← All servers
S

ScanMalware.com URL Scanner

warnings

mcp.scanmalware.com

MCP server for ScanMalware.com URL scanning, malware detection, and analysis.

https://mcp.scanmalware.com/mcpWebsiteNo authMCP 2025-11-25v0.1.6last checked 9 Oct 2026spoke MCP on 100% of 90 checks (30 days)initialize in 83 ms

Will my client connect?

Decided from what the probe found at the endpoint, and from what each client's own documentation says it can complete. Every row carries the day that documentation was read.

✓Claude CodeConnects

The endpoint answers an anonymous handshake, so no credential is needed.

claude mcp add --transport http scanmalware-com-url-scanner https://mcp.scanmalware.com/mcp

Claude Code docs · read on 2026-08-30

✓Claude (claude.ai & Desktop)Connects

The endpoint answers an anonymous handshake, so no credential is needed.

Settings → Connectors → Add custom connector, then paste https://mcp.scanmalware.com/mcp.

Claude (claude.ai & Desktop) docs · read on 2026-08-30

✓ChatGPTConnects

The endpoint answers an anonymous handshake, so no credential is needed.

Settings → Apps → Advanced settings → Developer mode, then create a connector pointing at https://mcp.scanmalware.com/mcp.

ChatGPT docs · read on 2026-08-30

✓CursorConnects

The endpoint answers an anonymous handshake, so no credential is needed.

{
  "mcpServers": {
    "scanmalware-com-url-scanner": {
      "url": "https://mcp.scanmalware.com/mcp"
    }
  }
}

Cursor docs · read on 2026-08-30

✓VS Code (Copilot)Connects

The endpoint answers an anonymous handshake, so no credential is needed.

{
  "servers": {
    "scanmalware-com-url-scanner": {
      "type": "http",
      "url": "https://mcp.scanmalware.com/mcp"
    }
  }
}

VS Code (Copilot) docs · read on 2026-08-30

How to authenticate

Checked against the endpoint by our probe on 9 Oct 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
No auth
Protected-resource metadata
✕Not found

Without it a client has to guess where the authorization server lives.

Anonymous access
Handshake succeeds; 128 tools listable
Credentials demanded in prose
✕submit_scan

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

What the probe found

warningTools needing credentials are listed without a challenge

1 of the 128 tools listed anonymously say in their own descriptions that they need an account or a key (submit_scan), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

Tools

find_js_fingerprint_similar_by_hashget_ai_analysisget_analyzer_resultsget_analyzer_statsget_api_rootget_bot_protectionget_capabilities_by_dateget_clipboard_eventsget_clipboard_statsget_cpe_by_scanget_cpe_statsget_ct_certificatesget_ct_dns_recordsget_ct_domains_by_ipget_ct_similar_domainsget_ct_timelineget_domain_historyget_domain_scansget_domain_statsget_faviconget_favicon_statsget_healthget_ids_alertsget_ip_statsget_jarm_signaturesget_jarm_statsget_js_fingerprintsget_js_library_inventoryget_js_runtime_behaviourget_js_runtime_coverageget_js_runtime_healthget_js_runtime_statsget_js_segments_by_scanget_js_segments_suspiciousget_js_segments_unknownget_jsfingerprintget_jsfingerprint_bundle_statsget_jsfingerprint_hash_prevalenceget_jsfingerprint_library_statsget_jsfingerprint_similarget_jsfingerprint_similarity_countsget_jsfingerprint_sourceget_latest_capabilitiesget_malware_by_scanget_malware_statsget_netlogget_ocr_by_scanget_ocr_statsget_open_graphget_pastejackingget_pcap_metadataget_platform_statsget_popular_technologiesget_rdapget_recent_scansget_recent_threatsget_recent_yara_threatsget_safe_browsingget_safe_browsing_statsget_scan_iocget_scan_progressget_scan_reportsget_scan_resultget_scan_summaryget_screenshot_statsget_technologies_by_scanget_technology_combinationsget_technology_statsget_tls_asn1get_tls_detailsget_top_tracking_keysget_yara_by_scanget_yara_matchesget_yara_statsrun_js_differential_analysissearch_ai_classificationsearch_ai_high_risksearch_ai_scam_typesearch_analyzer_high_risksearch_by_asnsearch_by_faviconsearch_by_fuzzy_hashsearch_by_ipsearch_by_jarmsearch_by_nameserversearch_by_registrarsearch_by_screenshot_hashsearch_cpesearch_favicon_mmh3search_js_fingerprint_by_bundlersearch_js_fingerprint_by_cdnsearch_js_fingerprint_by_fuzzy_hashsearch_js_fingerprint_by_librarysearch_js_fingerprint_by_library_versionsearch_js_fingerprint_by_md5search_js_fingerprint_by_normalized_hashsearch_js_fingerprint_by_serversearch_js_fingerprint_by_sha1search_js_fingerprint_by_sha256search_js_fingerprint_obfuscatedsearch_js_fingerprint_patternssearch_js_malware_familiessearch_js_obfuscationsearch_js_runtime_by_composite_hashsearch_js_runtime_by_signaturesearch_js_runtime_similarsearch_js_segments_by_hashsearch_js_segments_by_normalized_hashsearch_jsfingerprints_by_bundlersearch_jsfingerprints_by_fuzzy_hashsearch_jsfingerprints_by_librarysearch_jsfingerprints_by_library_versionsearch_jsfingerprints_by_md5search_jsfingerprints_by_normalized_hashsearch_jsfingerprints_by_sha1search_jsfingerprints_by_sha256search_ocrsearch_ocr_patternsearch_scanssearch_semanticsearch_similar_scanssearch_similar_screenshotssearch_suspicious_clipboardsearch_technologiessearch_tracking_keysubmit_scansubmit_scan_reportwait_for_scan

Contract history

8 Oct 2026v0.1.69 breaking7 compatible115 cosmeticinstructions rewritten

Breaking: get_js_fingerprinter2, get_js_fingerprinter2_coverage, get_js_fingerprinter2_health, get_js_fingerprinter2_stats, search_js_fingerprint_patterns, search_js_fingerprinter2_composite_hash, search_js_fingerprinter2_signature, search_js_fingerprinter2_similar

Instructions rewritten: find_js_fingerprint_similar_by_hash, get_ai_analysis, get_analyzer_results, get_analyzer_stats, get_api_root, get_bot_protection, get_capabilities_by_date, get_clipboard_events, get_clipboard_stats, get_cpe_by_scan, get_cpe_stats, get_ct_certificates, get_ct_dns_records, get_ct_domains_by_ip, get_ct_similar_domains, get_ct_timeline, get_domain_history, get_domain_scans, get_domain_stats, get_favicon_stats, get_health, get_ids_alerts, get_ip_stats, get_jarm_signatures, get_jarm_stats, get_js_fingerprints, get_js_library_inventory, get_js_segments_by_scan, get_js_segments_suspicious, get_js_segments_unknown, get_jsfingerprint, get_jsfingerprint_bundle_stats, get_jsfingerprint_hash_prevalence, get_jsfingerprint_library_stats, get_jsfingerprint_similar, get_jsfingerprint_similarity_counts, get_jsfingerprint_source, get_latest_capabilities, get_malware_by_scan, get_malware_stats, get_netlog, get_ocr_by_scan, get_ocr_stats, get_open_graph, get_pastejacking, get_pcap_metadata, get_platform_stats, get_popular_technologies, get_rdap, get_recent_scans, get_recent_threats, get_recent_yara_threats, get_safe_browsing, get_safe_browsing_stats, get_scan_ioc, get_scan_progress, get_scan_reports, get_scan_result, get_scan_summary, get_screenshot_stats, get_technologies_by_scan, get_technology_combinations, get_technology_stats, get_tls_asn1, get_tls_details, get_top_tracking_keys, get_yara_by_scan, get_yara_matches, get_yara_stats, run_js_differential_analysis, search_ai_classification, search_ai_high_risk, search_ai_scam_type, search_analyzer_high_risk, search_by_asn, search_by_fuzzy_hash, search_by_ip, search_by_jarm, search_by_nameserver, search_by_registrar, search_by_screenshot_hash, search_cpe, search_favicon_mmh3, search_js_fingerprint_by_bundler, search_js_fingerprint_by_cdn, search_js_fingerprint_by_fuzzy_hash, search_js_fingerprint_by_library, search_js_fingerprint_by_library_version, search_js_fingerprint_by_md5, search_js_fingerprint_by_normalized_hash, search_js_fingerprint_by_server, search_js_fingerprint_by_sha1, search_js_fingerprint_by_sha256, search_js_fingerprint_obfuscated, search_js_fingerprint_patterns, search_js_malware_families, search_js_obfuscation, search_js_segments_by_hash, search_js_segments_by_normalized_hash, search_jsfingerprints_by_bundler, search_jsfingerprints_by_fuzzy_hash, search_jsfingerprints_by_library, search_jsfingerprints_by_library_version, search_jsfingerprints_by_md5, search_jsfingerprints_by_normalized_hash, search_jsfingerprints_by_sha1, search_jsfingerprints_by_sha256, search_ocr_pattern, search_scans, search_semantic, search_similar_scans, search_similar_screenshots, search_suspicious_clipboard, search_technologies, search_tracking_key, wait_for_scan. The description an agent follows changed; the callable contract may not have.

8 Oct 2026v1.30.02 breaking6 cosmeticinstructions rewritten

Breaking: submit_scan, submit_scan_report

Instructions rewritten: get_favicon, get_jsfingerprint_similarity_counts, search_by_favicon, search_js_fingerprint_by_library, search_js_fingerprinter2_signature, search_ocr, submit_scan, submit_scan_report. The description an agent follows changed; the callable contract may not have.

2 Oct 2026v1.30.01 breaking6 cosmeticinstructions rewritten

Breaking: submit_scan

Instructions rewritten: get_favicon_stats, search_js_fingerprint_by_library, search_js_fingerprint_patterns, search_js_malware_families, search_js_obfuscation, search_ocr, submit_scan. The description an agent follows changed; the callable contract may not have.

10 Sep 2026v1.25.05 breaking2 cosmeticinstructions rewritten

Breaking: search_ai_classification, search_by_favicon, search_by_fuzzy_hash, search_by_screenshot_hash, search_tracking_key

Instructions rewritten: get_favicon, get_netlog. The description an agent follows changed; the callable contract may not have.

24 Aug 2026v1.25.0first recorded contract

Watch this server

Save its public contract as a baseline and manage breaking-change email alerts.

Set up a watch

Own this server?

Sign in to claim this listing by proving control of its host.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for ScanMalware.com URL Scanner
[![MCP status](https://mcpi.app/servers/scanmalware-com-url-scanner/badge.svg)](https://mcpi.app/servers/scanmalware-com-url-scanner)