# Compuute MCP Security Scanner

> Compuute MCP Security Scanner — daniel-abbay-compuute-scan-api. Use this tool when you need to scan MCP servers for security vulnerabilities and VEX (Vulnerability Exploitability eXchange) data is not available. It takes a public GitHub URL as input and returns severity counts, a score, and top findings with file and line information, helping to identify potential issues such as argument injection and known CVEs. Ideal for developers and security teams looking to detect security risks in their codebases, particularly those using languages with official MCP SDKs.

Canonical page: https://skillsregistry.net/skills/daniel-abbay-compuute-scan-api  
JSON: https://api.skillsregistry.net/v1/skills/daniel-abbay-compuute-scan-api

## Description

Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back.

37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning).

This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly.

POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review.

Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.

## Trust

- **Trust score (0–1):** 0.30
- **Verification tier:** unverified
- **Last scanned:** 2026-08-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-08-28

## Source

- **Source listing:** [Smithery](https://smithery.ai/server/daniel-abbay/compuute-scan-api)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "daniel-abbay-compuute-scan-api"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/daniel-abbay-compuute-scan-api` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/daniel-abbay-compuute-scan-api/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
