web-exposure-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scan_web_exposureA | Probe a LIVE deployed URL and confirm which sensitive files/directories are actually publicly reachable — by fetching the bytes, not guessing. Detects exposed .git, .env secrets, JavaScript source maps, backup/SQL dumps & archives (.bak/.sql/.zip), directory listing, and sensitive dotfiles (.htpasswd/.npmrc/.aws/credentials/.ssh/id_rsa). Read-only: nothing is written to the target. Returns only findings that are genuinely served, with evidence. |
| list_exposure_checksA | List every exposure check this server can run, with its id, severity, and the paths it probes. Use this to discover check ids for the |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 2 tools
The two tools are entirely distinct: one lists available checks, the other runs the scan. There is no overlap or ambiguity.
Both tools follow the consistent verb_noun pattern (list_exposure_checks, scan_web_exposure), making their purpose immediately clear.
With only two tools, the server is minimal but well-scoped. Each tool serves a clear function; no superfluous or missing core operations.
The tool set covers the full workflow: discover available checks, then run a targeted scan. No obvious gaps for the stated purpose of checking web exposure.