{"name":"io.github.securityscan-api/securityscan","slug":"securityscan-api-securityscan","title":null,"description":"Security for AI agents: MCP audits, secret redaction, skill vetting, network scans, agent checkout.","url":"https://mcp.market/server/securityscan-api-securityscan","rating":null,"grade":"A","score":89,"certified":false,"status":"active","category":"ai","tags":["ai","security"],"presence":{"score":21,"stars":0,"forks":0,"downloads_week":16,"last_push_at":"2026-08-30T15:56:53.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"pypi","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/securityscan-api/securitystack-mcp","website":null,"version":"0.2.0","remotes":[],"packages":[{"registryType":"pypi","identifier":"securityscan-mcp","version":"0.2.0","transport":{"type":"stdio"}}],"tools":[{"name":"audit_mcp_server_config","description":"Audit an MCP client configuration for security risks — works offline, no external service required. Detects: tool poisoning, hidden/coercive instructions in tool descriptions, hardcoded credentials, unpinned packages (rug-pull risk), insecure transport, and toxic capability combinations (shell + network, file-read + network).","write_action":false,"price_micros":0,"input_schema":null},{"name":"check_dependencies","description":"Check the health of your agent's external dependencies: uptime, SSL validity, blacklist status, and a trust score 0-100 (DepScan).","write_action":false,"price_micros":0,"input_schema":null},{"name":"full_stack_audit","description":"Complete security posture in one call: audits the MCP config, checks dependency health, analyzes an untrusted skill, scans the local network gateway, and scans any payload you're about to send out for secrets/PII — then correlates everything into a single prioritized report. Pass only what you have; each section is skipped gracefully if its input or service is missing.","write_action":false,"price_micros":0,"input_schema":null},{"name":"network_scan","description":"Active security scan of a device or host with an autonomous AI agent that decides which follow-up probes to run (ActiveScanner). Only scan targets you own or have permission to test.","write_action":false,"price_micros":0,"input_schema":null},{"name":"scan_secrets","description":"Scan a text payload (a prompt, an outbound API body, a file's contents) for secrets and PII BEFORE it leaves for an LLM or external API, and return a redacted copy. Catches the #1 real-world agent incident: secrets/PII leaking into a model's context.","write_action":false,"price_micros":0,"input_schema":null},{"name":"scan_skill","description":"Analyze an AI agent skill for prompt injection, malware patterns, and OWASP LLM Top 10 issues BEFORE installing it (SecurityScan).","write_action":false,"price_micros":0,"input_schema":null},{"name":"securityscan_checkout","description":"Start a Stripe checkout to buy a SecurityScan tier (agent-native sales). Returns a payment URL to hand to your user AND a PENDING API key that activates automatically once payment clears — no other setup step.","write_action":false,"price_micros":0,"input_schema":null},{"name":"securityscan_pricing","description":"SecurityScan catalog: tiers, prices, quotas and the evidence behind the product — the fact sheet an agent needs to evaluate or recommend a purchase to its user. Fully offline, no API key required.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":89,"grade":"A","scanned_at":"2026-09-20T20:57:25.837Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-20T20:57:25.796Z","components":{"code":{"score":25,"max":25,"notes":["5 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 21 days ago"]},"identity":{"score":6,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[],"inputs":{"packages":[{"registryType":"pypi","identifier":"securityscan-mcp","version":"0.2.0","found":true,"weeklyDownloads":16,"license":"Apache-2.0","dependencyCount":2,"publishedAt":"2026-08-30T16:19:00.636118Z"}],"repo":{"found":true,"owner":"securityscan-api","repo":"securitystack-mcp","archived":false,"pushedAt":"2026-08-30T15:56:53Z","stars":0,"forks":0,"openIssues":0,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/263033342?v=4","ownerCreatedAt":"2026-02-21T17:00:48Z","license":"Apache-2.0"},"icon":{"url":null,"source":"none"},"presence":{"stars":0,"forks":0,"downloadsWeek":16,"license":"Apache-2.0","lastPushAt":"2026-08-30T15:56:53.000Z","score":21}}}},"grade_history":[],"reviews":[]}