MacroCyber
Scan a site or AI-built app for exposed databases, keys and MCP endpoints, then verify the fixes.
Hosted MCP Server
npx add-mcp 'https://macrocyber.co/api/mcp'Installs into Claude Code, Codex, Cursor and more
Documentation
Every finding is something the domain actually said.
Find open databases, leaked AI keys, exposed MCP servers and AI runtimes, and forgotten hosts. Each finding records what the scanner observed (the response, header, certificate or DNS record behind it), its priority, and a concrete fix. Confirmed observations and heuristic checks are clearly distinguished.
Scope. The public scan looks for what AI-built apps tend to leak: Supabase and Firebase data a logged-out visitor can read, AI provider keys in the served code, and MCP servers, agent endpoints and AI runtimes that answer without authentication. Alongside those it checks DNS and email authentication, TLS, response headers, cookies, public pages, and the hosts discovered around the domain. It does not test injection, account permissions, or business logic. A finding identifies an observable exposure, not proof that someone has exploited it. Review the evidence before applying a fix. If a host blocks the scanner, the report marks its coverage as partial: unseen application behavior remains unassessed.
AI-era exposures and leaks
18 checks
Open Supabase and Firebase databases, AI and cloud keys in client code or served files, and MCP servers, agent gateways and model runtimes that answer without a login. Then everything else the deploy hands out: source and backups, debug and dev servers, open buckets, and the stack it runs on.