# io.github.securityscan-api/securityscan (pypi · securityscan-mcp)

Security for AI agents: MCP audits, secret redaction, skill vetting, network scans, agent checkout.

- Trust score: 57/100 (low)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- pypi · `securityscan-mcp`: 57/100 (this document), [markdown](https://verifymcp.io/servers/securityscan-api-securityscan/securityscan-mcp.md), [page](https://verifymcp.io/servers/securityscan-api-securityscan/securityscan-mcp)

## Channel facts

- Registry: `pypi`
- Package: `securityscan-mcp`
- Version: `0.2.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 50/100
  - Malware scan not yet available for this package.
  - No known CVEs affecting this package version or its production dependencies.
  - Runs setuptools.build_meta at install time, a recognised native-build step with no shell scripting around it.
  - 1 of 26 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 6/100
  - Repository check failed: the declared repository URL redirects; it must resolve directly.
  - Provenance check failed: no build-provenance attestation is published.
  - License check failed: no license is declared.
  - Actively maintained (last published 20 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 74/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1066 tokens (~133/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 70/100
  - Stability observed for 21 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the io.github.securityscan-api/securityscan MCP server?

io.github.securityscan-api/securityscan runs locally as a PyPI package, launched with uvx securityscan-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add securityscan-api-securityscan -- uvx securityscan-mcp
```

### Cursor

```json
{
  "mcpServers": {
    "securityscan-api-securityscan": {
      "command": "uvx",
      "args": [
        "securityscan-mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "securityscan-api-securityscan": {
      "command": "uvx",
      "args": [
        "securityscan-mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add securityscan-api-securityscan -- uvx securityscan-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "securityscan-api-securityscan": {
      "type": "local",
      "command": [
        "uvx",
        "securityscan-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add securityscan-api-securityscan --command uvx --arg securityscan-mcp
```

### Hermes

```yaml
mcp_servers:
  securityscan-api-securityscan:
    command: "uvx"
    args: ["securityscan-mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "securityscan-api-securityscan": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "securityscan-mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add securityscan-api-securityscan -t stdio -c uvx -a securityscan-mcp
```

### Other

```json
{
  "mcpServers": {
    "securityscan-api-securityscan": {
      "command": "uvx",
      "args": [
        "securityscan-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-19 (score 57, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 56, +1)

No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 55, +1)

No change was recorded against any check on this day. Stability & Change Management went from 47 to 50. That category is still filling its 30-day observation window: 14 days of observed history at the previous scan, 15 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-12 (score 54, +1)

No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-10 (score 53, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-08 (score 52, +1)

No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-07 (score 51, −15)

- [security regression] Malware scan: pass → unverified

### 2026-09-06 (score 66, +3)

- [functional improvement] Stability: unverified → 0.23
- [functional] MCP protocol: Implements a current MCP spec version (2026-07-28).

## MCP tools (8)

### `scan_skill` (~60 tokens)

Scan Skill

Analyze an AI agent skill for prompt injection, malware patterns, and
OWASP LLM Top 10 issues BEFORE installing it (SecurityScan).

Input parameters:

- `skill_url` (string, required): URL of the skill to analyze (e.g. a GitHub skill URL).

Output parameters:

- `result` (string)

### `check_dependencies` (~76 tokens)

Check Dependencies

Check the health of your agent's external dependencies: uptime, SSL
validity, blacklist status, and a trust score 0-100 (DepScan).

Input parameters:

- `endpoints` (array, required): List of URLs your agent/skill depends on,        e.g. ["https://api.openai.com", "https://api.stripe.com"]

Output parameters:

- `result` (string)

### `network_scan` (~193 tokens)

Network Scan

Active security scan of a device or host with an autonomous AI agent that
decides which follow-up probes to run (ActiveScanner). Only scan targets
you own or have permission to test.

Input parameters:

- `authorized` (boolean, required): REQUIRED. You must set this to True to certify that you own         the target or have explicit permission to test it. Setting it         to False (or omitting it) aborts the scan. Scanning without…
- `scan_type` (string): "quick" (~30s, top ports) [default], "standard" (~2min,        agent loop), "deep" (~10min, full ports + credentials check)
- `target` (string, required): IP, CIDR, or hostname. Examples: "192.168.1.1", "10.0.0.0/24"

Output parameters:

- `result` (string)

### `audit_mcp_server_config` (~126 tokens)

Audit Mcp Server Config

Audit an MCP client configuration for security risks — works offline,
no external service required. Detects: tool poisoning, hidden/coercive
instructions in tool descriptions, hardcoded credentials, unpinned
packages (rug-pull risk), insecure transport, and toxic capability
combinations (shell + network, file-read + network).

Input parameters:

- `config_json` (string, required): The FULL JSON content of the MCP config file as a string          (e.g. claude_desktop_config.json or .mcp.json). Paste the          file content, not the path.

Output parameters:

- `result` (string)

### `scan_secrets` (~186 tokens)

Scan Secrets

Scan a text payload (a prompt, an outbound API body, a file's contents)
for secrets and PII BEFORE it leaves for an LLM or external API, and
return a redacted copy. Catches the #1 real-world agent incident:
secrets/PII leaking into a model's context.

WORKS OFFLINE with no API key — the detection runs in-process (pure regex
\+ Luhn check, no network). If a SecretScan backend key IS configured, the
scan is routed there instead (which also persists an audit record).

Input parameters:

- `redact` (boolean): If True (default), each match is replaced with a token like     [REDACTED-KEY] / [REDACTED-EMAIL]. If False, only reports.
- `text` (string, required): The payload to inspect (prompt, request body, document text).

Output parameters:

- `result` (string)

### `full_stack_audit` (~214 tokens)

Full Stack Audit

Complete security posture in one call: audits the MCP config, checks
dependency health, analyzes an untrusted skill, scans the local network
gateway, and scans any payload you're about to send out for secrets/PII —
then correlates everything into a single prioritized report. Pass only
what you have; each section is skipped gracefully if its input or service
is missing.

Input parameters:

- `dependency_endpoints`: URLs your stack depends on (optional)
- `mcp_config_json` (string): MCP config content as string (optional)
- `network_authorized` (boolean): REQUIRED to scan network_target. Set True to certify                 you own or have permission to scan it. (optional, default False)
- `network_target` (string): IP to scan, e.g. "192.168.1.1" (optional)
- `skill_url` (string): untrusted skill to vet (optional)
- `text_to_scan` (string): payload to vet for secret/PII egress (optional)

Output parameters:

- `result` (string)

### `securityscan_pricing` (~83 tokens)

Securityscan Pricing

SecurityScan catalog: tiers, prices, quotas and the evidence behind the
product — the fact sheet an agent needs to evaluate or recommend a purchase
to its user. Fully offline, no API key required.

Returns:
    JSON with the tier table (price / target slots / scan types), the
    pricing model, benchmark evidence, and how to buy.

Output parameters:

- `result` (string)

### `securityscan_checkout` (~128 tokens)

Securityscan Checkout

Start a Stripe checkout to buy a SecurityScan tier (agent-native sales).
Returns a payment URL to hand to your user AND a PENDING API key that
activates automatically once payment clears — no other setup step.

Input parameters:

- `email` (string): optional — prefills the Stripe checkout page for your user
- `existing_key` (string): optional — upgrade an existing ask_live_ key instead of           minting a new one
- `tier` (string, required): one of "founder" ($29 one-time), "personal", "executive",   "enterprise" (monthly)

Output parameters:

- `result` (string)

## Diagnostics

Captured diagnostic sections: Provenance, Install scripts, Dependencies. The full working is on the page: https://verifymcp.io/servers/securityscan-api-securityscan/securityscan-mcp#diagnostics

## Score history

- 2026-09-20: 57
- 2026-09-19: 57
- 2026-09-18: 56
- 2026-09-17: 56
- 2026-09-16: 56
- 2026-09-15: 55
- 2026-09-14: 55
- 2026-09-13: 54
- 2026-09-12: 54
- 2026-09-11: 53
- 2026-09-10: 53
- 2026-09-09: 52
- 2026-09-08: 52
- 2026-09-07: 51
- 2026-09-06: 66
- 2026-09-05: 63
- 2026-09-04: 48
- 2026-09-03: 48
- 2026-09-02: 48
- 2026-09-01: 48
- 2026-08-31: 63
- 2026-08-30: 48

## Common questions

### What is the io.github.securityscan-api/securityscan MCP server?

io.github.securityscan-api/securityscan is an MCP server listed in the public MCP registry as io.github.securityscan-api/securityscan. Security for AI agents: MCP audits, secret redaction, skill vetting, network scans, agent checkout. This page covers its PyPI package (securityscan-mcp).

### Is the io.github.securityscan-api/securityscan MCP server safe to use?

io.github.securityscan-api/securityscan scores 57 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.github.securityscan-api/securityscan MCP server expose?

io.github.securityscan-api/securityscan exposes 8 tools: scan_skill, check_dependencies, network_scan, audit_mcp_server_config, scan_secrets, and 3 more. Their descriptions and schemas cost roughly 1,066 tokens of context every time the server is loaded.

### Is the io.github.securityscan-api/securityscan MCP server still maintained?

io.github.securityscan-api/securityscan is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- PyPI project: https://pypi.org/project/securityscan-mcp/
- Socket report: https://socket.dev/pypi/package/securityscan-mcp
- Changelog RSS feed: https://verifymcp.io/servers/securityscan-api-securityscan/securityscan-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/securityscan-api-securityscan/securityscan-mcp.json
- HTML version of this page: https://verifymcp.io/servers/securityscan-api-securityscan/securityscan-mcp
