[{"slug":"ZV-2026-1960","server_name":"mcp.scanmalware.com","severity":"breaking","title":"mcp.scanmalware.com: Field has_websocket was removed from search_js_fingerprint_patterns input; consumers still sending it may be rejected or silently ignored.","summary":"[risky] Description of get_technology_stats changed (42% word delta). [risky] Description of search_ai_high_risk changed (40% word delta). [risky] Description of search_js_fingerprint_obfuscated changed (32% word delta). [risky] Description of search_js_fingerprint_patterns changed (84% word delta). [breaking] Field has_websocket was removed from search_js_fingerprint_patterns input; consumers still sending it may be rejected or silently ignored. [risky] Description of search_js_malware_families changed (77% word delta). [risky] Description of search_js_obfuscation changed (84% word delta).","changes":[{"kind":"description_changed","tool":"get_technology_stats","after":"Get technology detection statistics across the archive: unique technologies, total detections and counts per category. This aggregate query can take up to 90 seconds by default.","before":"Get technology detection statistics across the archive: unique technologies, total detections and counts per category.","detail":"Description of `get_technology_stats` changed (42% word delta).","severity":"risky","descriptionDelta":0.42307692307692313},{"kind":"description_changed","tool":"search_ai_high_risk","after":"List scans that the AI analysis rated high risk, optionally above min_risk_score and min_confidence, each with URL, title and the analysis. min_risk_score is on the AI's 0-10 risk scale (default 7) and min_confidence is a 0-100 percentage (default 70).","before":"List scans that the AI analysis rated high risk, optionally above min_risk_score and min_confidence, each with URL, title and the analysis.","detail":"Description of `search_ai_high_risk` changed (40% word delta).","severity":"risky","descriptionDelta":0.4},{"kind":"description_changed","tool":"search_js_fingerprint_obfuscated","after":"List scanned JavaScript scored as obfuscated, filtered by score range, classification and minimum code length; exclude_libraries drops known library code. min_score and max_score are obfuscation scores from 0 to 1 (defaults 0.7 and 1.0). Paginated with page and per_page.","before":"List scanned JavaScript scored as obfuscated, filtered by score range, classification and minimum code length; exclude_libraries drops known library code. Paginated with page and per_page.","detail":"Description of `search_js_fingerprint_obfuscated` changed (32% word delta).","severity":"risky","descriptionDelta":0.32352941176470584},{"kind":"description_changed","tool":"search_js_fingerprint_patterns","after":"List scanned JavaScript files that match code-pattern filters: has_eval, has_crypto, high_entropy, no_library and cdn_mismatch, where false selects files without the pattern and filters can be combined. With no filter given, has_eval=true is applied. Each result has the fingerprint ID, scan, script URL, code length, obfuscation score and the patterns detected.","before":"Search JS fingerprints by patterns. Supply at least one boolean filter: has_eval, has_crypto, has_websocket, high_entropy, no_library, or cdn_mismatch. For example, use has_eval=true. Explicit false is also a filter; limit alone is not a filter.","detail":"Description of `search_js_fingerprint_patterns` changed (84% word delta).","severity":"risky","descriptionDelta":0.8412698412698413},{"kind":"input_property_removed","path":"inputSchema.properties.has_websocket","tool":"search_js_fingerprint_patterns","before":{"anyOf":[{"type":"boolean"},{"type":"null"}],"title":"Has Websocket","default":null},"detail":"Field `has_websocket` was removed from `search_js_fingerprint_patterns` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"description_changed","tool":"search_js_malware_families","after":"List groups of scans whose runtime JavaScript behaves alike (possible malware families), with clusters of at least min_cluster_size scans (default 2) at similarity_threshold or above (0 to 1, default 0.95). When the service has clustering switched off, status is 'disabled' and no families are returned.","before":"Search JS malware families. Supply min_cluster_size (at least 1) or similarity_threshold (0 to 1), or both; limit alone is not a filter. For example, use min_cluster_size=2.","detail":"Description of `search_js_malware_families` changed (77% word delta).","severity":"risky","descriptionDelta":0.7692307692307692},{"kind":"description_changed","tool":"search_js_obfuscation","after":"List scans by the obfuscation signals their runtime JavaScript showed, newest analysis first: overall risk, maximum and average risk score, eval and Function constructor calls and high-risk events. Optional filters are risk_level (such as 'high' or 'critical'), min_risk_score (0-100) and has_eval; with none, the most recently analysed scans are listed.","before":"Search JS obfuscation signals. Supply at least one of risk_level, min_risk_score, or has_eval; limit alone is not a filter. For example, use has_eval=true. Explicit false and a min_risk_score of 0 are valid filters.","detail":"Description of `search_js_obfuscation` changed (84% word delta).","severity":"risky","descriptionDelta":0.8412698412698413}],"published_at":"2026-10-08T09:55:17.518Z"},{"slug":"ZV-2026-1931","server_name":"mcp.scanmalware.com","severity":"breaking","title":"mcp.scanmalware.com: Field scan_type on submit_scan is now required.","summary":"[risky] Description of get_favicon changed (57% word delta). [risky] Description of get_jsfingerprint_similarity_counts changed (67% word delta). [risky] Description of search_by_favicon changed (60% word delta). [safe] Description of search_js_fingerprint_by_library changed (23% word delta). [risky] Description of search_js_fingerprinter2_signature changed (67% word delta). [safe] Description of search_ocr changed (18% word delta). [risky] Description of submit_scan changed (68% word delta). [breaking] Field scan_type on submit_scan is now required. [risky] Default of scan_type on submit_scan changed \"public\" → unset. [risky] Description of submit_scan_report changed (95% word delta). [breaking] Field x_real_ip was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. [breaking] Field user_agent was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. [breaking] Field skip_captcha was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. [breaking] Field captcha_token was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. [breaking] Field captcha_answer was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. [breaking] Field x_forwarded_for was removed from submit_scan_report input; consumers still sending it may be rejected or silently ignored. [breaking] report_type on submit_scan_report narrowed to a closed enum (positive_feedback, malware); previously valid values may now be rejected.","changes":[{"kind":"description_changed","tool":"get_favicon","after":"Get the favicon recorded for a scan_id: its size, MD5 and SHA-256 hashes, and the image base64-encoded. found is false when no favicon is stored for the scan.","before":"Get the favicon for a scan_id: size, hashes, and the image itself base64-encoded. Use the md5 with search_by_favicon to pivot.","detail":"Description of `get_favicon` changed (57% word delta).","severity":"risky","descriptionDelta":0.5666666666666667},{"kind":"description_changed","tool":"get_jsfingerprint_similarity_counts","after":"Get JS fingerprint similarity counts. This query can take up to 90 seconds by default.","before":"Get JS fingerprint similarity counts.","detail":"Description of `get_jsfingerprint_similarity_counts` changed (67% word delta).","severity":"risky","descriptionDelta":0.6666666666666667},{"kind":"description_changed","tool":"search_by_favicon","after":"Search scans by favicon hash (paginated): a mmh3 hash by default, or the favicon's MD5 with hash_type='md5'.","before":"Search scans by favicon hash (paginated).","detail":"Description of `search_by_favicon` changed (60% word delta).","severity":"risky","descriptionDelta":0.6},{"kind":"description_changed","tool":"search_js_fingerprint_by_library","after":"Search JS fingerprints by detected library identifier, such as 'react', 'jquery' or 'nextjs'. The display name 'Next.js' is accepted as an alias for 'nextjs'.","before":"Search JS fingerprints by detected library name. Use identifiers from get_js_library_inventory, such as 'react' or 'nextjs'. The display name 'Next.js' is accepted as an alias for 'nextjs'.","detail":"Description of `search_js_fingerprint_by_library` changed (23% word delta).","severity":"safe","descriptionDelta":0.23076923076923073},{"kind":"description_changed","tool":"search_js_fingerprinter2_signature","after":"Search JS Fingerprinter2 by signature. An uncached query can take up to 90 seconds by default.","before":"Search JS Fingerprinter2 by signature.","detail":"Description of `search_js_fingerprinter2_signature` changed (67% word delta).","severity":"risky","descriptionDelta":0.6666666666666667},{"kind":"description_changed","tool":"search_ocr","after":"Search OCR text (paginated). q must contain at least 3 characters after trimming. This query can take up to 90 seconds by default.","before":"Search OCR text (paginated). q must contain at least 3 characters after trimming. This query can take up to 90 seconds by default; allow it to finish before retrying.","detail":"Description of `search_ocr` changed (18% word delta).","severity":"safe","descriptionDelta":0.1785714285714286},{"kind":"description_changed","tool":"submit_scan","after":"Submit a URL to ScanMalware to be rendered and analysed in a sandboxed browser; returns the new scan_id. scan_type is required and sets who can see the result: 'public' lists the URL and its results in the public feed, visible to anyone and to search engines; 'unlisted' keeps the scan out of public listings, but anyone with its link can open it; 'private' limits the result to the ScanMalware account of this server's SCANMALWARE_BEARER_TOKEN and is rejected when no token is configured. Wraps POST /api/v1/scan of the ScanMalware API, documented at https://scanmalware.com/api-docs.","before":"Submit a URL to ScanMalware for scanning. WARNING: scan_type defaults to 'public', which publishes the target URL and scan results in the public feed and makes them visible to other users and search engines. Choose visibility explicitly: 'public' publishes the scan; 'unlisted' keeps it out of public listings but anyone with the direct link can access it; 'private' restricts results to the authenticated ScanMalware account and requires this server's SCANMALWARE_BEARER_TOKEN to be configured. For client targets, confidential URLs, or security engagements, ask the user to choose 'unlisted' or 'private' unless they have already specified visibility; use 'public' only with explicit approval to publish. Never fall back to a less restrictive visibility if submission fails.","detail":"Description of `submit_scan` changed (68% word delta).","severity":"risky","descriptionDelta":0.6846846846846847},{"kind":"input_required_added","path":"inputSchema.required.scan_type","tool":"submit_scan","detail":"Field `scan_type` on `submit_scan` is now required.","severity":"breaking"},{"kind":"default_changed","path":"inputSchema.properties.scan_type","tool":"submit_scan","before":"public","detail":"Default of `scan_type` on `submit_scan` changed \"public\" → unset.","severity":"risky"},{"kind":"description_changed","tool":"submit_scan_report","after":"Vote on a scan, as the Mark as Safe and Mark as Malicious buttons on its result page do: report_type 'positive_feedback' marks the scanned page as safe and 'malware' marks it as malicious. report_details is an optional note of up to 1000 characters. Votes are recorded as crowd feedback on the scan and are rate-limited per client IP. The website's other report types (phishing, spam, copyright and so on) need a captcha and are not available here.","before":"Submit a scan report.","detail":"Description of `submit_scan_report` changed (95% word delta).","severity":"risky","descriptionDelta":0.9464285714285714},{"kind":"input_property_removed","path":"inputSchema.properties.x_real_ip","tool":"submit_scan_report","before":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"X Real Ip","default":null},"detail":"Field `x_real_ip` was removed from `submit_scan_report` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_property_removed","path":"inputSchema.properties.user_agent","tool":"submit_scan_report","before":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"User Agent","default":null},"detail":"Field `user_agent` was removed from `submit_scan_report` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_property_removed","path":"inputSchema.properties.skip_captcha","tool":"submit_scan_report","before":{"anyOf":[{"type":"boolean"},{"type":"null"}],"title":"Skip Captcha","default":null},"detail":"Field `skip_captcha` was removed from `submit_scan_report` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_property_removed","path":"inputSchema.properties.captcha_token","tool":"submit_scan_report","before":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Captcha Token","default":null},"detail":"Field `captcha_token` was removed from `submit_scan_report` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_property_removed","path":"inputSchema.properties.captcha_answer","tool":"submit_scan_report","before":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Captcha Answer","default":null},"detail":"Field `captcha_answer` was removed from `submit_scan_report` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"input_property_removed","path":"inputSchema.properties.x_forwarded_for","tool":"submit_scan_report","before":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"X Forwarded For","default":null},"detail":"Field `x_forwarded_for` was removed from `submit_scan_report` input; consumers still sending it may be rejected or silently ignored.","severity":"breaking"},{"kind":"enum_narrowed","path":"inputSchema.properties.report_type","tool":"submit_scan_report","after":"enum[positive_feedback,malware]","before":"open","detail":"`report_type` on `submit_scan_report` narrowed to a closed enum (positive_feedback, malware); previously valid values may now be rejected.","severity":"breaking"}],"published_at":"2026-10-07T20:23:15.865Z"},{"slug":"ZV-2026-1712","server_name":"mcp.scanmalware.com","severity":"breaking","title":"mcp.scanmalware.com: scan_type on submit_scan narrowed to a closed enum (public, unlisted, private); previously valid values may now be rejected.","summary":"[risky] Description of get_favicon_stats changed (79% word delta). [risky] Description of search_js_fingerprint_by_library changed (75% word delta). [risky] Description of search_js_fingerprint_patterns changed (83% word delta). [risky] Description of search_js_malware_families changed (83% word delta). [risky] Description of search_js_obfuscation changed (87% word delta). [risky] Description of search_ocr changed (86% word delta). [risky] Description of submit_scan changed (94% word delta). [breaking] scan_type on submit_scan narrowed to a closed enum (public, unlisted, private); previously valid values may now be rejected.","changes":[{"kind":"description_changed","tool":"get_favicon_stats","after":"Get favicon statistics. This aggregate query can take up to 90 seconds by default.","before":"Get favicon statistics.","detail":"Description of `get_favicon_stats` changed (79% word delta).","severity":"risky","descriptionDelta":0.7857142857142857},{"kind":"description_changed","tool":"search_js_fingerprint_by_library","after":"Search JS fingerprints by detected library name. Use identifiers from get_js_library_inventory, such as 'react' or 'nextjs'. The display name 'Next.js' is accepted as an alias for 'nextjs'.","before":"Search JS fingerprints by library name.","detail":"Description of `search_js_fingerprint_by_library` changed (75% word delta).","severity":"risky","descriptionDelta":0.75},{"kind":"description_changed","tool":"search_js_fingerprint_patterns","after":"Search JS fingerprints by patterns. Supply at least one boolean filter: has_eval, has_crypto, has_websocket, high_entropy, no_library, or cdn_mismatch. For example, use has_eval=true. Explicit false is also a filter; limit alone is not a filter.","before":"Search JS fingerprints by patterns.","detail":"Description of `search_js_fingerprint_patterns` changed (83% word delta).","severity":"risky","descriptionDelta":0.8333333333333334},{"kind":"description_changed","tool":"search_js_malware_families","after":"Search JS malware families. Supply min_cluster_size (at least 1) or similarity_threshold (0 to 1), or both; limit alone is not a filter. For example, use min_cluster_size=2.","before":"Search JS malware families.","detail":"Description of `search_js_malware_families` changed (83% word delta).","severity":"risky","descriptionDelta":0.8333333333333334},{"kind":"description_changed","tool":"search_js_obfuscation","after":"Search JS obfuscation signals. Supply at least one of risk_level, min_risk_score, or has_eval; limit alone is not a filter. For example, use has_eval=true. Explicit false and a min_risk_score of 0 are valid filters.","before":"Search JS obfuscation signals.","detail":"Description of `search_js_obfuscation` changed (87% word delta).","severity":"risky","descriptionDelta":0.8666666666666667},{"kind":"description_changed","tool":"search_ocr","after":"Search OCR text (paginated). q must contain at least 3 characters after trimming. This query can take up to 90 seconds by default; allow it to finish before retrying.","before":"Search OCR text (paginated).","detail":"Description of `search_ocr` changed (86% word delta).","severity":"risky","descriptionDelta":0.8571428571428572},{"kind":"description_changed","tool":"submit_scan","after":"Submit a URL to ScanMalware for scanning. WARNING: scan_type defaults to 'public', which publishes the target URL and scan results in the public feed and makes them visible to other users and search engines. Choose visibility explicitly: 'public' publishes the scan; 'unlisted' keeps it out of public listings but anyone with the direct link can access it; 'private' restricts results to the authenticated ScanMalware account and requires this server's SCANMALWARE_BEARER_TOKEN to be configured. For client targets, confidential URLs, or security engagements, ask the user to choose 'unlisted' or 'private' unless they have already specified visibility; use 'public' only with explicit approval to publish. Never fall back to a less restrictive visibility if submission fails.","before":"Submit a URL for scanning.","detail":"Description of `submit_scan` changed (94% word delta).","severity":"risky","descriptionDelta":0.9382716049382716},{"kind":"enum_narrowed","path":"inputSchema.properties.scan_type","tool":"submit_scan","after":"enum[public,unlisted,private]","before":"open","detail":"`scan_type` on `submit_scan` narrowed to a closed enum (public, unlisted, private); previously valid values may now be rejected.","severity":"breaking"}],"published_at":"2026-10-02T13:54:16.564Z"},{"slug":"ZV-2026-1015","server_name":"mcp.scanmalware.com","severity":"breaking","title":"mcp.scanmalware.com: classification on search_ai_classification narrowed to a closed enum (LEGITIMATE, LOW_RISK, MODERATE_RISK, HIGH_RISK, CONFIRMED_SCAM); previously valid values may now be rejected.","summary":"[risky] Description of get_favicon changed (75% word delta). [risky] Description of get_netlog changed (82% word delta). [breaking] classification on search_ai_classification narrowed to a closed enum (LEGITIMATE, LOW_RISK, MODERATE_RISK, HIGH_RISK, CONFIRMED_SCAM); previously valid values may now be rejected. [breaking] hash_type on search_by_favicon narrowed to a closed enum (mmh3, md5); previously valid values may now be rejected. [breaking] hash_type on search_by_fuzzy_hash narrowed to a closed enum (tlsh, ssdeep, sdhash); previously valid values may now be rejected. [breaking] hash_type on search_by_screenshot_hash narrowed to a closed enum (ahash, phash, dhash, whash, color_hash, crop_resistant); previously valid values may now be rejected.","changes":[{"kind":"description_changed","tool":"get_favicon","after":"Get the favicon for a scan_id: size, hashes, and the image itself base64-encoded. Use the md5 with search_by_favicon to pivot.","before":"Get favicon metadata for a scan_id.","detail":"Description of `get_favicon` changed (75% word delta).","severity":"risky","descriptionDelta":0.75},{"kind":"description_changed","tool":"get_netlog","after":"Describe the network log (Chrome NetLog) for a scan_id: whether one exists, its size, and its encoding. The log itself is not returned - these are routinely tens of megabytes gzipped.","before":"Get network log for a scan_id.","detail":"Description of `get_netlog` changed (82% word delta).","severity":"risky","descriptionDelta":0.8214285714285714},{"kind":"enum_narrowed","path":"inputSchema.properties.classification","tool":"search_ai_classification","after":"enum[LEGITIMATE,LOW_RISK,MODERATE_RISK,HIGH_RISK,CONFIRMED_SCAM]","before":"open","detail":"`classification` on `search_ai_classification` narrowed to a closed enum (LEGITIMATE, LOW_RISK, MODERATE_RISK, HIGH_RISK, CONFIRMED_SCAM); previously valid values may now be rejected.","severity":"breaking"},{"kind":"enum_narrowed","path":"inputSchema.properties.hash_type","tool":"search_by_favicon","after":"enum[mmh3,md5]","before":"open","detail":"`hash_type` on `search_by_favicon` narrowed to a closed enum (mmh3, md5); previously valid values may now be rejected.","severity":"breaking"},{"kind":"enum_narrowed","path":"inputSchema.properties.hash_type","tool":"search_by_fuzzy_hash","after":"enum[tlsh,ssdeep,sdhash]","before":"open","detail":"`hash_type` on `search_by_fuzzy_hash` narrowed to a closed enum (tlsh, ssdeep, sdhash); previously valid values may now be rejected.","severity":"breaking"},{"kind":"enum_narrowed","path":"inputSchema.properties.hash_type","tool":"search_by_screenshot_hash","after":"enum[ahash,phash,dhash,whash,color_hash,crop_resistant]","before":"open","detail":"`hash_type` on `search_by_screenshot_hash` narrowed to a closed enum (ahash, phash, dhash, whash, color_hash, crop_resistant); previously valid values may now be rejected.","severity":"breaking"}],"published_at":"2026-09-13T04:52:20.041Z"}]