
SkanQRCode
com.skanqrcodev1.0.0Updated Oct 7, 2026
Check whether a URL or IP is safe before an AI agent fetches or opens it.
Overview
Lets an assistant check whether a URL or IP address is malicious before fetching, opening or sharing it.
- What it does
- The server exposes a check_url tool that classifies a full URL or IP address and returns a structured verdict with an action of block, warn or allow, plus reason codes and the resolved final URL. A get_usage tool reports the monthly quota, requests used and requests left. It is read-only: allow and block lists are managed in the provider's dashboard, not through the assistant.
- When to use it
- Useful when an assistant handles links from untrusted sources such as QR codes, emails, chat messages, web pages or other tools' output and should verify them before fetching or passing them on. Also useful for tracking remaining monthly check quota.
- Requirements
- Runs locally over stdio via the npm package @skanqrcode/mcp-server, so Node.js 20 or later is needed. A SkanQRCode API key is required in the SKANQRCODE_API_KEY environment variable; a free sk_test_ key allows 1,000 checks a month. An optional SKANQRCODE_BASE_URL must use https. Network access to the API is required.
Installation
In SourceWeft
- Open SkanQRCode in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
@skanqrcode/mcp-server
The official SkanQRCode MCP server. It gives an AI agent a URL safety check to run before it fetches, opens or hands a user a link from an untrusted source: a QR code, an email, a chat message, a web page or another tool's output.
It runs locally over stdio, so it works with Claude Desktop, Claude Code, Cursor, Windsurf and any other MCP client that starts a local process.
Setup
- Create an API key at app.skanqrcode.com. The free plan gives you
an
sk_test_key with 1,000 checks a month, no card required. - Add the server to your MCP client.
Claude Desktop (claude_desktop_config.json), Cursor and most other clients:
Claude Code:
Requires Node.js 20 or later.
Tools
check_url
Classifies a URL or IP address. Input:
Returns the API's verdict as structured content:
The agent should branch on action: block means do not fetch or open it, warn means ask the
user first, allow means go ahead. Each call uses one unit of your monthly quota.
get_usage
Returns the monthly quota, requests used and requests left (optional month as YYYY-MM). It
does not use quota.
Errors
A failed call returns isError: true with
{ "error": { "code": "...", "message": "...", "requestId": "...", "retryAfterSeconds": 12 } }.
For rate_limited, wait retryAfterSeconds; for quota_exceeded, stop and tell the user.
Why there are no list tools
The server is read-only. Text an agent reads can try to steer it, and an agent that could add allow-list entries could be talked into approving a phishing domain. Manage allow and block lists in the dashboard.
Environment variables
Your key is sent only to the API, only over HTTPS, and is never logged.
Sandbox keys
With an sk_test_ key the result says environment: "sandbox" and
licensedForProduction: false: the verdicts are real, but the free plan is licensed for testing
only. Use an sk_live_ key from a paid plan in production.
Development
API reference: docs.skanqrcode.com.
Source: mcp/server/README.md at commit bda1f2a
Tools
0Version history
1- v1.0.0LatestOct 7, 2026


