
| get_malware_stats Get malware stats. |
input · output |
| get_netlog Describe the network log (Chrome NetLog) for a scan_id: whether one exists, its size, and its encoding. The log itself is not returned - these are routinely tens of megabytes gzipp |
input · output |
| get_ocr_by_scan Get OCR data for a scan_id. |
input · output |
| get_ocr_stats Get OCR stats. |
input · output |
| get_open_graph Get Open Graph data for a scan_id. |
input · output |
| get_pastejacking Get pastejacking findings for a scan_id. |
input · output |
| get_pcap_metadata Get PCAP metadata for a scan_id. |
input · output |
| get_platform_stats Get platform statistics. |
input · output |
| get_popular_technologies Get popular technologies (paginated). |
input · output |
| get_rdap Get RDAP details for a scan_id. |
input · output |
| get_recent_scans Get recent public scans (paginated). |
input · output |
| get_recent_threats Get recent malware threats. |
input · output |
| get_recent_yara_threats Get recent YARA threats. |
input · output |
| get_safe_browsing Get safe browsing threats for a scan_id. |
input · output |
| get_safe_browsing_stats Get safe browsing stats. |
input · output |
| get_scan_ioc Get IOC matches for a scan_id. |
input · output |
| get_scan_progress Get scan progress by scan_id. |
input · output |
| get_scan_reports Get available reports for a scan_id. |
input · output |
| get_scan_result Get full scan result by scan_id. |
input · output |
| get_scan_summary Get compact scan summary by scan_id. |
input · output |
| get_screenshot_stats Get screenshot statistics. |
input · output |
| get_technologies_by_scan Get detected technologies for a scan_id. |
input · output |
| get_technology_combinations Get technology combinations (paginated). |
input · output |
| get_technology_stats Get technology stats. |
input · output |
| get_tls_asn1 Get TLS certificate ASN.1 data for a scan_id. |
input · output |
| get_tls_details Get TLS details for a scan_id. |
input · output |
| get_top_tracking_keys Get top tracking keys. |
input · output |
| get_yara_by_scan Get YARA results for a scan_id. |
input · output |
| get_yara_matches Get YARA matches for a scan_id. |
input · output |
| get_yara_stats Get YARA stats. |
input · output |
| run_js_differential_analysis Run JS differential analysis for a scan_id. |
input · output |
| search_ai_classification Search AI scans by classification. |
input · output |
| search_ai_high_risk Search AI high-risk scans. |
input · output |
| search_ai_scam_type Search AI scans by scam type. |
input · output |
| search_analyzer_high_risk Search analyzer high-risk scans (paginated). |
input · output |
| search_by_asn Search scans by ASN (paginated). |
input · output |
| search_by_favicon Search scans by favicon hash (paginated). |
input · output |
| search_by_fuzzy_hash Search scans by fuzzy hash (paginated). |
input · output |
| search_by_ip Search scans by IP address (paginated). |
input · output |
| search_by_jarm Search scans by JARM signature (paginated). |
input · output |
| search_by_nameserver Search scans by nameserver. |
input · output |
| search_by_registrar Search scans by registrar (paginated). |
input · output |
| search_by_screenshot_hash Search scans by screenshot hash (paginated). |
input · output |
| search_cpe Search CPEs by pattern (paginated). |
input · output |
| search_favicon_mmh3 Search favicon by mmh3 hash (paginated). |
input · output |
| search_js_fingerprint_by_bundler Search JS fingerprints by bundler type. |
input · output |
| search_js_fingerprint_by_cdn Search JS fingerprints by CDN. |
input · output |
| search_js_fingerprint_by_fuzzy_hash Search JS fingerprints by fuzzy hash. |
input · output |
| search_js_fingerprint_by_library Search JS fingerprints by detected library name. Use identifiers from get_js_library_inventory, such as 'react' or 'nextjs'. The display name 'Next.js' is accepted as an alias for |
input · output |
| search_js_fingerprint_by_library_version Search JS fingerprints by library version. |
input · output |
| search_js_fingerprint_by_md5 Search JS fingerprints by MD5 hash. |
input · output |
| search_js_fingerprint_by_normalized_hash Search JS fingerprints by normalized hash. |
input · output |
| search_js_fingerprint_by_server Search JS fingerprints by server type. |
input · output |
| search_js_fingerprint_by_sha1 Search JS fingerprints by SHA1 hash. |
input · output |
| search_js_fingerprint_by_sha256 Search JS fingerprints by SHA256 hash. |
input · output |
| search_js_fingerprint_obfuscated Search obfuscated JS fingerprints. |
input · output |
| search_js_fingerprint_patterns Search JS fingerprints by patterns. Supply at least one boolean filter: has_eval, has_crypto, has_websocket, high_entropy, no_library, or cdn_mismatch. For example, use has_eval=tr |
input · output |
| search_js_fingerprinter2_composite_hash Search JS Fingerprinter2 by composite hash. |
input · output |
| search_js_fingerprinter2_signature Search JS Fingerprinter2 by signature. |
input · output |
| search_js_fingerprinter2_similar Search JS Fingerprinter2 similar scans. |
input · output |
| search_js_malware_families Search JS malware families. Supply min_cluster_size (at least 1) or similarity_threshold (0 to 1), or both; limit alone is not a filter. For example, use min_cluster_size=2. |
input · output |
| search_js_obfuscation Search JS obfuscation signals. Supply at least one of risk_level, min_risk_score, or has_eval; limit alone is not a filter. For example, use has_eval=true. Explicit false and a min |
input · output |
| search_js_segments_by_hash Search JS segments by code hash. |
input · output |
| search_js_segments_by_normalized_hash Search JS segments by normalized hash. |
input · output |
| search_jsfingerprints_by_bundler Search JS fingerprints by bundler (paginated). |
input · output |
| search_jsfingerprints_by_fuzzy_hash Search JS fingerprints by fuzzy hash (paginated). |
input · output |
| search_jsfingerprints_by_library Search JS fingerprints by library (paginated). |
input · output |
| search_jsfingerprints_by_library_version Search JS fingerprints by library version (paginated). |
input · output |
| search_jsfingerprints_by_md5 Search JS fingerprints by MD5 (paginated). |
input · output |
| search_jsfingerprints_by_normalized_hash Search JS fingerprints by normalized hash (paginated). |
input · output |
| search_jsfingerprints_by_sha1 Search JS fingerprints by SHA1 (paginated). |
input · output |
| search_jsfingerprints_by_sha256 Search JS fingerprints by SHA256 (paginated). |
input · output |
| search_ocr Search OCR text (paginated). q must contain at least 3 characters after trimming. This query can take up to 90 seconds by default; allow it to finish before retrying. |
input · output |
| search_ocr_pattern Search OCR by pattern (paginated). |
input · output |
| search_scans Search scans (q must be at least 3 characters). |
input · output |
| search_semantic Semantic search over scans (paginated). |
input · output |
| search_similar_scans Search for scans similar to a scan_id (paginated). |
input · output |
| search_similar_screenshots Search for similar screenshots by hash. |
input · output |
| search_suspicious_clipboard Search suspicious clipboard indicators (paginated). |
input · output |
| search_technologies Search technologies (paginated). |
input · output |
| search_tracking_key Search by tracking key (paginated). |
input · output |
| submit_scan Submit a URL to ScanMalware for scanning. WARNING: scan_type defaults to 'public', which publishes the target URL and scan results in the public feed and makes them visible to othe |
input · output |
| submit_scan_report Submit a scan report. |
input · output |
| wait_for_scan Poll until a scan reaches a terminal status, returning the final summary. |
input · output |
Verify it yourself
npx teppi-check https://mcp.scanmalware.com/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ28RFSSAGM938DHWXNYRR