SkanQRCode

com.skanqrcodev1.0.0更新于 Oct 7, 2026

Check whether a URL or IP is safe before an AI agent fetches or opens it.

已验证STDIO仅桌面Security & Monitoring

概览

AI 生成的概览

让助手在抓取、打开或分享链接之前,检查某个 URL 或 IP 地址是否恶意。

功能
该服务器提供 check_url 工具,对完整 URL 或 IP 地址进行分类,返回结构化判定结果,包含 block、warn 或 allow 的动作、原因代码以及最终解析地址。另有 get_usage 工具,用于查询每月配额、已用请求数和剩余请求数。服务器为只读:允许与阻止列表需在服务商控制台中管理,不能通过助手修改。
适用场景
适合助手处理来自不可信来源的链接时使用,例如二维码、电子邮件、聊天消息、网页或其他工具的输出,在抓取或转交之前先行核验。也适合查看每月检查配额的剩余情况。
运行要求
通过 npm 包 @skanqrcode/mcp-server 以 stdio 在本地运行,需要 Node.js 20 或更高版本。必须在 SKANQRCODE_API_KEY 环境变量中提供 SkanQRCode API 密钥;免费的 sk_test_ 密钥每月可进行 1,000 次检查。可选的 SKANQRCODE_BASE_URL 必须使用 https。需要访问该 API 的网络连接。
安装前请注意
API 密钥属于机密,会通过 HTTPS 发送给服务商的 API。每次调用 check_url 都会消耗一个月的配额单位。使用 sk_test_ 密钥得到的判定为沙箱结果,未获生产使用许可。可选的 userId 字段应为不透明标识符,绝不能是电子邮件或姓名。该服务器为只读,无法修改允许或阻止列表。

安装

在 SourceWeft 中

  1. 打开 控制台中的 SkanQRCode,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

@skanqrcode/mcp-server

The official SkanQRCode MCP server. It gives an AI agent a URL safety check to run before it fetches, opens or hands a user a link from an untrusted source: a QR code, an email, a chat message, a web page or another tool's output.

It runs locally over stdio, so it works with Claude Desktop, Claude Code, Cursor, Windsurf and any other MCP client that starts a local process.

Setup

  1. Create an API key at app.skanqrcode.com. The free plan gives you an sk_test_ key with 1,000 checks a month, no card required.
  2. Add the server to your MCP client.

Claude Desktop (claude_desktop_config.json), Cursor and most other clients:

json
{  "mcpServers": {    "skanqrcode": {      "command": "npx",      "args": ["-y", "@skanqrcode/mcp-server"],      "env": { "SKANQRCODE_API_KEY": "sk_test_..." }    }  }}

Claude Code:

bash
claude mcp add skanqrcode --env SKANQRCODE_API_KEY=sk_test_... -- npx -y @skanqrcode/mcp-server

Requires Node.js 20 or later.

Tools

check_url

Classifies a URL or IP address. Input:

FieldRequiredDescription
targetyesThe full URL (with scheme) or IP address, up to 4,096 characters.
userIdnoOpaque id of the end user the check is for, for per-user caching. Never an email or a name.

Returns the API's verdict as structured content:

json
{  "verdict": "malicious",  "action": "block",  "mode": "url",  "reasons": ["ACTIVE_THREAT_FEED_MATCH", "KNOWN_MALWARE_MATCH"],  "finalUrl": null,  "cached": false,  "executionTimeMs": 38,  "environment": "production",  "licensedForProduction": true,  "requestId": "req_01j9z8qaenp0s2c4d6f8g0h1jk"}

The agent should branch on action: block means do not fetch or open it, warn means ask the user first, allow means go ahead. Each call uses one unit of your monthly quota.

get_usage

Returns the monthly quota, requests used and requests left (optional month as YYYY-MM). It does not use quota.

Errors

A failed call returns isError: true with { "error": { "code": "...", "message": "...", "requestId": "...", "retryAfterSeconds": 12 } }. For rate_limited, wait retryAfterSeconds; for quota_exceeded, stop and tell the user.

Why there are no list tools

The server is read-only. Text an agent reads can try to steer it, and an agent that could add allow-list entries could be talked into approving a phishing domain. Manage allow and block lists in the dashboard.

Environment variables

VariableRequiredDefault
SKANQRCODE_API_KEYyes—
SKANQRCODE_BASE_URLnohttps://api.skanqrcode.com (must be https://)

Your key is sent only to the API, only over HTTPS, and is never logged.

Sandbox keys

With an sk_test_ key the result says environment: "sandbox" and licensedForProduction: false: the verdicts are real, but the free plan is licensed for testing only. Use an sk_live_ key from a paid plan in production.

Development

bash
npm installnpm test          # unit tests and an MCP client/server round tripnpm run buildSKANQRCODE_API_KEY=sk_test_... npx @modelcontextprotocol/inspector node dist/index.js

API reference: docs.skanqrcode.com.

来源:mcp/server/README.md,提交 bda1f2a

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.0最新Oct 7, 2026