Scannd MCP server
Trigger security scans and read reports/vulnerabilities via the hosted Scannd API. Free: 2 scans/mo.
verified publishersource repositoryupdated recentlyactive entry
Local VERIFIED Security
Details
- Registry name
- com.scannd/scannd
- Publisher
- scannd
- Version
- 0.1.0
- Distribution
- Local. the server runs as a process on your own machine and talks to the client over stdio. You install the package first, and your data stays on your machine.
- Transports
- stdio
- Source repository
- zachforrest/webscannerio
- Website
- https://scannd.com
- First published
- Registry updated
- Credentials required
- 1 environment variable
- Schema generation
- 2025-12-11
Packages
npm scannd-mcp
- Version
- 0.1.0
- Transport
- stdio
- Runtime
- not specified
| Variable | Required | Secret | Purpose |
|---|---|---|---|
| SCANND_API_KEY | Yes | Yes | Scannd API key (starts with sk_). Sent to the hosted API as the X-API-Key header. Get one at https://scannd.com; the free tier includes 2 scans/month. |
Install Scannd
Pick your client. The configuration below is generated from this server's published package and endpoint data.
Claude Code command line
Configuration file: .mcp.json or ~/.claude.json
claude mcp add scannd --env SCANND_API_KEY=<scannd_api_key> -- npx -y scannd-mcpReplace each placeholder with your own value before saving.
Check it worked: Run claude mcp list and check the server reports connected.
Cursor IDE
Configuration file: .cursor/mcp.json or ~/.cursor/mcp.json
{
"mcpServers": {
"scannd": {
"command": "npx",
"args": ["-y", "scannd-mcp"],
"env": {
"SCANND_API_KEY": "<scannd_api_key>"
}
}
}
}Replace each placeholder with your own value before saving.
Check it worked: The server appears under Settings, then MCP with a green dot.
Claude Desktop desktop app
Configuration file: ~/Library/Application Support/Claude/claude_desktop_config.json or %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"scannd": {
"command": "npx",
"args": ["-y", "scannd-mcp"],
"env": {
"SCANND_API_KEY": "<scannd_api_key>"
}
}
}
}Replace each placeholder with your own value before saving.
Quit the app completely and reopen it.
Check it worked: Look for the tools icon in the message composer.
Visual Studio Code IDE
Configuration file: .vscode/mcp.json or user settings.json under mcp
{
"servers": {
"scannd": {
"type": "stdio",
"command": "npx",
"args": ["-y", "scannd-mcp"],
"env": {
"SCANND_API_KEY": "<scannd_api_key>"
}
}
}
}Replace each placeholder with your own value before saving.
Check it worked: Open the Copilot chat tools picker and confirm the server is listed.
Codex CLI command line
Configuration file: ~/.codex/config.toml
codex mcp add scannd -- npx -y scannd-mcpReplace each placeholder with your own value before saving.
Check it worked: Run codex mcp list and check the server is present.
More clients (9), including automation platforms
ChatGPT web app
This client cannot start a local process, and this server publishes no hosted endpoint.
Cline IDE
Configuration file: cline_mcp_settings.json, reachable from the MCP Servers pane
{
"mcpServers": {
"scannd": {
"command": "npx",
"args": ["-y", "scannd-mcp"],
"env": {
"SCANND_API_KEY": "<scannd_api_key>"
}
}
}
}Replace each placeholder with your own value before saving.
Check it worked: The server appears in the MCP Servers pane with its tool count.
Goose desktop app
Configuration file: ~/.config/goose/config.yaml
extensions:
scannd:
type: stdio
cmd: npx
args: ["-y", "scannd-mcp"]
enabled: trueReplace each placeholder with your own value before saving.
Check it worked: Run goose session and confirm the extension loads.
LangChain agent framework
Install the MCP adapter package and construct a client in code
client = MultiServerMCPClient({
"scannd": {
"command": "npx",
"args": ["-y", "scannd-mcp"],
"transport": "stdio",
}
})Replace each placeholder with your own value before saving.
Check it worked: Print the loaded tool list before running the agent.
Make automation platform
This client cannot start a local process, and this server publishes no hosted endpoint.
n8n automation platform
This client cannot start a local process, and this server publishes no hosted endpoint.
Windsurf IDE
Configuration file: ~/.codeium/windsurf/mcp_config.json
{
"mcpServers": {
"scannd": {
"command": "npx",
"args": ["-y", "scannd-mcp"],
"env": {
"SCANND_API_KEY": "<scannd_api_key>"
}
}
}
}Replace each placeholder with your own value before saving.
Check it worked: The server appears in the Cascade plugin list.
Zapier automation platform
This client cannot start a local process, and this server publishes no hosted endpoint.
Zed IDE
Configuration file: ~/.config/zed/settings.json
{
"context_servers": {
"scannd": {
"command": {
"path": "npx",
"args": ["-y", "scannd-mcp"]
}
}
}
}Replace each placeholder with your own value before saving.
Check it worked: The agent panel lists the server under context servers.
Tools
The publisher has not disclosed a tool manifest. The tool list can only be seen by connecting to the server, which this catalogue does not do on the publisher's behalf.
Command line alternative
None found. The published package declares no executable and no matching Homebrew formula exists, so the MCP server appears to be the only route. This is a negative result from automated checks, not a statement from the publisher.
Repository signals
The repository the publisher listed no longer resolves. It may have been renamed, made private or deleted.
Security, privacy and enterprise use
Read from the publisher's own website on 2026-08-13. Links only: nothing here is independently verified.
Policies
- Privacy policy
- Terms of service
- security.txt machine readable
Certifications the publisher names
No certification is named on the pages that were read.Enterprise use
The publisher does not link an enterprise or business page, so enterprise terms could not be determined. Contact them directly.Publisher
- Website
- scannd.com
- Profiles
- none listed on the publisher's site
- Community
- no subreddit linked from the publisher's site
Review platforms
Ratings are not shown. G2, Trustpilot and Capterra all prohibit republishing their scores without a licence, and marking up a borrowed rating as our own would breach search engine policy. These are profile links only, and a profile may not exist for every publisher.
Frequently asked questions
- What does the Scannd MCP server do?
- Trigger security scans and read reports/vulnerabilities via the hosted Scannd API. Free: 2 scans/mo.
- Do I need to install anything to use Scannd?
- Yes. Scannd runs as a local process, so the package has to be installed on the machine where the client runs.
- How do I install Scannd?
- Install the npm package scannd-mcp and run it with npx -y scannd-mcp.
- Does Scannd need an API key?
- Yes. It reads 1 environment variable from the environment, so you need to supply SCANND_API_KEY before the server will start.
- What is SCANND_API_KEY used for in Scannd?
- Scannd API key (starts with sk_). Sent to the hosted API as the X-API-Key header. Get one at https://scannd.com; the free tier includes 2 scans/month.
- Which transport does Scannd use?
- Stdio. Your client has to support that transport to connect.
- Where is the source code for Scannd?
- The publisher lists https://github.com/zachforrest/webscannerio as the source repository.
- Is Scannd an official server?
- It is published under the namespace com.scannd, which means the publisher proved control of that domain when registering. That confirms who published it, not that it has been reviewed for quality or security.
- Which version of Scannd is listed here?
- Version 0.1.0, taken from the latest registry entry.
Other servers in Security
HelpMyAgent
Pay-per-call data APIs for AI agents: business, compliance, procurement, VAT and IBAN via x402.BlackVeil DNS & Email Security Scanner
DNS and email security scanner with 79 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.Go Vulnerability Database Tracker, buy per-query in-session (govulnwatch)
Go vulnerability database: new GO-IDs, CVE aliases, amended advisories for Go deps.Delega
Delega MCP client. Public hosted access retired July 28, 2026; existing owner credentials only.Pretorin Compliance
Access Pretorin compliance systems, controls, evidence, and narratives from your AI tools.shyn
Local-first ambient memory for your Mac, pages, meetings, notes, encrypted on-device.ComplyEdge TrustLint, offline EU AI Act compliance checks
Offline TrustLint checks: EU AI Act Article 5, Article 50, GPAI, plus GDPR and HIPAA.Ofw
OurFamilyWizard co-parenting for Claude, messages, calendar, expenses, and journal.
