MCP server scan
Is an MCP server live, and do its tool descriptions hide prompt injection?
POST/api/hub/v1/mcp/scan
urlstringRequired · URL · max 2,000 charsbearerstringOptional · max 4,000 chars — Optional bearer token for a server that requires auth. Used for this call only and never stored.
Example request
curl -X POST https://businessmcp.com/api/hub/v1/mcp/scan \
-H "Authorization: Bearer $BUSINESSMCP_API_KEY" \
-H "Content-Type: application/json" \
-d '{"url":"https://mcp.example.com/mcp"}'MCP name mcp_server_scanFull reference and response