Endpoints: 28,729MCP servers: 18,413Payout addresses: 2,070Paid calls: 1,517Letters: 13Defects: 1,321counted just now
teppi

MCP serverus.secscan/secscan

Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts.
UNRATEDActivestreamable-httpsecscan.us

Overview

Score?
UNRATED 0.084
of what a free look can see, on 1 looks
Looks
6
last 18 hr ago
Tools
12

More info

URL
secscan.us/api/mcp
streamable-http
Says it is
secscan 1.1.0
protocol 2025-06-18
In the record since
10 days ago

Among servers18,413 with a card

0median 0.606 · this server 0.084 · highest on record 0.8561

Toolsfrom sha256:55d08d3e37…f8fab5

The tools this server lists, read out of the definition it returned
ToolSchema
add_monitor
Put a site the user owns under continuous monitoring: hourly uptime checks, CVE matching, certificate alerts and regular rescans. Runs a full baseline scan straight away, which use
input · no output
check_domain_verification
Check whether the file or DNS record from start_domain_verification is live. On success the domain is verified and its next scan includes active tests. DNS changes can take a few m
input · no output
dismiss_finding
Mark a finding as a false positive for this site, so future scans of it stop reporting it — the same as Dismiss in the app, and undoable there. ONLY use this after the user has con
input · no output
get_account
How many scans the user can still run — free scans, plan scans and credits — and their plan. Check this before starting several scans.
input · no output
get_report
The finished report for a scan: grade, what the scan tested and what it skipped (a clean grade says nothing about skipped areas, so say so), prioritised findings with fixes and evi
input · no output
get_scan_status
Status of a scan (queued, scanning, analyzing, complete, failed). With wait_seconds (max 60) it waits for the scan to finish and returns the full report as soon as it does.
input · no output
list_monitors
Sites under continuous monitoring: latest grade, last and next scan, uptime check, CVE alerts, new problems in the last scan and certificate expiry. Use the monitor id with monitor
input · no output
list_recent_scans
The user's most recent scans with their status, newest first.
input · no output
list_verified_domains
Domains the user has proved they own. Only these receive active testing (injection, XSS, SSRF, access control); others get passive checks. Verify more at https://secscan.us/domains
input · no output
monitor_scan_now
Run a full scan of a monitored site now instead of waiting for its schedule — e.g. to confirm a fix. Free for plan holders; otherwise uses one of the user's scans, as in the app. T
input · no output
scan_url
Start a SecScan security scan of a web application the user owns or is authorised to test. Returns a scan_id; most scans finish in under a minute — then call get_scan_status with w
input · no output
start_domain_verification
Begin proving the user owns a domain, which unlocks active tests (injection, XSS, SSRF, access control) on its scans. Returns a file to publish on the site, or a DNS TXT record — a
input · no output
Verify it yourselfnpx teppi-check https://secscan.us/api/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M38ZPMQR60EYA0VAGSS0HJ9J