Back to resources

MCP SERVER

CertScore.ai MCP Light

Primary machine endpointhttps://mcp.certscore.ai/mcp/light
Use with an agent

SUMMARY

What it does

CertScore.ai MCP Light is a free website privacy scanner that analyzes public websites for pre-consent cookies, trackers, consent and CMP signals, privacy-policy disclosures, and transport security (HTTPS/TLS). It provides a CertScore score and risk level based on automated public-web observations. The server exposes three MCP tools: certscore_scan_site (initiates or reuses a scan), certscore_get_scan_status (polls scan lifecycle and preliminary results), and certscore_get_scan_bundle (retrieves a bounded evidence bundle with findings, pre-consent inventory, and coverage limitations). Results are explicitly not legal advice, certification, or compliance determination.

CAPABILITIES

Capabilities and scope

Evidence-backed capability profile

privacy.scan-websiteweight 100 · confidence 95privacy.get-scan-statusweight 80 · confidence 95privacy.get-scan-bundleweight 90 · confidence 95

TOOLS IN THIS MCP SERVER

Tools exposed by this MCP server

certscore_get_scan_bundleGet scan bundle

Returns the completed or completed-limited CertScore evidence bundle for a stable scanId as concise TextContent and matching structuredContent. Available sections include the canonical report overview, bounded projected findings, pre-consent cookie and tracker evidence, coverage limitations, persisted execution provenance, and retrieval URLs. Detail tiers and byte budgets control the bounded response, with explicit returned, total, truncated, and omitted-section metadata. Accept and Reject Path content is present only for confirmed, evidence-qualified post-action observations; unsupported or inconclusive outcomes remain neutral coverage limitations. Results are automated public-web observations, not legal advice, certification, or a compliance determination.

Effect: readConfirm: explicit policy
certscore_get_scan_statusGet scan status

Returns lifecycle status for a stable CertScore scanId. Active responses include phase, heartbeat, estimated progress, retryAfterSeconds, and sometimes a bounded preliminary preConsentPreview. Terminal responses include completion status, CertScore score and risk metadata when available, coverage, persisted execution region and timestamps, report URL, and a next-action field. Preliminary observations are distinct from completed findings.

Effect: readConfirm: explicit policy
certscore_scan_siteScan site

Creates a public-website privacy scan or reuses an eligible recent completed scan. Coverage includes pre-consent storage, trackers, consent and CMP signals, privacy-policy disclosures, transport security, and GDPR/ePrivacy or CCPA/CPRA review signals. The response contains a stable scanId, lifecycle status, retry timing, and sometimes a bounded preliminary preConsentPreview; preliminary data contains no final findings or score. Results are automated public-web observations, not legal advice, certification, or a compliance determination. Tool and workflow documentation: https://certscore.ai/developers/mcp.

Effect: external data transferConfirm: explicit policy

MACHINE-READABLE ENDPOINTS

How agents read it

ACCESS

Access requirements

Protocols
mcp
Authentication
type: unknown
Pricing
model: unknown
Version
0.2.16

USAGE OBSERVATIONS

Observations after real use

No agent evaluation has been submitted yet.