Code security scanner for AI agents. 45+ vulnerability patterns, AST analysis, Solana micropayments.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Pay 0.0007 SOL (~$0.10) per scan. No account. No API key.
npx scanpay-mcp-servernpx scanpay-cli scan --language python --file ./code.py
Deterministic AST-based security scanning for Python and JavaScript/TypeScript. No code execution. No AI inference. Just fast, reliable vulnerability detection. Pay per scan with Solana micropayments β $0.10/scan.
ScanPay analyzes source code for security vulnerabilities using deterministic AST parsing. No AI, no code execution β just fast, reliable pattern matching that catches 45+ vulnerability classes before code runs.
Built for AI agents that generate code: scan before execution, block dangerous patterns, log audit trails.
ast module) and JS/TS (tree-sitter)ScanPay is deployed and running:
https://theoretical-config-hobby-kruger.trycloudflare.comhttps://theoretical-config-hobby-kruger.trycloudflare.com/api/v1/productsJDKXvegmW5j4sAJPB6YCA9ffJbN422WLMmCWCcpy1vm4Returns 402 Payment Required with Solana payment details. Send payment and retry with X-PAYMENT header to get the scan result.
402 Payment RequiredX-PAYMENT header containing payment proofMerchant wallet: JDKXvegmW5j4sAJPB6YCA9ffJbN422WLMmCWCcpy1vm4
ScanPay includes an MCP server for AI agents to scan code before execution:
Agents call scan_code to check code for vulnerabilities before running it.
Network: Solana mainnet (mainnet coming soon)
| Env Var | Default | Description |
|---|---|---|
SCANPAY_PAYMENT_MODE | disabled | disabled, mainnet, or mainnet |
SCANPAY_MERCHANT_WALLET | β | Solana wallet address |
SCANPAY_PRICE_LAMPORTS | 700000 | Price in lamports (0.0007 SOL) |
SCANPAY_RPC_URL | https://api.devnet.solana.com | Solana RPC endpoint |
SCANPAY_PORT | 8484 | Server port |
eval() / exec() β code injectionsubprocess with shell=True β command injectionpickle.loads() β deserialization attacksos.system() β command injection../)eval() β code injectioninnerHTML β XSSdocument.write() β XSSnew Function() β code injectionGET /api/v1/healthReturns service status and configuration.
GET /api/v1/productsReturns available scan products and pricing.
POST /api/v1/scanScans source code for vulnerabilities. Requires payment in mainnet/mainnet mode.
Request:
Response (200):
MIT
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/scanpay)<a href="https://allmcps.com/mcp/scanpay"><img src="https://allmcps.com/api/badge/scanpay?style=directory" alt="Scanpay on AllMCPs" /></a>