Scannd MCP server

Trigger security scans and read reports/vulnerabilities via the hosted Scannd API. Free: 2 scans/mo.

63/100?Number 156 of 895 in Security

verified publishersource repositoryupdated recentlyactive entry

How this score is calculated

Local VERIFIED Security

Details

Registry name
com.scannd/scannd
Publisher
scannd
Version
0.1.0
Distribution
Local. the server runs as a process on your own machine and talks to the client over stdio. You install the package first, and your data stays on your machine.
Transports
stdio
Source repository
zachforrest/webscannerio
First published
Registry updated
Credentials required
1 environment variable
Schema generation
2025-12-11

Packages

npm scannd-mcp

Version
0.1.0
Transport
stdio
Runtime
not specified
Environment variables
VariableRequiredSecretPurpose
SCANND_API_KEYYesYesScannd API key (starts with sk_). Sent to the hosted API as the X-API-Key header. Get one at https://scannd.com; the free tier includes 2 scans/month.

Install Scannd

Pick your client. The configuration below is generated from this server's published package and endpoint data.

Claude Code command line

Configuration file: .mcp.json or ~/.claude.json

Local package (npm)
claude mcp add scannd --env SCANND_API_KEY=<scannd_api_key> -- npx -y scannd-mcp

Replace each placeholder with your own value before saving.

Check it worked: Run claude mcp list and check the server reports connected.

Official Claude Code MCP documentation

Cursor IDE

Configuration file: .cursor/mcp.json or ~/.cursor/mcp.json

Local package (npm)
{
  "mcpServers": {
    "scannd": {
      "command": "npx",
      "args": ["-y", "scannd-mcp"],
      "env": {
        "SCANND_API_KEY": "<scannd_api_key>"
      }
    }
  }
}

Replace each placeholder with your own value before saving.

Check it worked: The server appears under Settings, then MCP with a green dot.

Official Cursor MCP documentation

Claude Desktop desktop app

Configuration file: ~/Library/Application Support/Claude/claude_desktop_config.json or %APPDATA%\Claude\claude_desktop_config.json

Local package (npm)
{
  "mcpServers": {
    "scannd": {
      "command": "npx",
      "args": ["-y", "scannd-mcp"],
      "env": {
        "SCANND_API_KEY": "<scannd_api_key>"
      }
    }
  }
}

Replace each placeholder with your own value before saving.

Quit the app completely and reopen it.

Check it worked: Look for the tools icon in the message composer.

Official Claude Desktop MCP documentation

Visual Studio Code IDE

Configuration file: .vscode/mcp.json or user settings.json under mcp

Local package (npm)
{
  "servers": {
    "scannd": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "scannd-mcp"],
      "env": {
        "SCANND_API_KEY": "<scannd_api_key>"
      }
    }
  }
}

Replace each placeholder with your own value before saving.

Check it worked: Open the Copilot chat tools picker and confirm the server is listed.

Official Visual Studio Code MCP documentation

Codex CLI command line

Configuration file: ~/.codex/config.toml

Local package (npm)
codex mcp add scannd -- npx -y scannd-mcp

Replace each placeholder with your own value before saving.

Check it worked: Run codex mcp list and check the server is present.

Official Codex CLI MCP documentation

More clients (9), including automation platforms

Tools

The publisher has not disclosed a tool manifest. The tool list can only be seen by connecting to the server, which this catalogue does not do on the publisher's behalf.

Command line alternative

None found. The published package declares no executable and no matching Homebrew formula exists, so the MCP server appears to be the only route. This is a negative result from automated checks, not a statement from the publisher.

Repository signals

The repository the publisher listed no longer resolves. It may have been renamed, made private or deleted.

Security, privacy and enterprise use

Read from the publisher's own website on 2026-08-13. Links only: nothing here is independently verified.

Policies

Certifications the publisher names

No certification is named on the pages that were read.

Enterprise use

The publisher does not link an enterprise or business page, so enterprise terms could not be determined. Contact them directly.

Publisher

Website
scannd.com
Profiles
none listed on the publisher's site
Community
no subreddit linked from the publisher's site

Review platforms

CAPTERRA G2 OMR TRUSTPILOT

Ratings are not shown. G2, Trustpilot and Capterra all prohibit republishing their scores without a licence, and marking up a borrowed rating as our own would breach search engine policy. These are profile links only, and a profile may not exist for every publisher.

Frequently asked questions

What does the Scannd MCP server do?
Trigger security scans and read reports/vulnerabilities via the hosted Scannd API. Free: 2 scans/mo.
Do I need to install anything to use Scannd?
Yes. Scannd runs as a local process, so the package has to be installed on the machine where the client runs.
How do I install Scannd?
Install the npm package scannd-mcp and run it with npx -y scannd-mcp.
Does Scannd need an API key?
Yes. It reads 1 environment variable from the environment, so you need to supply SCANND_API_KEY before the server will start.
What is SCANND_API_KEY used for in Scannd?
Scannd API key (starts with sk_). Sent to the hosted API as the X-API-Key header. Get one at https://scannd.com; the free tier includes 2 scans/month.
Which transport does Scannd use?
Stdio. Your client has to support that transport to connect.
Where is the source code for Scannd?
The publisher lists https://github.com/zachforrest/webscannerio as the source repository.
Is Scannd an official server?
It is published under the namespace com.scannd, which means the publisher proved control of that domain when registering. That confirms who published it, not that it has been reviewed for quality or security.
Which version of Scannd is listed here?
Version 0.1.0, taken from the latest registry entry.