{"uid":"cap_GmeeeM_Txi9a74dA3-P4R","slug":"synthora-mcp-server-security-scanner-843dca02","name":"SYNTHORA MCP Server Security Scanner","description":"MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — returning a security_score + findings[]. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. 0.05 USDC via x402 on Base. SYNTHORA.","url":"https://api.hergertsynthora.com/v1/mcpscan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","description":"MCP server URL (Streamable-HTTP endpoint)"},"manifest":{"type":"object","description":"Or paste the MCP manifest (serverInfo + tools) directly"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_NmIPaDMfdCb7DBhqWai1x","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Probes an MCP server via JSON-RPC and runs a deterministic rule engine to detect security vulnerabilities, returning a security score and findings list","exampleAgentPrompt":"Can you security-scan the MCP server at https://mcp.example.com/rpc and tell me its security score and any dangerous capabilities or embedded secrets it found?","exampleUseCases":[{"title":"Vet a third-party MCP server before use","prompt":"Before I connect my agent to that new MCP server at https://tools.vendorapp.com/mcp, can you scan it for security issues — I want to know if it has any dangerous exec or shell tools, embedded secrets, or prompt injection risks?"},{"title":"Audit a self-hosted MCP manifest","prompt":"I have my MCP server manifest here — can you run a security audit on it and give me a score plus a list of any vulnerabilities like permissive input schemas or missing auth headers?"},{"title":"Continuous trust check before agent deployment","prompt":"We're about to deploy an agent fleet that connects to https://internal.corp/mcp — can you do a security scan on that MCP endpoint and flag anything that could be a risk before we go live?"}],"resultDescription":"Returns a security_score (numeric trust rating) and a findings[] array detailing specific vulnerabilities detected — including embedded secrets, dangerous shell/exec/filesystem tool capabilities, prompt-injection surface areas, hidden unicode characters, overly permissive input schemas, and missing auth/TLS/CORS headers. Response is Ed25519-signed for verifiability.","failureModes":["MCP server URL is unreachable or returns non-JSON-RPC response","Manifest provided is malformed or missing required serverInfo/tools fields","Target server does not respond to JSON-RPC initialize or tools/list calls","Payment of 0.05 USDC via x402 on Base not fulfilled — request rejected","Server timeout if target MCP endpoint is slow to respond"],"whenToPreferThis":"Choose this endpoint when you need a zero-LLM, deterministic, cryptographically signed security assessment of an MCP server before connecting an AI agent to it. Prefer it over manual review when you need a consistent, rule-based security score rather than an LLM opinion, and when you need tamper-evident Ed25519-signed results for audit trails.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:02:28.187Z","isFirstParty":false}