ZV-2026-1931 · 2026-10-07 · mcp.scanmalware.com
mcp.scanmalware.com: Field scan_type on submit_scan is now required.
breaking
What changed
Field scan_type on submit_scan is now required. Field x_real_ip was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field user_agent was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field skip_captcha was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field captcha_token was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field captcha_answer was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field x_forwarded_for was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. report_type on submit_scan_report narrowed to a closed enum (positive_feedback, malware); previously valid values may now be rejected.
What to do
If your agents call mcp.scanmalware.com, pin the new snapshot, patch the affected call sites, and let a green contract check confirm the fix. If you don't use the changed tools, nothing is required, but the rest of the ecosystem just learned about it at the same moment you did.
The redline
− scan_type Field scan_type on submit_scan is now required. − x_real_ip Field x_real_ip was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. − user_agent Field user_agent was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. − skip_captcha Field skip_captcha was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. − captcha_token Field captcha_token was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. − captcha_answer Field captcha_answer was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. − x_forwarded_for Field x_forwarded_for was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. − open + enum[positive_feedback,malware] submit_scan_report − Get the favicon for a scan_id: size, hashes, and the image itself base64-encoded. Use the … + Get the favicon recorded for a scan_id: its size, MD5 and SHA-256 hashes, and the image ba… get_favicon − Get JS fingerprint similarity counts. + Get JS fingerprint similarity counts. This query can take up to 90 seconds by default. get_jsfingerprint_similarity_counts − Search scans by favicon hash (paginated). + Search scans by favicon hash (paginated): a mmh3 hash by default, or the favicon's MD5 wit… search_by_favicon − Search JS Fingerprinter2 by signature. + Search JS Fingerprinter2 by signature. An uncached query can take up to 90 seconds by defa… search_js_fingerprinter2_signature − Submit a URL to ScanMalware for scanning. WARNING: scan_type defaults to 'public', which p… + Submit a URL to ScanMalware to be rendered and analysed in a sandboxed browser; returns th… submit_scan + scan_type Default of scan_type on submit_scan changed "public" → unset. − Submit a scan report. + Vote on a scan, as the Mark as Safe and Mark as Malicious buttons on its result page do: r… submit_scan_report − Search JS fingerprints by detected library name. Use identifiers from get_js_library_inven… + Search JS fingerprints by detected library identifier, such as 'react', 'jquery' or 'nextj… search_js_fingerprint_by_library − Search OCR text (paginated). q must contain at least 3 characters after trimming. This que… + Search OCR text (paginated). q must contain at least 3 characters after trimming. This que… search_ocr