{"uid":"cap_YdeJ5v_lQOuZ4FUxd0xBX","slug":"saylor-innovations-watchdog-mcp-server-security-scan-cf56283e","name":"Saylor Innovations Watchdog — MCP Server Security Scan","description":"MCP Server Security Scan (tool poisoning, prompt injection, risky capabilities) — Security","url":"https://saylorinnovations.com/api/mcp-scan?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","POST","PUT","PATCH","DELETE","HEAD"],"type":"string"},"queryParams":{"type":"object","properties":{"url":{"type":"string","description":"MCP server endpoint URL, e.g. https://example.com/mcp (query)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string","const":"json"},"example":{"type":"object","required":["url","verdict"],"properties":{"url":{"type":"string"},"score":{"type":["number","null"]},"tools":{"type":"array","items":{"type":"object"}},"counts":{"type":"object"},"server":{"type":"object"},"reasons":{"type":"array","items":{"type":"string"}},"verdict":{"enum":["no-issues-found","caution","high-risk","do-not-connect","auth-required","unreachable","not-mcp","not-scanned"],"type":"string"},"findings":{"type":"array","items":{"type":"object"}}}}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_uqxMqLLfLHbG4ibwspdbd","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans an MCP server endpoint for security vulnerabilities including tool poisoning, prompt injection, and risky capabilities, returning a verdict and detailed findings","exampleAgentPrompt":"Can you run a security scan on the MCP server at https://example.com/mcp and tell me if it's safe to connect to — specifically check for tool poisoning or prompt injection risks?","exampleUseCases":[{"title":"Vetting a third-party MCP server before use","prompt":"Before I connect my agent to that new MCP server at https://partner-tools.com/mcp, can you scan it for security issues like tool poisoning or prompt injection and give me a verdict?"},{"title":"Automated safety check in an agent onboarding flow","prompt":"I'm adding https://community-mcp.io/mcp to my workflow — run a security scan on it and let me know the risk score and any specific findings I should be worried about."},{"title":"Red-teaming a self-hosted MCP server","prompt":"Can you audit my own MCP server at https://internal.mycompany.com/mcp for risky capabilities or prompt injection vulnerabilities before I let external agents connect to it?"}],"resultDescription":"Returns a JSON object containing: the scanned URL, a verdict enum (no-issues-found, caution, high-risk, do-not-connect, auth-required, unreachable, not-mcp, not-scanned), a numeric risk score (or null), an array of tools exposed by the server, categorized finding counts, detailed findings with descriptions, human-readable reasons for the verdict, and server metadata.","failureModes":["unreachable verdict if the MCP server URL is offline or network-blocked","not-mcp verdict if the URL does not serve a valid MCP protocol","auth-required verdict if the server requires authentication before scanning","not-scanned if the server could not be evaluated for any reason","malformed URL input causing request failure","rate-limit or payment failure at $0.01 per call"],"whenToPreferThis":"Use this endpoint when you need to evaluate the trustworthiness and safety of any MCP server before connecting an AI agent to it, particularly when assessing untrusted, community-contributed, or third-party MCP servers for tool poisoning, prompt injection, or dangerous capability exposure. Prefer this over generic HTTP probing or manual inspection when you need a structured security verdict with categorized findings.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:39:55.112Z","isFirstParty":false,"canonicalSlug":"saylor-innovations-watchdog-mcp-server-security-scan-cf56283e"}