CertScore.ai MCP Light
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
- 0.2.20
- Version
- remote
- Transport
- 4
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 4 tools scanned
- metadata: scanned
No findings.
Tools (4)
certscore_scan_site
Use for a user-requested website launch review, vendor assessment, cookie/tracker inventory, consent/GPC investigation or privacy-policy review. A public URL or domain is enough. Creates a privacy scan or reuses an eligible recent completed scan; default freshness=latest saves new-scan quota. Use refresh only for an explicitly requested fresh scan or post-fix recheck. Retain scanId, poll certscore_get_scan_status only while active at retryAfterSeconds, then read certscore_get_scan_bundle. A preliminary preConsentPreview is not final findings or totals. Coverage includes pre-consent storage, trackers, consent and CMP signals, privacy-policy disclosures, transport security and GDPR/ePrivacy or CCPA/CPRA review signals. Results are automated observations, not legal advice, certification, or a compliance determination. https://certscore.ai/developers/mcp.
certscore_get_scan_status
Returns lifecycle status for a stable CertScore scanId. Active responses include phase, heartbeat, estimated progress, retryAfterSeconds, and sometimes a bounded preliminary preConsentPreview. Terminal responses include completion status, CertScore score and risk metadata when available, coverage, persisted execution region and timestamps, report URL, and a next-action field. Preliminary observations are distinct from completed findings.
certscore_get_report_evidence_page
For a focused question, use section=consent, gpc, policy, tracking, transport or forms. This returns selected retained report sections plus shared scan, score, findings and coverage context. Preserve section on cursor continuation; unselected or not-returned fields are not evidence of absence. Use workpaper=tracking separately for the starting-page tracking inventory, privacy choices/notices and GPC evidence, with JSON and CSV downloads. Never combine section and workpaper. The workpaper selector also applies to every continuation request. Otherwise retrieve scan report display content as paginated JSON, without internal diagnostic JSON downloads. The response also offers a single-file full JSON download; private JSON download links expire after five minutes and need no OAuth header; use pagination if your host blocks file downloads. Repeated display records use reportContentRef JSON Pointers. Includes evidence tables, full-site page and resource inventories, all retained additional-pa
certscore_get_scan_bundle
Main answer for a completed or completed-limited scan: canonical findings, next steps, supporting evidence, score, date/region, coverage and report URL. An existing scanId is enough; no new scan is created. The evidence index describes response delivery, never evidence absence. Optional next actions lead to deeper report tables, tracking workpapers and JSON/CSV exports. Use detail=evidence for request examples and policy candidates, including scans with no findings; detail=full adds bounded retained context. Preserve returned/total counts and omission metadata. Accept/Reject execution succeeded means a completed click and bounded observation; succeeded_with_confirmation additionally verifies the consent decision. Retained after-click facts remain distinct from registered decisions. Absent or failed capture remains explicitly limited. Use canonical findings for scoring effects. A later missing finding does not prove a fix. Results are automated public-web observations, not legal advice,