Investigate URLs with urlscan.io tools for scans, indicators, screenshots, and results.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "urlscan-mcp" yet — see the docs or source repo.
Use urlscan-mcp to search for scans related to the domain example.com, then summarize matches, suspicious findings, and indicators worth pivoting on.
A summary of matching scans plus domains, IPs, or other indicators for further investigation.
Use urlscan-mcp to retrieve the scan results, screenshot, and DOM for this URL, then summarize the page characteristics in brief bullet points: https://example.com
A concise summary of the scan output and page artifacts to help assess content and risk.
Use urlscan-mcp to submit this URL for scanning, and once results are available, extract key findings and related indicators: https://example.com/login
The URL is submitted, followed by key findings and pivotable indicators from the scan results.
When a suspicious link appears, security researchers or developers can use it to search existing scans, retrieve screenshots and DOM data, and quickly decide whether deeper investigation is needed.
During a security investigation, users can pivot on known indicators to search and connect related scan results, expanding suspicious domains, IPs, or page clues.
If no existing result is available for a target URL, users can submit it for scanning and then inspect the output for an initial assessment.
It is an MCP server that exposes urlscan.io as tools for security investigations. It supports searching scans, pivoting on indicators, retrieving screenshots and DOM data, reading scan results, and submitting URLs.
Based on the description, it can return compact scan results and retrieve page screenshots, DOM data, and scan information. The results are optimized to fit LLM context windows.
The provided material does not include installation steps, runtime requirements, or key details. See the source repository for the exact setup.
Investigate threat indicators via urlscan and VirusTotal with compact structured results.
Run phishing triage, malware scans, and certificate threat analysis with natural language.
Analyze MCP tool security risks, detect malicious behavior, and provide risk scores.
Intelligently crawl and explore websites, then return structured web analysis.
Scan MCP servers for runtime, static, config, dependency, and compliance risks.
Scan MCP tool descriptions for prompt injection and privilege escalation risks.