Skip to content
MCP ThesaurusMCP Thesaurus

Compuute MCP Security Scanner

CommunityIncomplete39/100Claim

streamable-httpMITupdated 13d ago

Scan-as-a-Service for MCP servers. HTTP + MCP wrapper around compuute-scan โ€” the MCP-specific static security scanner. Designed for agent-callable consumption.

SourceWebsite

What can you do with Compuute MCP Security Scanner?

compuute-scan-api

Scan-as-a-Service for MCP servers. HTTP + MCP wrapper around compuute-scan โ€” the MCP-specific static security scanner. Designed for agent-callable consumption.

POST a public GitHub repo URL โ†’ get a structured security report scored against 38 MCP-specific rules across 8 languages (TS/JS, Python, Go, Rust, C#, Java, Kotlin).

Honesty note (read first): compuute-scan is a pattern-breadth detector, not an exploitability oracle. Historic false-positive rate after manual validation is ~90% on raw output (verified against modelcontextprotocol/servers: 138 raw findings โ†’ 13 confirmed). Every response carries a _disclaimer field stating this explicitly. Use findings as a triage queue, not as a list of confirmed vulnerabilities. See docs/FP-RATES.md for per-rule transparency.

Live at https://scan.compuute.se. Service version reported by /v1/health.


Endpoints

Core scan

Method Path Purpose Auth
POST /v1/scan Scan a public GitHub MCP-server repo (free tier, rate-limited) none
POST /v1/scan/pay Same as above via x402 micropayment ($0.10 USDC on Base L2) X-Payment header

POST /v1/scan/pay with no body to read the payment requirements without paying โ€” the request body is optional precisely so discovery probes reach the 402 instead of body validation. Verify with the Coinbase Agentic Wallet CLI:

npx awal x402 details https://scan.compuute.se/v1/scan/pay

| GET | /v1/scan/info | Scanner version + limits + supported ecosystems | none | | GET | /v1/health | Liveness + scanner-binary availability | none |

Machine-readable contracts

Method Path Purpose
GET /openapi.json OpenAPI v3 spec with per-field descriptions
GET /docs Swagger UI for the OpenAPI spec

MCP server (live)

Endpoint Tool Transport
/mcp/ scan_mcp_server(github_url) Streamable HTTP

Install in Claude Code: claude mcp add compuute-scan --transport http --url https://scan.compuute.se/mcp/

Discovery (/.well-known/)

Path Format Consumer
/.well-known/agent-card.json A2A v1.0 Agent Card (canonical) A2A protocol clients
/.well-known/agent.json A2A Agent Card (alias) pre-1.0 A2A clients/crawlers
/.well-known/ai-plugin.json OpenAI plugin manifest ChatGPT / OpenAI tools
/.well-known/x402.json x402 payment manifest Coinbase Agent.market crawlers, x402 aggregators
/.well-known/x402 Alias of x402.json x402 probes without .json suffix
/llms.txt markdown summary LLM-driven agent-search crawlers (Exa, Perplexity-style) per llmstxt.org
/robots.txt crawler policy search engines
/sitemap.xml URL index search engines

Example

curl -X POST https://scan.compuute.se/v1/scan \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: 00000000-0000-0000-0000-000000000001' \
  -d '{"repo_url": "https://github.com/modelcontextprotocol/servers"}'

Response (truncated):

{
  "repo_url": "https://github.com/modelcontextprotocol/servers",
  "scanner": {"name": "compuute-scan", "version": "0.6.2", "layers_covered": ["L0", "L1"]},
  "summary": {"critical": 1, "high": 94, "medium": 22, "low": 0, "files_scanned": 77},
  "score": 0,
  "recommendation": "AVOID โ€” 1 critical and 94 high finding(s)...",
  "top_findings": [...],
  "performance": {"clone_seconds": 1.2, "scan_seconds": 0.5, "repo_size_bytes": 41234},
  "_disclaimer": "PATTERN MATCH โ€” compuute-scan is a static analyzer..."
}

Agent-shaped API features

Feature How
Idempotent retries (24h cache) Idempotency-Key header
HTTP cache ETag + Cache-Control: public, max-age=1800
Conditional GET If-None-Match โ†’ 304 Not Modified
Rate-limit headers X-RateLimit-Limit/Remaining/Reset
Strict input validation Pydantic extra="forbid", GitHub-HTTPS-only
OWASP security headers HSTS / X-Frame-Options / X-Content-Type-Options / CSP / Referrer-Policy / Permissions-Policy
OpenAPI for discovery GET /openapi.json with descriptions on every field
MCP for agent discovery /mcp/ exposes scan_mcp_server tool
x402 for autonomous purchase /v1/scan/pay returns 402 with USDC/Base payment requirements
Honest framing Every response carries _disclaimer โ€” pattern match, not exploitability claim

Pricing

Tier Audience Price
Open Source CLI Indie devs, agent builders $0 โ€” npx compuute-scan ./repo
Hosted API (free) Agent operators evaluating MCP servers $0 โ€” POST /v1/scan, rate-limited
Hosted API (x402) Autonomous agents in Agent.market ecosystem $0.10 USDC/scan โ€” POST /v1/scan/pay
MCP Security Audit Enterprises shipping MCP to production $5Kโ€“$30K SoW
AI Procurement Risk Audit CFO/CTO/CISO buying enterprise AI capacity $5Kโ€“$15K SoW

Full breakdown with JSON-LD: https://compuute.se/pricing.

Local development

python3 -m venv venv && source venv/bin/activate
pip install -r requirements.txt
export COMPUUTE_SCAN_PATH=$HOME/compuute-scan/compuute-scan.js
uvicorn main:app --reload

x402 payment env vars (all optional locally; /v1/scan/pay returns 503 until the wallet is set):

Var Purpose Default
X402_WALLET_ADDRESS Base L2 address receiving USDC unset (x402 disabled)
X402_NETWORK CAIP-2 network id โ€” eip155:8453 (Base mainnet) or eip155:84532 (Base Sepolia) eip155:8453
X402_PRICE_USD Price per scan 0.10
X402_FACILITATOR_URL Facilitator base URL CDP facilitator (serves both networks)
CDP_API_KEY_ID / CDP_API_KEY_SECRET CDP API key for facilitator verify/settle auth unset (verify will be rejected)

Rehearsing payments on testnet

Set X402_NETWORK=eip155:84532 to quote prices in Base Sepolia USDC, which is free from a faucet. The CDP facilitator serves Sepolia too, so a testnet payment exercises the real verify/settle path and your real CDP API keys โ€” without moving real money.

Asset address and EIP-712 domain are selected together per network: Base mainnet USDC signs as "USD Coin", Base Sepolia as "USDC". Mixing them fails every signature with an error that looks like a bad API key, which is why they live in one NETWORKS table rather than separate env vars.

Mainnet is the default and an unknown value falls back to it, so a typo can never silently ask real agents to pay in worthless testnet USDC. Check which mode is live with curl -s https://scan.compuute.se/v1/health โ€” the x402 block reports network and testnet.

Tests

pytest tests/ -v
# 34 tests covering scan, x402, MCP, discovery, OpenAPI

Scripts

Script What it does
scripts/precheck.sh Start-of-session check: branch, working tree, tests, live state, next backlog item
scripts/postcheck.sh End-of-session check: committer hygiene, tests, append to docs/PROGRESS.md
scripts/status.sh 30-second live-state check against scan.compuute.se (4 probes)
scripts/sbom.sh Generate CycloneDX SBOM, optionally upload to a GitHub Release
scripts/prospect-research.sh Pull qualified prospects from GitHub + Anthropic Registry, draft DM angles
scripts/measure-tiers.sh T0/T1/T2 distribution snapshot per docs/agent-economy-strategy.md ยง5 โ€” reach, engagement, conversion measured against Railway logs + Base RPC + GitHub stars

Architecture

  • api/services/scan.py โ€” clone + sandbox + scan + parse. Pure functions.
  • api/services/x402_service.py โ€” x402 v2 verify / settle on the official x402 SDK; CDP facilitator (Base mainnet) by default; Bazaar discovery extension in 402 bodies.
  • api/services/cdp_auth.py โ€” minimal CDP API-key JWT auth for the facilitator (PyJWT + cryptography; avoids the full cdp-sdk).
  • api/serializers/scan_serializer.py โ€” Pydantic models, strict validation.
  • api/routes/scan.py โ€” HTTP layer for /v1/scan: idempotency, cache, ETag.
  • api/routes/scan_x402.py โ€” HTTP layer for /v1/scan/pay.
  • api/routes/discovery.py โ€” /.well-known/*, /robots.txt, /sitemap.xml.
  • api/mcp_server.py โ€” FastMCP server exposing scan_mcp_server.
  • main.py โ€” FastAPI wiring + middleware (security headers, CORS).

Bundled compuute-scan version is pinned in the Dockerfile (ARG COMPUUTE_SCAN_REF=v0.6.2).

Documentation

Doc For
docs/agent-economy-strategy.md The strategic doc โ€” a16z-verified data, the 11-signal buyer-agent model, two-track strategy, 30-day pivot trigger. Read first if you're trying to understand the company.
docs/STRATEGY.md Position, pricing tiers, roadmap, decision log
docs/ARCHITECTURE.md Component diagram, request flow, threat model, deployment topology
docs/DEVELOPMENT.md Local setup, layout, code style, common pitfalls โ€” onboard a new dev in 30 min
docs/MONITORING.md Endpoints to watch, automated checks, runbook for failures
docs/FP-RATES.md Per-rule false-positive transparency
docs/scan-self-triage.md What this scanner reports when run against its own code
docs/whitepaper/ MCP Security Methodology v1.0 (Markdown + PDF)
docs/case-studies/ Three anonymized engagement reports from the May 2026 batch
docs/advisories/ Public advisories under the COMPUUTE-YYYY-NNN numbering
docs/security/ Self-pentest reports (90-day cadence)
docs/audits/ The AI Procurement Risk Audit checklist (lead magnet)
docs/compliance/ SOC 2 Type I readiness statement, TSC control mapping
docs/submissions/ LangChain + CrewAI tool wrappers ready for PR/marketplace
skills/compuute-scan/ Claude Skill package (SKILL.md + scan.sh) โ€” submitted to anthropics/skills#1346
CODE_OF_CONDUCT.md Contributor Covenant 2.1
docs/launches/ Show HN draft + posting checklist
docs/setup/ Status page (BetterStack) + analytics (PostHog) setup guides
docs/agentic-market-submission.md Three paths to Coinbase Agent.market listing
BACKLOG.md GitHub Issues + Project board roadmap
IDEAS.md Composted product hypotheses with gating rules
CONTRIBUTING.md How to contribute
SECURITY.md Vulnerability disclosure policy (90-day window)

Security

Found a vulnerability? See SECURITY.md โ€” email security@compuute.se. We follow a 90-day coordinated disclosure window.

License

MIT (matches compuute-scan).

Author

Compuute AB โ€” daniel@compuute.se