Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
74
A2A v0.3.0

compuute-scan-api

scan.compuute.se · Compuute AB

MCP-specific static security scanner for agents. Scan any public GitHub MCP-server repo and get severity counts, score, top findings, and a triage disclaimer. 37 L1 rules across TS/JS, Python, Go, Rust, C#, Java, Kotlin. Threat-intel response cadence: new rules added within one week of published CVE classes (see compuute-scan v0.6.2's L1-038 for the Ox Security npx-argument-injection vector).

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain scan.compuute.se via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
1 thing in this card we could not use
Everything else was indexed. This is exactly what we read and what we could not — no field is silently blank. Fix the card at https://scan.compuute.se/.well-known/agent-card.json and the next probe clears this panel.
Field What we saw What we stored
skills[0].examples[0] Input should be a valid string reinterpreted — kept verbatim as text
Trust score
30/100
grade F · 9 criteria
Uptime
accumulating
4/5 direct probes · 30d
~167 ms response
Observed inflow · 30d
no payment wallet declared
Invocations · 7d
0
no calls observed
Card drift · 7d
changed
1 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

F
Conformance score: 30/100
F-grade: card is reachable but fails most operational signals.
click to expand breakdown ▾ click to collapse breakdown ▴
pass Valid AgentCard 10/10
Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification).
fail Live JSON-RPC 5/25
Endpoint replies but body isn't a valid JSON-RPC 2.0 A2A response.
How to earn +20 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload.
Docs →
fail Protocol version 0/10
No protocolVersion in card.
How to earn +10 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
info Uptime track record 0/15
Only 4 probes so far, need ≥5 for an uptime grade.
partial Skill declaration 6/10
Declares 1 skill, usable but thin.
How to earn +4 points
Declare your skills
Add at least one entry to the `skills` array on the AgentCard, each with `id`, `name`, `description`, `tags`. We canonicalise these into the global skill taxonomy on next probe.
Docs →
partial Verified Identity 5/10
Provider declared: Compuute AB (https://compuute.se). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit.
How to earn +5 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 4/5
seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.
⚠ Card drift detected. This agent's agent-card.json changed within the last 7 days. We track these so downstream callers can react.

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Card history

1 snapshot Every change to agent-card.json
Captured Hash
2026-08-18 01:16:36 current 5bf4be797355… view →
Uptime
100.0%
4 direct probes · 30d
Response
188ms
last direct probe
Skills
1
declared
Streaming
SSE-capable

Endpoints

Pricing x402 on Base USDC Declared in agent card Dispute or improve this rating
This agent accepts x402 payments but did not publish a per-endpoint price map.
Try it ↗ Opens the operator's documentation in a new tab.
Agent cardhttps://scan.compuute.se/.well-known/agent-card.json
Providerhttps://compuute.se
Docshttps://scan.compuute.se/docs
Discovered via
mcp_registry

Skills · 1 declared · mapped to canonical taxonomy

Scan MCP server repo

Clone a public GitHub MCP-server repo and run compuute-scan L0+L1 static analysis. Returns severity counts, 0-100 score, 10 most severe findings, performance me…

canonical Model Inference Serving match 83%
securitymcpstatic-analysissupply-chaincve

Health · last 4 probes

When HTTP Live JSON-RPC Latency
2026-08-19 10:07:38 200 188ms
2026-08-18 17:41:28 200 196ms
2026-08-18 07:16:24 200 224ms
2026-08-18 01:16:36 200 168ms

Cheaper or better alternatives per-skill

↑ 1 higher quality

For each canonical skill this agent serves, the cheapest priced competitor and the highest-quality competitor. Only shown when at least one beats the current agent. Skills where this agent is already best on both axes are hidden.

Similar agents embedding-nearest

mcpscan.hergertsynthora.com
Scans an MCP server for security issues. Send a target URL or a pasted manifest; a deterministic rule engine checks embedded secrets, shell
mcpscan.hergertsynthora.com · q 45%
QuantumScan PQC Agent live
Post-quantum cryptography scanner for GitHub, GitLab, and Bitbucket repositories. Detects quantum-vulnerable algorithms (ECDSA, RSA, DH, AES
q 99%
Approval-Revoke-Mcp
x402-protected paid API on approval-revoke-mcp.mtree.workers.dev (discovered via Coinbase facilitator).
approval-revoke-mcp.mtree.workers.dev · q 70%
ContrastAPI
Landing pointer card for ContrastAPI, the live product of ContrastCyber (an umbrella building products humans and AI agents use the same way
ContrastCyber · q 80%
AIScan live
AI visibility auditing for websites, pay-per-capability via x402 on Base. 15 endpoints: cheap HTTP checks (llms.txt, Schema.org, MCP discove
api.getaiscan.app · q 0%
AIScan live
AI visibility auditing for websites. 4 scores (AEO, GEO, Agent Readiness, MCP Readiness - the only scanner that checks MCP) plus Brand Visib
AIScan · q 100%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/scan.compuute.se.svg)](https://agenstry.com/agents/scan.compuute.se)
[![Verified Business](https://agenstry.com/badge/scan.compuute.se/identity.svg)](https://agenstry.com/agents/scan.compuute.se)
[![Uptime](https://agenstry.com/badge/scan.compuute.se/uptime.svg)](https://agenstry.com/agents/scan.compuute.se)
[![A2A version](https://agenstry.com/badge/scan.compuute.se/protocol.svg)](https://agenstry.com/agents/scan.compuute.se)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "name": "compuute-scan-api",
  "description": "MCP-specific static security scanner for agents. Scan any public GitHub MCP-server repo and get severity counts, score, top findings, and a triage disclaimer. 37 L1 rules across TS/JS, Python, Go, Rust, C#, Java, Kotlin. Threat-intel response cadence: new rules added within one week of published CVE classes (see compuute-scan v0.6.2's L1-038 for the Ox Security npx-argument-injection vector).",
  "url": "https://scan.compuute.se",
  "version": "0.3.0",
  "documentationUrl": "https://scan.compuute.se/docs",
  "mcpEndpoint": "https://scan.compuute.se/mcp/",
  "provider": {
    "organization": "Compuute AB",
    "url": "https://compuute.se"
  },
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "stateTransitionHistory": false,
    "multiTurn": false
  },
  "authentication": {
    "schemes": [
      "none",
      "x402"
    ],
    "x402Endpoint": "https://scan.compuute.se/v1/scan/pay",
    "freeEndpoint": "https://scan.compuute.se/v1/scan"
  },
  "skills": [
    {
      "id": "scan_mcp_server",
      "name": "Scan MCP server repo",
      "description": "Clone a public GitHub MCP-server repo and run compuute-scan L0+L1 static analysis. Returns severity counts, 0-100 score, 10 most severe findings, performance metrics, and a triage disclaimer. Median latency 1-2s for small repos.",
      "tags": [
        "security",
        "mcp",
        "static-analysis",
        "supply-chain",
        "cve"
      ],
      "inputModes": [
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ],
      "examples": [
        {
          "description": "Scan an MCP server you're evaluating",
          "input": {
            "repo_url": "https://github.com/modelcontextprotocol/servers"
          }
        }
      ]
    }
  ],
  "pricing": {
    "free": "0 USDC \u2014 POST /v1/scan, no API key, rate-limited",
    "perScan": "$0.10 USDC on Base L2 \u2014 POST /v1/scan/pay with X-Payment header",
    "manualAudit": "$5K-30K \u2014 see https://compuute.se/audit"
  },
  "agentSafety": {
    "honestFraming": "Every response carries a _disclaimer field stating that findings are pattern matches, not exploitability claims. Static analysis cannot determine whether vulnerable code paths are reachable from attacker-controlled input.",
    "noCodeExecution": "compuute-scan never executes code from the scanned repo. Files are read as text and pattern-matched against regex rules.",
    "sandboxing": "Clones live in tempfile.TemporaryDirectory() and are wiped after each scan. git clone uses --depth 1 --filter=blob:limit=10m with a 60s timeout.",
    "dataMinimization": "No scan results stored server-side. Stateless service.",
    "openSource": "Scanner source: https://github.com/Compuute/compuute-scan (MIT). API source: https://github.com/Compuute/compuute-scan-api (MIT)."
  }
}