ScamCheck MCP Server
Scan suspicious messages, URLs, and text for scams inside any MCP-compatible AI assistant using ScamCheck AI.
Use the
scan_messagetool to check SMS, emails, WhatsApp messages, job offers, links, or OCR-extracted text for scam indicators.Pass a required
input(message/URL/text, min 8 chars) and optionalsource(text,url, orscreenshot; defaulttext).Get a verdict (Likely Scam / Suspicious / Likely Safe), risk score (0-100), category, confidence, reasons flagged, and recommended actions.
Run anonymously with no signup or API key, or add an optional API key for higher rate limits (100 scans/month free, unlimited Pro/Business).
Install in Claude Desktop, Cursor, and other MCP clients via npx or a one-click
.mcpbextension.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ScamCheck MCP ServerCheck if this text is a scam: 'Win a free iPhone!'"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ScamCheck MCP Server
Scan suspicious messages, URLs, and text for scams inside any AI assistant that supports MCP (Claude Desktop, Claude Code, Cursor, and more). No signup or API key needed โ works out of the box on the free anonymous tier.
Quick start (no API key)
Add to your Claude Desktop / Cursor config:
{
"mcpServers": {
"scamcheck": {
"command": "npx",
"args": ["scamcheck-mcp-server"]
}
}
}That's it. Ask your assistant "is this message a scam?" and paste the message.
Related MCP server: scamshield
Higher limits (optional API key)
The anonymous tier is rate-limited per IP. For higher limits, grab a free key at scamcheck.tech/dashboard/developer and add it:
{
"mcpServers": {
"scamcheck": {
"command": "npx",
"args": ["scamcheck-mcp-server"],
"env": {
"SCAMCHECK_API_KEY": "sk-live-your-key-here"
}
}
}
}Tool: scan_message
Parameter | Type | Required | Description |
| string | โ | The message, URL, or text to scan |
|
| โ | Content type (default: |
Example response
๐ด Likely Scam โ Risk Score: 89/100
Category: phishing ยท Confidence: 92%
Summary: This message impersonates a bank to steal credentials.
Why this was flagged:
โข Creates false urgency with account suspension threat
โข Uses a URL that does not match the official bank domain
โข Requests sensitive personal information via link
What to do:
โ Do not click any links in this message
โ Contact your bank directly using the number on your card
โ Report to your bank's fraud department
Full report: https://scamcheck.tech/result/abc123Rate limits
Anonymous (no key): IP rate-limited
Free API key: 100 scans/month
Pro/Business: Unlimited
Install in Claude Desktop (one click)
Download scamcheck.mcpb and double-click it, or drag it into Claude Desktop โ Settings โ Extensions. The API key field is optional; leave it blank to use the free tier.
Privacy Policy
Full policy: scamcheck.tech/privacy
What is collected: only the text or URL you ask the
scan_messagetool to check, plus the optional API key you configure. The extension reads nothing else from your computer or your conversations.How it is used: the content is sent over HTTPS to the ScamCheck API (
scamcheck.tech) and analysed to produce the verdict. Anonymous requests are rate-limited by IP address.Storage and retention: scans may be stored to generate a shareable result link and to improve detection. Retention is described in the full policy linked above.
Third parties: ScamCheck uses an AI model provider to analyse scans. Your data is not sold or used for advertising.
Contact: privacy questions or deletion requests go to support via scamcheck.tech or the GitHub issues.
Available Tools
1 toolscan_messageAInspect
Scan a suspicious message, URL, or text for scam indicators using ScamCheck AI. Returns a verdict (Likely Scam / Suspicious / Likely Safe), risk score (0-100), category, confidence, reasons flagged, and recommended actions. Use this whenever a user shares a message they received and wants to know if it's a scam.
| Name | Required | Description | Default |
|---|---|---|---|
| input | Yes | The message, URL, or text to scan. Minimum 8 characters. Can be SMS, email, WhatsApp message, job offer, or any suspicious content. | |
| source | No | The type of content: 'text' for messages/emails, 'url' for links, 'screenshot' for OCR-extracted text. Default: text. | text |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Description details that the tool returns a verdict, risk score, category, confidence, reasons flagged, and recommended actions. This goes beyond the tool name, and no annotations are provided, so the description carries the full burden. No contradictory or missing behavioral info.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Description is concise and front-loaded with the primary action. Every sentence adds value without redundancy. No unnecessary words.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given only two parameters and no nested objects or output schema, the description fully covers purpose, usage, parameters, and expected output. No gaps or missing information.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, but the description adds context by explaining that input can be SMS, email, etc., and clarifies source types. It also mentions minimum 8 characters, which is not in the schema's 'description' field.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool scans a suspicious message, URL, or text for scam indicators using ScamCheck AI, with specific verb 'scan' and resource 'suspicious content'. It distinguishes the tool's purpose well even without sibling context.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says 'Use this whenever a user shares a message they received and wants to know if it's a scam.' Provides clear context for when to use, though no exclusions or alternatives are mentioned.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v1.1.1- First observed
scan_message
TDQS
Scored across 1 tool
With only one tool, there is no ambiguity. The tool's purpose is clearly distinct as it targets a single action: scanning messages for scams.
The single tool name 'scan_message' follows a clear verb_noun pattern, which is consistent and predictable.
One tool is appropriate for a narrow, single-purpose server like ScamCheck. It slightly underrepresents potential additional features but is reasonable given the focused scope.
The tool covers the core functionality of scanning messages for scams. Minor gaps exist (e.g., no history or configuration), but the primary use case is fully addressed.
Maintenance
Related MCP Connectors
Scam and phishing detection for AI agents: safe/warn/danger verdicts for URLs and messages.
AI-powered scam and threat verification for phone numbers, URLs, texts, and emails.
AI-powered scam detection for suspicious texts, emails, and screenshots. US-focused.
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Related MCP Servers
- AlicenseAqualityBmaintenanceScam Detector - MCP server providing AI-powered tools and automation by MEOK AI Labs5MIT
- FlicenseNot gradedqualityCmaintenanceMCP server for detecting and analyzing scams using various heuristics and data sources.-
- FlicenseNot gradedqualityBmaintenanceEnables MCP-compatible AI agents to scan crypto transactions for scam addresses, clipboard-hijack patterns, and typos, as well as report scam addresses and check usage, directly in conversation.-
- FlicenseNot gradedqualityAmaintenanceEnables MCP-compatible AI assistants to scan files and raw content for malware, prompt injection, and other threats, manage accounts and API keys, and access SDK/API documentation.-