ZV-2026-1931 · 2026-10-07 · mcp.scanmalware.com

mcp.scanmalware.com: Field scan_type on submit_scan is now required.

breaking

What changed

Field scan_type on submit_scan is now required. Field x_real_ip was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field user_agent was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field skip_captcha was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field captcha_token was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field captcha_answer was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. Field x_forwarded_for was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. report_type on submit_scan_report narrowed to a closed enum (positive_feedback, malware); previously valid values may now be rejected.

What to do

If your agents call mcp.scanmalware.com, pin the new snapshot, patch the affected call sites, and let a green contract check confirm the fix. If you don't use the changed tools, nothing is required, but the rest of the ecosystem just learned about it at the same moment you did.

The redline

−  scan_type  Field scan_type on submit_scan is now required.
−  x_real_ip  Field x_real_ip was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored.
−  user_agent  Field user_agent was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored.
−  skip_captcha  Field skip_captcha was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored.
−  captcha_token  Field captcha_token was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored.
−  captcha_answer  Field captcha_answer was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored.
−  x_forwarded_for  Field x_forwarded_for was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored.
−  open
+  enum[positive_feedback,malware]   submit_scan_report
−  Get the favicon for a scan_id: size, hashes, and the image itself base64-encoded. Use the …
+  Get the favicon recorded for a scan_id: its size, MD5 and SHA-256 hashes, and the image ba…   get_favicon
−  Get JS fingerprint similarity counts.
+  Get JS fingerprint similarity counts. This query can take up to 90 seconds by default.   get_jsfingerprint_similarity_counts
−  Search scans by favicon hash (paginated).
+  Search scans by favicon hash (paginated): a mmh3 hash by default, or the favicon's MD5 wit…   search_by_favicon
−  Search JS Fingerprinter2 by signature.
+  Search JS Fingerprinter2 by signature. An uncached query can take up to 90 seconds by defa…   search_js_fingerprinter2_signature
−  Submit a URL to ScanMalware for scanning. WARNING: scan_type defaults to 'public', which p…
+  Submit a URL to ScanMalware to be rendered and analysed in a sandboxed browser; returns th…   submit_scan
+  scan_type  Default of scan_type on submit_scan changed "public" → unset.
−  Submit a scan report.
+  Vote on a scan, as the Mark as Safe and Mark as Malicious buttons on its result page do: r…   submit_scan_report
−  Search JS fingerprints by detected library name. Use identifiers from get_js_library_inven…
+  Search JS fingerprints by detected library identifier, such as 'react', 'jquery' or 'nextj…   search_js_fingerprint_by_library
−  Search OCR text (paginated). q must contain at least 3 characters after trimming. This que…
+  Search OCR text (paginated). q must contain at least 3 characters after trimming. This que…   search_ocr
Full mcp.scanmalware.com changelog →JSON feedWatch this for my agents