
CertScore.ai MCP Light MCP server
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
0 stars
Reviews
Write oneNobody has reviewed CertScore.ai MCP Light yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
CertScore.ai MCP Light tools (4, 1 write)
write = sends, deletes, buys or postscertscore_get_report_evidence_pageFreeRetrieve scan report display content as paginated JSON, without internal diagnostic JSON downloads. The response also offers a single-file full JSON download; private JSON download links expire after five minutes and need no OAuth header; use pagination if your host blocks file downloads. Repeated display records use reportContentRef JSON Pointers. Includes including evidence tables, full-site page and resource inventories, all retained additional-page form fields, form snapshot download references, and retained limitations. Snapshot images are downloaded separately from the returned URLs, with OAuth bearer authentication for workspace scans. Available on OAuth and Light. Start with scanId; follow pagination.nextCursor until complete. Pages share a snapshot; restart if it changes. Each entry has a JSON Pointer path and value; oversized strings use numbered parts. Export completion is not complete observation coverage. Use the concise scan bundle for summaries; use this tool for exhaustive report evidence. No new scan is created.
certscore_get_scan_bundleFreeReturns the completed or completed-limited CertScore evidence bundle for a stable scanId as concise TextContent and matching structuredContent. Available sections include the canonical report overview, bounded projected findings, pre-consent cookie and tracker evidence, coverage limitations, persisted execution provenance, and retrieval URLs. Detail tiers and byte budgets control the bounded response, with explicit returned, total, truncated, and omitted-section metadata. Accept and Reject results distinguish registered decisions from retained after-click facts. Their execution reports succeeded for a completed click and bounded observation, and succeeded_with_confirmation when the consent decision is also verified. Optional afterAction summaries remain useful when registration is unconfirmed; absent or failed capture remains explicitly limited. Consume canonical findings for any scoring effect. Results are automated public-web observations, not legal advice, certification, or a compliance determination.
certscore_get_scan_statusFreeReturns lifecycle status for a stable CertScore scanId. Active responses include phase, heartbeat, estimated progress, retryAfterSeconds, and sometimes a bounded preliminary preConsentPreview. Terminal responses include completion status, CertScore score and risk metadata when available, coverage, persisted execution region and timestamps, report URL, and a next-action field. Preliminary observations are distinct from completed findings.
certscore_scan_sitewrite actionFreeCreates a public-website privacy scan or reuses an eligible recent completed scan. Coverage includes pre-consent storage, trackers, consent and CMP signals, privacy-policy disclosures, transport security, and GDPR/ePrivacy or CCPA/CPRA review signals. The response contains a stable scanId, lifecycle status, retry timing, and sometimes a bounded preliminary preConsentPreview; preliminary data contains no final findings or score. Results are automated public-web observations, not legal advice, certification, or a compliance determination. Tool and workflow documentation: https://certscore.ai/developers/mcp.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 1371ms20/20
- Tool poisoning4 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 1 write-action tools with no auth3/15
- Maintenancelast push 0 days ago15/15
- Maintainer identitynamespace and repository owner differ; website matches verified namespace5/10
Findings (1)
- highWrite-action tools reachable without authentication
auth.open-write
Install directly
claude mcp add --transport http mcp-light https://mcp.certscore.ai/mcp/light
CertScore.ai MCP Light: common questions
- Is CertScore.ai MCP Light MCP server safe?
- Mostly: it is graded B (77/100). Read the CertScore.ai MCP Light safety report
- How do I install CertScore.ai MCP Light?
- It runs remotely at mcp.certscore.ai. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does CertScore.ai MCP Light need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is CertScore.ai MCP Light maintained?
- The last commit was 2 days ago (2026-09-19). The latest release is v0.2.20.
- Is CertScore.ai MCP Light up?
- 100% of our last 7 checks got an answer. We check remote servers about four times a day.
- What can I use instead of CertScore.ai MCP Light?
- Servers from other publishers that do the same job: Domain Liveness MCP server and Dashclaw MCP server.
Alternatives to CertScore.ai MCP Light
Same job from other publishers: the closest match first, then the best rated.
- Domain LivenessIs this business's website still there? Checks apex and www, and DNS separately from HTTP.not reviewedEstablishedA
- DashclawPolicy checks, approvals, records, and governed HTTP capabilities for unattended agents.not reviewedEstablishedB