S

SYNTHORA · Mcpscan

by SYNTHORA

POSTBase

$0.05

per call · USD Coin on Base

MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — returning a security_score + findings[]. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. 0.05 USDC via x402 on Base. SYNTHORA.

Endpoint

POST https://api.hergertsynthora.com/v1/mcpscan

1

Calls / 30d

1

Unique payers / 30d

Aug 12

Last called

exact

Payment scheme

Call this service

TypeScript · @x402/fetch
import { wrapFetchWithPayment } from "@x402/fetch";
import { privateKeyToAccount } from "viem/accounts";

const account = privateKeyToAccount(process.env.PRIVATE_KEY);
const fetchWithPay = wrapFetchWithPayment(fetch, account);

const res = await fetchWithPay("https://api.hergertsynthora.com/v1/mcpscan", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "manifest": {
      "name": "demo-mcp",
      "tools": [
        {
          "description": "web search",
          "name": "search"
        },
        {
          "description": "http fetch",
          "name": "fetch"
        }
      ],
      "version": "1.0.0"
    }
  }),
});
const data = await res.json();
cURL
curl -X POST \
  "https://api.hergertsynthora.com/v1/mcpscan" \
  -H "Content-Type: application/json" \
  -d '{"manifest":{"name":"demo-mcp","tools":[{"description":"web search","name":"search"},{"description":"http fetch","name":"fetch"}],"version":"1.0.0"}}' \
  -H "X-PAYMENT: <signed x402 payment>"

Example response

{
  "niche": "mcp_scan",
  "ok": true,
  "result": {
    "counts": {
      "critical": 1,
      "high": 2,
      "low": 0,
      "medium": 2
    },
    "findings": [
      {
        "detail": "openai_key embedded in tool",
        "id": "MCP-S01",
        "rule": "secret_in_manifest",
        "severity": "critical",
        "tool": "read_file"
      }
    ],
    "security_score": 14,
    "signed": "ed25519",
    "target": "https://mcp.example.dev/mcp",
    "tools_scanned": 2,
    "verdict": "critico"
  }
}

Payment details

Pay to0x10800a5a5b9d72251566ec651e862a8b4b427de0
AssetUSD Coin · 0x833589fcd6edb6e08f4c7c32d4f71b54bda02913
NetworksBase
Schemesexact

Is this your API?

Pin it to the top of AI & Inference and the homepage with a featured placement.

Get featured →

More from SYNTHORA & similar services