
SkanQRCode
com.skanqrcodev1.0.0更新于 Oct 7, 2026
Check whether a URL or IP is safe before an AI agent fetches or opens it.
概览
让助手在抓取、打开或分享链接之前,检查某个 URL 或 IP 地址是否恶意。
- 功能
- 该服务器提供 check_url 工具,对完整 URL 或 IP 地址进行分类,返回结构化判定结果,包含 block、warn 或 allow 的动作、原因代码以及最终解析地址。另有 get_usage 工具,用于查询每月配额、已用请求数和剩余请求数。服务器为只读:允许与阻止列表需在服务商控制台中管理,不能通过助手修改。
- 适用场景
- 适合助手处理来自不可信来源的链接时使用,例如二维码、电子邮件、聊天消息、网页或其他工具的输出,在抓取或转交之前先行核验。也适合查看每月检查配额的剩余情况。
- 运行要求
- 通过 npm 包 @skanqrcode/mcp-server 以 stdio 在本地运行,需要 Node.js 20 或更高版本。必须在 SKANQRCODE_API_KEY 环境变量中提供 SkanQRCode API 密钥;免费的 sk_test_ 密钥每月可进行 1,000 次检查。可选的 SKANQRCODE_BASE_URL 必须使用 https。需要访问该 API 的网络连接。
安装
在 SourceWeft 中
- 打开 控制台中的 SkanQRCode,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
@skanqrcode/mcp-server
The official SkanQRCode MCP server. It gives an AI agent a URL safety check to run before it fetches, opens or hands a user a link from an untrusted source: a QR code, an email, a chat message, a web page or another tool's output.
It runs locally over stdio, so it works with Claude Desktop, Claude Code, Cursor, Windsurf and any other MCP client that starts a local process.
Setup
- Create an API key at app.skanqrcode.com. The free plan gives you
an
sk_test_key with 1,000 checks a month, no card required. - Add the server to your MCP client.
Claude Desktop (claude_desktop_config.json), Cursor and most other clients:
Claude Code:
Requires Node.js 20 or later.
Tools
check_url
Classifies a URL or IP address. Input:
Returns the API's verdict as structured content:
The agent should branch on action: block means do not fetch or open it, warn means ask the
user first, allow means go ahead. Each call uses one unit of your monthly quota.
get_usage
Returns the monthly quota, requests used and requests left (optional month as YYYY-MM). It
does not use quota.
Errors
A failed call returns isError: true with
{ "error": { "code": "...", "message": "...", "requestId": "...", "retryAfterSeconds": 12 } }.
For rate_limited, wait retryAfterSeconds; for quota_exceeded, stop and tell the user.
Why there are no list tools
The server is read-only. Text an agent reads can try to steer it, and an agent that could add allow-list entries could be talked into approving a phishing domain. Manage allow and block lists in the dashboard.
Environment variables
Your key is sent only to the API, only over HTTPS, and is never logged.
Sandbox keys
With an sk_test_ key the result says environment: "sandbox" and
licensedForProduction: false: the verdicts are real, but the free plan is licensed for testing
only. Use an sk_live_ key from a paid plan in production.
Development
API reference: docs.skanqrcode.com.
来源:mcp/server/README.md,提交 bda1f2a
工具
0版本历史
1- v1.0.0最新Oct 7, 2026


