Scan any API for OWASP Top 10 vulnerabilities and get a security risk score. Covers authentication, authorization (BOLA/BFLA), injection, data exposure, rate limiting, GraphQL, and LLM security.
middleBrick | API-Security is a remote MCP server published at middlebrick.com. It has been probed 7 times since 9/12/2026. It answered in 7 of them (100.0%), a near-uninterrupted record. Median response time is 418 ms, placing it among the faster endpoints. It offers a narrow, focused set of 3 tools. On the protocol side it still runs 2025-11-25 and has not moved to the newer spec.
Can an LLM agent pick the right tool here — names, descriptions and parameter clarity are assessed.
scan_api — Parameter 'method' lacks allowed HTTP method examples.list_scans — Parameter 'status' does not specify valid status values.Risk: low
tools/list structure, inputSchema validity, and a functional smoke test — the components of the 0-100 score.
Tools the server advertised in the latest measurement — measured, not catalog-claimed.
scan_apiScan an API endpoint for security vulnerabilities and get a risk score
urlstringrequiredmethodstringget_scanGet results of a previous middleBrick scan by its ID
scanIdstringrequiredlist_scansList previous middleBrick API security scans
limitnumberoffsetnumberstatusstringDerived by comparing consecutive probes — changes in era, protocol version, build and reachability.
Add this badge to your README — it updates automatically as measurements change.
[](https://mcpmetrics.io/servers/middlebrick-api-security)<a href="https://mcpmetrics.io/servers/middlebrick-api-security"><img src="https://mcpmetrics.io/badge/middlebrick/api-security/era.svg" alt="mcpmetrics"></a>You are seeing the last 7 days. Sign up for the full history. Which check failed and why is in the dashboard.
Sign up free to seeThe catalog entries whose name and description are closest to this one, found with the same index the search box uses.
Japanese LLM security — prompt injection detection (jpi-guard) + PII masking (PII Guard). Free.
Japanese prompt injection detection and x402 pre-payment security check API. Deterministic validator included. No AI used for core validation.
AI-powered application security testing — scan APIs, discover endpoints, and find vulnerabilities.
AI skill security scanner. Detects prompt injection, credential theft, ClawHavoc. Free, no signup.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Search millions of x402 APIs for data, finance, validation, security, inventory, sync and automation
| Run | Era | Modern | ms | Legacy | ms | Versions |
|---|---|---|---|---|---|---|
| 2026-09-13 06:40:42 | Legacy | 401 | 331 | 200 | 333 | 2025-11-25 |
| 2026-09-13 04:35:29 | Legacy | 401 | 337 | 200 | 393 | 2025-11-25 |
| 2026-09-13 01:33:33 | Legacy | 401 | 298 | 200 | 301 | 2025-11-25 |
| 2026-09-12 23:31:36 | Legacy | 401 | 468 | 200 | 459 | 2025-11-25 |
| 2026-09-12 21:29:15 | Legacy | 401 | 418 | 200 | 476 | 2025-11-25 |
| 2026-09-12 19:27:29 | Legacy | 401 | 467 | 200 | 401 | 2025-11-25 |
| 2026-09-12 17:24:09 | Legacy | 401 | 471 | 200 | 486 | 2025-11-25 |
Each block is one measurement round. Green: working response. Amber: responded but the server was returning errors (5xx). Red: no response at all.
Each cell is one probe run. Faded cells are incomplete probes — one leg did not answer, so the era is inconclusive.
The two probe legs separately: modern server/discover and legacy initialize.
Comments
Sign in to write a comment
No comments yet. Be the first.