
SkanQRCode
com.skanqrcodev1.0.0更新於 Oct 7, 2026
Check whether a URL or IP is safe before an AI agent fetches or opens it.
概覽
讓助理在抓取、開啟或分享連結之前,檢查某個 URL 或 IP 位址是否惡意。
- 功能
- 此伺服器提供 check_url 工具,對完整 URL 或 IP 位址進行分類,回傳結構化判定結果,包含 block、warn 或 allow 的動作、原因代碼以及最終解析位址。另有 get_usage 工具,可查詢每月配額、已用請求數與剩餘請求數。伺服器為唯讀:允許與封鎖清單須在服務商的控制台中管理,無法透過助理修改。
- 適用情境
- 適合助理處理來自不可信來源的連結時使用,例如 QR code、電子郵件、聊天訊息、網頁或其他工具的輸出,在抓取或轉交之前先行查驗。也適合查看每月檢查配額的剩餘情況。
- 執行需求
- 透過 npm 套件 @skanqrcode/mcp-server 以 stdio 在本機執行,需要 Node.js 20 或更新版本。必須在 SKANQRCODE_API_KEY 環境變數中提供 SkanQRCode API 金鑰;免費的 sk_test_ 金鑰每月可進行 1,000 次檢查。選用的 SKANQRCODE_BASE_URL 必須使用 https。需要連線至該 API 的網路存取。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 SkanQRCode,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
@skanqrcode/mcp-server
The official SkanQRCode MCP server. It gives an AI agent a URL safety check to run before it fetches, opens or hands a user a link from an untrusted source: a QR code, an email, a chat message, a web page or another tool's output.
It runs locally over stdio, so it works with Claude Desktop, Claude Code, Cursor, Windsurf and any other MCP client that starts a local process.
Setup
- Create an API key at app.skanqrcode.com. The free plan gives you
an
sk_test_key with 1,000 checks a month, no card required. - Add the server to your MCP client.
Claude Desktop (claude_desktop_config.json), Cursor and most other clients:
Claude Code:
Requires Node.js 20 or later.
Tools
check_url
Classifies a URL or IP address. Input:
Returns the API's verdict as structured content:
The agent should branch on action: block means do not fetch or open it, warn means ask the
user first, allow means go ahead. Each call uses one unit of your monthly quota.
get_usage
Returns the monthly quota, requests used and requests left (optional month as YYYY-MM). It
does not use quota.
Errors
A failed call returns isError: true with
{ "error": { "code": "...", "message": "...", "requestId": "...", "retryAfterSeconds": 12 } }.
For rate_limited, wait retryAfterSeconds; for quota_exceeded, stop and tell the user.
Why there are no list tools
The server is read-only. Text an agent reads can try to steer it, and an agent that could add allow-list entries could be talked into approving a phishing domain. Manage allow and block lists in the dashboard.
Environment variables
Your key is sent only to the API, only over HTTPS, and is never logged.
Sandbox keys
With an sk_test_ key the result says environment: "sandbox" and
licensedForProduction: false: the verdicts are real, but the free plan is licensed for testing
only. Use an sk_live_ key from a paid plan in production.
Development
API reference: docs.skanqrcode.com.
來源:mcp/server/README.md,提交 bda1f2a
工具
0版本歷史
1- v1.0.0最新Oct 7, 2026


