# SecScan (remote · secscan.us)

Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts.

- Trust score: 83/100 (high trust)
- Change this week: +47
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-01

## Components

- remote · `secscan.us`: 83/100 (this document), [markdown](https://verifymcp.io/servers/us-secscan-secscan/api-mcp.md), [page](https://verifymcp.io/servers/us-secscan-secscan/api-mcp)

## Channel facts

- Endpoint: `https://secscan.us/api/mcp`
- Transports: `streamable-http`
- Auth: `required`
- Version: `1.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-01.

- **Endpoint Security**: 94/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 84/100
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 1276 tokens (~106/item across 12 items; 12 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 17/100
  - Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 98/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 93% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 12 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the SecScan MCP server?

SecScan is a hosted endpoint at https://secscan.us/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http us-secscan-secscan 'https://secscan.us/api/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "us-secscan-secscan": {
      "url": "https://secscan.us/api/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "us-secscan-secscan": {
      "type": "http",
      "url": "https://secscan.us/api/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.us-secscan-secscan]
url = "https://secscan.us/api/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "us-secscan-secscan": {
      "type": "remote",
      "url": "https://secscan.us/api/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add us-secscan-secscan --url 'https://secscan.us/api/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  us-secscan-secscan:
    url: "https://secscan.us/api/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "us-secscan-secscan": {
      "Transport": "http",
      "Url": "https://secscan.us/api/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add us-secscan-secscan -t streamable-http -u 'https://secscan.us/api/mcp'
```

### Other

```json
{
  "mcpServers": {
    "us-secscan-secscan": {
      "type": "http",
      "url": "https://secscan.us/api/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-01 (score 83, +1)

- [security] Tool “scan_url” rewrote its description, which is the text the model reads
- [cosmetic] “scan_url” added an optional parameter “github_repo”

### 2026-09-28 (score 82, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 81, +2)

- [security improvement] Authorization: fail → pass
- [security] First check of Authorization: partial
- [functional improvement] Stability: unverified → 0.03

### 2026-09-26 (score 79, +43)

- [security improvement] Transport: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [security] Authorization: Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token.
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Destructive annotations: pass
- [functional] First check of Tool coverage: 93
- [functional] First check of Schema quality: pass

### 2026-09-25 (score 36, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-23 (score 36)

First indexed and scored.

## MCP tools (12)

### `scan_url` (~173 tokens)

Scan a website

Start a SecScan security scan of a web application the user owns or is authorised to test. Returns a scan_id; most scans finish in under a minute — then call get_scan_status with wait_seconds, or get_report. Active tests (injection, XSS, SSRF…) run only on domains the user has verified; others get passive checks. Optionally also reads a public GitHub repository for committed secrets (github_repo); that only contacts GitHub, never the site. Each scan uses one of the user's free scans, plan scans or credits.

Input parameters:

- `github_repo` (string): Optional public GitHub repository to check for committed secrets, e.g. https://github.com/owner/repo. Public repositories only.
- `url` (string, required): The URL to scan, e.g. https://example.com

### `get_scan_status` (~83 tokens)

Check a scan

Status of a scan (queued, scanning, analyzing, complete, failed). With wait_seconds (max 60) it waits for the scan to finish and returns the full report as soon as it does.

Input parameters:

- `scan_id` (string, required): The scan_id returned by scan_url
- `wait_seconds` (integer): Wait up to this long for the scan to finish

### `get_report` (~170 tokens)

Read a scan report

The finished report for a scan: grade, what the scan tested and what it skipped (a clean grade says nothing about skipped areas, so say so), prioritised findings with fixes and evidence, and a fix prompt written for the user's AI editor. Findings come 25 per page, most severe first — pass offset for the next page, or min_severity (e.g. "high") to focus on what matters most.

Input parameters:

- `limit` (integer): Findings per page (default 25, max 50)
- `min_severity` (string): Only findings at this severity or worse, e.g. "high"
- `offset` (integer): Skip this many findings, for the next page
- `scan_id` (string, required): The scan_id returned by scan_url or list_recent_scans

### `list_recent_scans` (~29 tokens)

List recent scans

The user's most recent scans with their status, newest first.

Input parameters:

- `limit` (integer)

### `list_verified_domains` (~51 tokens)

List verified domains

Domains the user has proved they own. Only these receive active testing (injection, XSS, SSRF, access control); others get passive checks. Verify more at https://secscan.us/domains.

### `get_account` (~36 tokens)

Scans left and plan

How many scans the user can still run — free scans, plan scans and credits — and their plan. Check this before starting several scans.

### `start_domain_verification` (~113 tokens)

Start verifying a domain

Begin proving the user owns a domain, which unlocks active tests (injection, XSS, SSRF, access control) on its scans. Returns a file to publish on the site, or a DNS TXT record — an editor can usually add the file to the codebase and deploy it. Then call check_domain_verification. Calling it again returns the same token, so a record already published stays valid.

Input parameters:

- `domain` (string, required): The domain, e.g. example.com or https://example.com

### `check_domain_verification` (~62 tokens)

Check a domain verification

Check whether the file or DNS record from start_domain_verification is live. On success the domain is verified and its next scan includes active tests. DNS changes can take a few minutes.

Input parameters:

- `domain` (string, required): The domain passed to start_domain_verification

### `list_monitors` (~48 tokens)

List monitored sites

Sites under continuous monitoring: latest grade, last and next scan, uptime check, CVE alerts, new problems in the last scan and certificate expiry. Use the monitor id with monitor_scan_now.

### `add_monitor` (~88 tokens)

Monitor a site

Put a site the user owns under continuous monitoring: hourly uptime checks, CVE matching, certificate alerts and regular rescans. Runs a full baseline scan straight away, which uses one of the user's scans exactly as in the app (free for plan holders). Returns the baseline scan_id for get_scan_status.

Input parameters:

- `url` (string, required): The site to monitor, e.g. https://example.com

### `monitor_scan_now` (~78 tokens)

Rescan a monitored site now

Run a full scan of a monitored site now instead of waiting for its schedule — e.g. to confirm a fix. Free for plan holders; otherwise uses one of the user's scans, as in the app. Takes the monitor id from list_monitors.

Input parameters:

- `monitor_id` (string, required): The monitor id from list_monitors or add_monitor

### `dismiss_finding` (~99 tokens)

Dismiss a false positive

Mark a finding as a false positive for this site, so future scans of it stop reporting it — the same as Dismiss in the app, and undoable there. ONLY use this after the user has confirmed the finding is wrong; never dismiss a real problem to improve a grade.

Input parameters:

- `finding_name` (string, required): The finding's name exactly as get_report shows it
- `scan_id` (string, required): The scan whose report contains the finding

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/us-secscan-secscan/api-mcp#diagnostics

## Score history

- 2026-10-01: 83
- 2026-09-30: 82
- 2026-09-29: 82
- 2026-09-28: 82
- 2026-09-27: 81
- 2026-09-26: 79
- 2026-09-25: 36
- 2026-09-24: 36
- 2026-09-23: 36

## Common questions

### What is the SecScan MCP server?

SecScan is an MCP server listed in the public MCP registry as us.secscan/secscan. Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts. This page covers its hosted endpoint (https://secscan.us/api/mcp).

### Is the SecScan MCP server safe to use?

SecScan scores 83 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the SecScan MCP server expose?

SecScan exposes 12 tools: scan_url, get_scan_status, get_report, list_recent_scans, list_verified_domains, and 7 more. Their descriptions and schemas cost roughly 1,030 tokens of context every time the server is loaded.

### Does the SecScan MCP server require authentication?

Yes. SecScan asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the SecScan MCP server still maintained?

SecScan is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://secscan.us/api/mcp
- Authorisation metadata: https://secscan.us/.well-known/oauth-protected-resource/api/mcp
- Website: https://secscan.info/ai-editors
- Changelog RSS feed: https://verifymcp.io/servers/us-secscan-secscan/api-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/us-secscan-secscan/api-mcp.json
- HTML version of this page: https://verifymcp.io/servers/us-secscan-secscan/api-mcp
