Malinois MCP server
Check a live app you own for public databases, leaked keys and exposed files.
Little public usage data yet
Reviews
Write oneNobody has reviewed Malinois yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Malinois tools (2, 1 write)
write = sends, deletes, buys or postsexplain_findingFreeReturns the plain-language meaning and step-by-step fix for one Malinois finding. Use it while helping the user fix an issue reported by scan_app, or when they ask what a finding means. Pass the rule_id exactly as scan_app returned it. Read-only, no network, instant.
scan_appwrite actionFreeRuns a passive, outside-in security check of a live web app and returns a letter grade (A–F), each issue in plain language with fix steps, and a report link. Use when the user asks whether their deployed app is safe, before launch, or after a redeploy to confirm a fix. It checks for publicly readable Supabase/Firebase data, secret keys (Stripe, OpenAI, Supabase service_role…) in client JavaScript, downloadable .env/.git files, source maps, permissive CORS and missing security headers. Do not use it for apps the user does not own or is not authorized to test, for localhost or private addresses, or to review source code — it only sees what the public URL serves. Behavior: sends ordinary GET requests like a browser (no login, exploitation or load testing); takes about 10–30 seconds; saves the result as a report page on malinois.app, linked in the response; secrets appear only masked. Each app can be checked at most 20 times per hour.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 658ms20/20
- Tool poisoning2 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 1 write-action tools with no auth3/15
- Maintenanceno repository listed3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (2)
- highWrite-action tools reachable without authentication
auth.open-write - lowNo source repository listed
maint.no-repo
Install directly
claude mcp add --transport http scan https://malinois.app/mcp
Malinois: common questions
- Is Malinois MCP server safe?
- With care: it is graded C, so read the findings first (60/100). Read the Malinois safety report
- How do I install Malinois?
- It runs remotely at malinois.app. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does Malinois need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Malinois maintained?
- The latest release is v1.1.0.
- Is Malinois up?
- 100% of our last 2 checks got an answer. We check remote servers about four times a day.
- What can I use instead of Malinois?
- Servers from other publishers that do the same job: b/cited MCP server, MCP server and DNS Doctor MCP server. Compare all Malinois alternatives.
Alternatives to Malinois
Same job from other publishers: the closest match first, then the best rated.
- b/citedAEO tools: scan any URL for AI-citation readiness, read the public leaderboard and citation panel.not reviewedNewB
- MCPClient editing for sites you built: register, scan, publish, go live, invite the client.not reviewedNewC
DNS DoctorScan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.not reviewedGrowingA- OpenQRGenerate, edit and track dynamic (editable) QR codes with scan analytics. Hosted MCP and REST API.not reviewedGrowingA
- BenspdfRead PDFs locally: text, pages, metadata, scan detection, layout, permissions, render, OCR.not reviewedGrowingA