Check a live app you own for public databases, leaked keys and exposed files.
Malinois is a remote MCP server published at malinois.app. It has been probed 6 times since 9/12/2026. It answered in 6 of them (100.0%), a near-uninterrupted record. Median response time is 967 ms, a delay an agent will notice. It offers a narrow, focused set of 2 tools. On the protocol side it speaks the 2026-07-28 stateless spec.
Can an LLM agent pick the right tool here — names, descriptions and parameter clarity are assessed.
scan_app — Description is cut off, missing critical information about what 'publicly readabl' refers to.explain_finding — Does not explicitly state read-only nature or instant execution in description.Risk: low
tools/list structure, inputSchema validity, and a functional smoke test — the components of the 0-100 score.
Tools the server advertised in the latest measurement — measured, not catalog-claimed.
scan_appRuns a passive, outside-in security check of a live web app and returns a letter grade (A–F), each issue in plain language with fix steps, and a report link. Use when the user asks whether their deployed app is safe, before launch, or after a redeploy to confirm a fix. It checks for publicly readable Supabase/Firebase data, secret keys (Stripe, OpenAI, Supabase service_role…) in client JavaScript, downloadable .env/.git files, source maps, permissive CORS and missing security headers. Do not use it for apps the user does not own or is not authorized to test, for localhost or private addresses, or to review source code — it only sees what the public URL serves. Behavior: sends ordinary GET requests like a browser (no login, exploitation or load testing); takes about 10–30 seconds; saves the
urlstringrequiredi_own_thisbooleanrequiredlangstringexplain_findingReturns the plain-language meaning and step-by-step fix for one Malinois finding. Use it while helping the user fix an issue reported by scan_app, or when they ask what a finding means. Pass the rule_id exactly as scan_app returned it. Read-only, no network, instant.
rule_idstringrequiredlangstringDerived by comparing consecutive probes — changes in era, protocol version, build and reachability.
Add this badge to your README — it updates automatically as measurements change.
[](https://mcpmetrics.io/servers/app-malinois-scan)<a href="https://mcpmetrics.io/servers/app-malinois-scan"><img src="https://mcpmetrics.io/badge/app.malinois/scan/era.svg" alt="mcpmetrics"></a>You are seeing the last 7 days. Sign up for the full history. Which check failed and why is in the dashboard.
Sign up free to seeThe catalog entries whose name and description are closest to this one, found with the same index the search box uses.
Yapp turns "build me a page and publish it" into a live URL. Connect once (browser OAuth, or a token for terminal clients) and your AI can publish a webpage from HTML, or host a PDF, image, or ZIP exactly as-is to a public `<slug>.yapp.page` URL in seconds, then update, password-protect, set expiry, attach a custom domain, or read form submissions, all by asking. Free to start; no local install. **Tools (15):** `publish_page`, `publish_file`, `update_page`, `delete_page`, `get_page_stats`, `list_my_pages`, `rename_page`, `change_page_slug`, `set_page_expiry`, `set_page_password`, `list_submissions`, `add_custom_domain`, `list_custom_domains`, `check_custom_domain`, `remove_custom_domain`.
Public fellowship and grant search with sourced details and live filter vocabularies.
Public holiday data for 30+ countries. Check holidays, working days and calendars via AI assistants.
Free no-account URL security scan: 0-100 Launch Readiness score for any live site in ~15 seconds.
Free brand-name Clearance Checks from live registries; connect a plan (API key) for full checks.
HEAD a public URL and say whether it looks like a PDF. Body discarded.
| Run | Era | Modern | ms | Legacy | ms | Versions |
|---|---|---|---|---|---|---|
| 2026-09-13 01:33:33 | Dual-era | 200 | 967 | 200 | 1002 | 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26 |
| 2026-09-12 23:31:36 | Dual-era | 200 | 1278 | 200 | 1238 | 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26 |
| 2026-09-12 21:29:15 | Dual-era | 200 | 1185 | 200 | 1131 | 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26 |
| 2026-09-12 19:27:29 | Dual-era | 200 | 465 | 200 | 498 | 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26 |
| 2026-09-12 17:24:09 | Dual-era | 200 | 701 | 200 | 760 | 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26 |
| 2026-09-12 15:21:42 | Dual-era | 200 | 725 | 200 | 720 | 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26 |
Each block is one measurement round. Green: working response. Amber: responded but the server was returning errors (5xx). Red: no response at all.
Each cell is one probe run. Faded cells are incomplete probes — one leg did not answer, so the era is inconclusive.
The two probe legs separately: modern server/discover and legacy initialize.
Comments
Sign in to write a comment
No comments yet. Be the first.