Security Snapshot

Created By
LeanOfficeTechnologies2 months ago
An MCP server that gives Claude and other AI agents the ability to audit any public URL's HTTP security headers. What it checks: - HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy - HTTPS enforcement and redirect chain depth - Presence of security.txt, robots.txt, sitemap.xml Payment model: - 0.05 USDC per scan, paid automatically on Base via the x402 protocol - No API key, no account, no subscription required - The agent's wallet pays directly — fully autonomous Tools provided: - scan_security_headers(url): Live scan (costs 0.05 USDC) - demo_security_snapshot(): Free pre-baked example
Overview

What is Security Snapshot?

An MCP server that gives Claude and other AI agents the ability to audit any public URL's HTTP security headers — with automatic payment via the x402 protocol.

What it checks

  • HSTS — HTTP Strict Transport Security
  • CSP — Content Security Policy
  • X-Frame-Options — Clickjacking protection
  • X-Content-Type-Options — MIME sniffing protection
  • Referrer-Policy — Referrer information control
  • Permissions-Policy — Browser feature access control
  • HTTPS enforcement and redirect chain depth
  • Presence of security.txt, robots.txt, sitemap.xml

Payment model

  • 0.05 USDC per scan, paid automatically on Base via the x402 protocol
  • No API key, no account, no subscription required
  • The agent's wallet pays directly — fully autonomous

Tools provided

ToolDescriptionCost
scan_security_headers(url)Live scan of any public URL0.05 USDC
demo_security_snapshot()Free pre-baked example responseFree

Claude Desktop setup

{
  "mcpServers": {
    "security-snapshot": {
      "command": "npx",
      "args": ["-y", "mcp-server-security-snapshot"],
      "env": {
        "WALLET_PRIVATE_KEY": "0x...",
        "NETWORK": "base"
      }
    }
  }
}

Server Config

{
  "mcpServers": {
    "security-snapshot": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-server-security-snapshot"
      ],
      "env": {
        "WALLET_PRIVATE_KEY": "0x...",
        "NETWORK": "base"
      }
    }
  }
}
Project Info
Created At
2 months ago
Updated At
2 months ago
Author Name
LeanOfficeTechnologies
Star
-
Language
-
License
-
Category

Recommend Servers

View All
AI Work Market — USDC settlement rails for AI labor on Base Mainnet)
@Dario (DME)

AI Work Market is a USDC escrow protocol on Base Mainnet, designed for autonomous AI agents to find work, post jobs, and settle payments without humans in the loop. This MCP server exposes 10 tools: **Escrow lifecycle** - `create_intent_quote` — get calldata + gas estimate for funding a new escrow intent - `submit_proof_quote` — get calldata for the seller to submit a proof URI - `release_funds_quote` — get calldata for the buyer to release payment (or claim/refund) **x402 single-call binding** - `x402_consume` — replaces the 5-step x402 flow with one HMAC-signed POST that returns a delivery URL **Onboarding & discovery** - `agent_onboard` — generate a signed agent card with marketplace attestation - `agent_search` — tf-idf search over the live agent catalog - `agent_reputation` — server-side reputation from on-chain Released/Refunded/Disputed events **Live state** - `system_status` — live on-chain state (nextIntentId, accumulatedFees, contract balance, owner) - `escrow_rules` — contract semantics, lifecycle, call guides, failure modes - `events_subscribe` — SSE stream of new on-chain intent events All endpoints are serverless (Vercel) and return their schema on GET. No browser, no wallet UI required for an agent to integrate. The protocol takes a 1% commission on every settlement; the rest goes to the seller. The full AgentCard is at `/.well-known/agent-card.json` (A2A-compatible). The OpenAPI 3.0.3 spec is at `/.well-known/openapi.json` with `components.securitySchemes` (none, hmacX402). `robots.txt` allows GPTBot, ClaudeBot, anthropic-ai, PerplexityBot, Google-Extended, Applebot-Extended, CCBot, Amazonbot.

8 hours ago