Scans Python and JavaScript/TypeScript code for 45+ vulnerability patterns through an MCP tool with optional Solana payments.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ we're steadily working through the catalog.
๐ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Scanpay.
The scanpay MCP server gives AI agents a code-scanning tool for Python, JavaScript, TypeScript, and TSX source. Its analysis is rule-based and deterministic: identical input produces the same result, and the scanner does not execute submitted code or use AI inference. Findings identify matched rules, severity, messages, and source lines, along with a count by severity.
The scanner covers more than 45 vulnerability patterns. Examples include Python eval() and exec() usage, shell-enabled subprocess calls, unsafe deserialization with pickle.loads(), os.system(), SQL injection patterns, path traversal, and hardcoded credentials. JavaScript and TypeScript checks include eval(), innerHTML, document.write(), new Function(), SQL injection patterns, and prototype pollution.
The MCP process is started with npx and configured with a SCANPAY_URL value that identifies the ScanPay HTTP API. An agent calls scan_code, and the MCP server forwards the source and language to the API's scan endpoint. The response contains a status, findings, and a summary with total, critical, high, medium, and low counts.
When the API requires payment, the request follows an x402 v2 flow on Solana. The API first returns HTTP 402 with payment information. A client pays 0.0007 SOL to the configured merchant wallet, then retries with an X-PAYMENT header containing proof of payment. The API verifies the payment before returning scan results.
Run the MCP process with the package command shown below:
The repository also documents self-hosting the API with Python: install the requirements, run python main.py, and use the resulting local address as the MCP endpoint. API configuration includes payment mode, merchant wallet, price in lamports, Solana RPC URL, and listening port. The documented default price is 700,000 lamports, equivalent to 0.0007 SOL.
scan_code to inspect source before an agent runs or uses it.scan_code as the MCP tool.The MCP server is a client of the ScanPay API; it does not itself establish that the API is available or free to use. Paid deployments require Solana payment handling, and the documented live flow uses mainnet pricing of 0.0007 SOL per scan. Self-hosted configurations can disable payment according to the API configuration.
Results are limited to the scanner's implemented rules and supported languages. Static analysis can report matched patterns, but the README does not claim complete vulnerability coverage. The scanner does not execute code, and its output should therefore be treated as a security-check result rather than proof that code is safe.
The repository lists MIT licensing. The live API addresses in the README are public deployment URLs and may differ between examples, so configure SCANPAY_URL explicitly instead of assuming one endpoint.
No reviews yet โ be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/scanpay)<a href="https://allmcps.com/mcp/scanpay"><img src="https://allmcps.com/api/badge/scanpay?style=directory" alt="Scanpay on AllMCPs" /></a>