ScamCheck MCP Server
by smijo-geek
README.md
# ScamCheck MCP Server
Scan suspicious messages, URLs, and text for scams inside any AI assistant that supports MCP (Claude Desktop, Claude Code, Cursor, and more). **No signup or API key needed** โ works out of the box on the free anonymous tier.
## Quick start (no API key)
Add to your Claude Desktop / Cursor config:
```json
{
"mcpServers": {
"scamcheck": {
"command": "npx",
"args": ["scamcheck-mcp-server"]
}
}
}
```
That's it. Ask your assistant *"is this message a scam?"* and paste the message.
## Higher limits (optional API key)
The anonymous tier is rate-limited per IP. For higher limits, grab a free key at [scamcheck.tech/dashboard/developer](https://scamcheck.tech/dashboard/developer) and add it:
```json
{
"mcpServers": {
"scamcheck": {
"command": "npx",
"args": ["scamcheck-mcp-server"],
"env": {
"SCAMCHECK_API_KEY": "sk-live-your-key-here"
}
}
}
}
```
## Tool: `scan_message`
| Parameter | Type | Required | Description |
|-----------|------|----------|-------------|
| `input` | string | โ | The message, URL, or text to scan |
| `source` | `text` \| `url` \| `screenshot` | โ | Content type (default: `text`) |
## Example response
```
๐ด Likely Scam โ Risk Score: 89/100
Category: phishing ยท Confidence: 92%
Summary: This message impersonates a bank to steal credentials.
Why this was flagged:
โข Creates false urgency with account suspension threat
โข Uses a URL that does not match the official bank domain
โข Requests sensitive personal information via link
What to do:
โ Do not click any links in this message
โ Contact your bank directly using the number on your card
โ Report to your bank's fraud department
Full report: https://scamcheck.tech/result/abc123
```
## Rate limits
- Anonymous (no key): IP rate-limited
- Free API key: 100 scans/month
- Pro/Business: Unlimited
## Install in Claude Desktop (one click)
Download [scamcheck.mcpb](https://scamcheck.tech/scamcheck.mcpb) and double-click it, or drag it into **Claude Desktop โ Settings โ Extensions**. The API key field is optional; leave it blank to use the free tier.
## Privacy Policy
Full policy: [scamcheck.tech/privacy](https://scamcheck.tech/privacy)
- **What is collected:** only the text or URL you ask the `scan_message` tool to check, plus the optional API key you configure. The extension reads nothing else from your computer or your conversations.
- **How it is used:** the content is sent over HTTPS to the ScamCheck API (`scamcheck.tech`) and analysed to produce the verdict. Anonymous requests are rate-limited by IP address.
- **Storage and retention:** scans may be stored to generate a shareable result link and to improve detection. Retention is described in the full policy linked above.
- **Third parties:** ScamCheck uses an AI model provider to analyse scans. Your data is not sold or used for advertising.
- **Contact:** privacy questions or deletion requests go to support via [scamcheck.tech](https://scamcheck.tech) or the [GitHub issues](https://github.com/smijo-geek/scamcheck-mcp-server/issues).
TDQS
A4.5/5.0
Scored across 1 tool
Disambiguation5/5
With only one tool, there is no ambiguity. The tool's purpose is clearly distinct as it targets a single action: scanning messages for scams.
Naming Consistency5/5
The single tool name 'scan_message' follows a clear verb_noun pattern, which is consistent and predictable.
Tool Count4/5
One tool is appropriate for a narrow, single-purpose server like ScamCheck. It slightly underrepresents potential additional features but is reasonable given the focused scope.
Completeness4/5
The tool covers the core functionality of scanning messages for scams. Minor gaps exist (e.g., no history or configuration), but the primary use case is fully addressed.
Maintenance
ActivityMaintained
ResponsivenessNo issues