SkanQRCode

com.skanqrcodev1.0.0更新於 Oct 7, 2026

Check whether a URL or IP is safe before an AI agent fetches or opens it.

已驗證STDIO僅桌面Security & Monitoring

概覽

AI 產生的概覽

讓助理在抓取、開啟或分享連結之前,檢查某個 URL 或 IP 位址是否惡意。

功能
此伺服器提供 check_url 工具,對完整 URL 或 IP 位址進行分類,回傳結構化判定結果,包含 block、warn 或 allow 的動作、原因代碼以及最終解析位址。另有 get_usage 工具,可查詢每月配額、已用請求數與剩餘請求數。伺服器為唯讀:允許與封鎖清單須在服務商的控制台中管理,無法透過助理修改。
適用情境
適合助理處理來自不可信來源的連結時使用,例如 QR code、電子郵件、聊天訊息、網頁或其他工具的輸出,在抓取或轉交之前先行查驗。也適合查看每月檢查配額的剩餘情況。
執行需求
透過 npm 套件 @skanqrcode/mcp-server 以 stdio 在本機執行,需要 Node.js 20 或更新版本。必須在 SKANQRCODE_API_KEY 環境變數中提供 SkanQRCode API 金鑰;免費的 sk_test_ 金鑰每月可進行 1,000 次檢查。選用的 SKANQRCODE_BASE_URL 必須使用 https。需要連線至該 API 的網路存取。
安裝前請注意
API 金鑰屬於機密,會透過 HTTPS 傳送給服務商的 API。每次呼叫 check_url 都會消耗一個月的配額單位。使用 sk_test_ 金鑰取得的判定為沙箱結果,未獲正式環境使用授權。選用的 userId 欄位應為不透明識別碼,絕不能是電子郵件或姓名。此伺服器為唯讀,無法修改允許或封鎖清單。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 SkanQRCode,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

@skanqrcode/mcp-server

The official SkanQRCode MCP server. It gives an AI agent a URL safety check to run before it fetches, opens or hands a user a link from an untrusted source: a QR code, an email, a chat message, a web page or another tool's output.

It runs locally over stdio, so it works with Claude Desktop, Claude Code, Cursor, Windsurf and any other MCP client that starts a local process.

Setup

  1. Create an API key at app.skanqrcode.com. The free plan gives you an sk_test_ key with 1,000 checks a month, no card required.
  2. Add the server to your MCP client.

Claude Desktop (claude_desktop_config.json), Cursor and most other clients:

json
{  "mcpServers": {    "skanqrcode": {      "command": "npx",      "args": ["-y", "@skanqrcode/mcp-server"],      "env": { "SKANQRCODE_API_KEY": "sk_test_..." }    }  }}

Claude Code:

bash
claude mcp add skanqrcode --env SKANQRCODE_API_KEY=sk_test_... -- npx -y @skanqrcode/mcp-server

Requires Node.js 20 or later.

Tools

check_url

Classifies a URL or IP address. Input:

FieldRequiredDescription
targetyesThe full URL (with scheme) or IP address, up to 4,096 characters.
userIdnoOpaque id of the end user the check is for, for per-user caching. Never an email or a name.

Returns the API's verdict as structured content:

json
{  "verdict": "malicious",  "action": "block",  "mode": "url",  "reasons": ["ACTIVE_THREAT_FEED_MATCH", "KNOWN_MALWARE_MATCH"],  "finalUrl": null,  "cached": false,  "executionTimeMs": 38,  "environment": "production",  "licensedForProduction": true,  "requestId": "req_01j9z8qaenp0s2c4d6f8g0h1jk"}

The agent should branch on action: block means do not fetch or open it, warn means ask the user first, allow means go ahead. Each call uses one unit of your monthly quota.

get_usage

Returns the monthly quota, requests used and requests left (optional month as YYYY-MM). It does not use quota.

Errors

A failed call returns isError: true with { "error": { "code": "...", "message": "...", "requestId": "...", "retryAfterSeconds": 12 } }. For rate_limited, wait retryAfterSeconds; for quota_exceeded, stop and tell the user.

Why there are no list tools

The server is read-only. Text an agent reads can try to steer it, and an agent that could add allow-list entries could be talked into approving a phishing domain. Manage allow and block lists in the dashboard.

Environment variables

VariableRequiredDefault
SKANQRCODE_API_KEYyes—
SKANQRCODE_BASE_URLnohttps://api.skanqrcode.com (must be https://)

Your key is sent only to the API, only over HTTPS, and is never logged.

Sandbox keys

With an sk_test_ key the result says environment: "sandbox" and licensedForProduction: false: the verdicts are real, but the free plan is licensed for testing only. Use an sk_live_ key from a paid plan in production.

Development

bash
npm installnpm test          # unit tests and an MCP client/server round tripnpm run buildSKANQRCODE_API_KEY=sk_test_... npx @modelcontextprotocol/inspector node dist/index.js

API reference: docs.skanqrcode.com.

來源:mcp/server/README.md,提交 bda1f2a

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 7, 2026