Access ScanBIM's AI-powered AEC platform supporting real-time BIM model viewing, conversion, and analysis across Revit, Navisworks, ACC, and 50+ 3D formats via Autodesk Platform Services.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The scanbim-mcp MCP server exposes 19 tools, focused primarily on AI capabilities. Its published description reads: "Access ScanBIM's AI-powered AEC platform supporting real-time BIM model viewing, conversion, and analysis across Revit, Navisworks, ACC, and 50+ 3D formats via Autodesk Platform S…". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates scanbim-mcp F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Data-exfiltration parameters" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check scanbim-mcp's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add scanbim-mcp to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://scanbim-mcp.itmartin24.workers.dev/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Ingest a 3D model from a public URL into APS OSS and kick off a Model Derivative translation job, returning the URN plus a browser viewer link and QR code. Supports 50+ formats: Revit (.rvt/.rfa), Nav
Run a first-pass bounding-box clash check between two element categories in a translated model. Element boxes are read from the APS Model Derivative properties endpoint; ScanBIM never estimates or syn
Return a shareable browser URL for the embedded APS viewer and a matching QR code for mobile/XR handoff. Does not require the model to be fully translated — the viewer page will poll the manifest. Whe
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: upload_model
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: upload_model
A tool description tries to alter the model’s use of another tool.
uploaded; call get_model_metadata instead. APS scopes: data:read data:write data:RecommendationDescriptions must describe only their own tool.
tool: detect_clashes
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: detect_clashes
A tool description tries to alter the model’s use of another tool.
ating yet (call get_model_metadata first to confirm manifest.status=='success'), oRecommendationDescriptions must describe only their own tool.
tool: get_viewer_link
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
erver-side via /token. Rate limits: APS default ~50 req/min per app pRecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_viewer_link
A tool description tries to alter the model’s use of another tool.
progress — call get_model_metadata. APS scopes: none (URL assembly only); the viewRecommendationDescriptions must describe only their own tool.
tool: list_models
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: list_models
A tool description tries to alter the model’s use of another tool.
xact URN — call get_model_metadata directly. This tool is not a search; it returnsRecommendationDescriptions must describe only their own tool.
tool: get_model_metadata
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_model_metadata
A tool description tries to alter the model’s use of another tool.
se: right after upload_model to poll translation progress, or later to inspeRecommendationDescriptions must describe only their own tool.
tool: get_supported_formats
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh (not applicable: no ARecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_supported_formats
A tool description tries to alter the model’s use of another tool.
before calling upload_model, or to surface pricing tier info. When to use:RecommendationDescriptions must describe only their own tool.
tool: acc_list_projects
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: acc_list_projects
A tool description tries to alter the model’s use of another tool.
id to pass into acc_create_issue, acc_list_issues, acc_create_rfi, acc_list_rfisRecommendationDescriptions must describe only their own tool.
tool: acc_create_issue
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: acc_create_issue
A tool description tries to alter the model’s use of another tool.
h. When to use: detect_clashes flagged a critical clash, or a field user reporRecommendationDescriptions must describe only their own tool.
tool: acc_create_rfi
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: acc_create_rfi
A tool description tries to alter the model’s use of another tool.
hlist fix — use acc_create_issue. The question is internal to one trade — handleRecommendationDescriptions must describe only their own tool.
tool: acc_list_issues
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: acc_list_issues
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
shboard view of open issues, to find a specific issue by metadata, or to check the status of previousRecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: acc_list_rfis
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: acc_search_documents
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
y. You want the file contents — this returns metadata; download separately viRecommendationRemove side-channel parameters; constrain tool inputs.
tool: acc_project_summary
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh; 403 scope or resourcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: acc_project_summary
A tool description tries to alter the model’s use of another tool.
projects — call acc_list_projects. You want issues/RFIs counts — call the list toRecommendationDescriptions must describe only their own tool.
tool: xr_launch_vr_session
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh (only at viewer pageRecommendationRemove side-channel parameters; constrain tool inputs.
tool: xr_launch_vr_session
A tool description tries to alter the model’s use of another tool.
h_ar_session or get_viewer_link. The model has not finished translating — callRecommendationDescriptions must describe only their own tool.
tool: xr_launch_vr_session
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
ables:read data:read (enforced at viewer page load, not at tool call). Rate limits: APS defauRecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: xr_launch_ar_session
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh (only at viewer pageRecommendationRemove side-channel parameters; constrain tool inputs.
tool: xr_launch_ar_session
A tool description tries to alter the model’s use of another tool.
browser) — use get_viewer_link. APS scopes: viewables:read data:read (enforcedRecommendationDescriptions must describe only their own tool.
tool: xr_launch_ar_session
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
ables:read data:read (enforced at viewer page load, not at tool call). Rate limits: APS defauRecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: xr_list_sessions
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh (not applicable: no ARecommendationRemove side-channel parameters; constrain tool inputs.
tool: xr_list_sessions
A tool description tries to alter the model’s use of another tool.
ns launched via xr_launch_vr_session and xr_launch_ar_session, sorted by creation tiRecommendationDescriptions must describe only their own tool.
tool: twinmotion_render
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh (will apply when pipeRecommendationRemove side-channel parameters; constrain tool inputs.
tool: twinmotion_render
A tool description tries to alter the model’s use of another tool.
rendering — use get_viewer_link. You need a moving camera — use twinmotion_walkRecommendationDescriptions must describe only their own tool.
tool: twinmotion_walkthrough
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh (will apply when pipeRecommendationRemove side-channel parameters; constrain tool inputs.
tool: twinmotion_walkthrough
A tool description tries to alter the model’s use of another tool.
ractivity — use get_viewer_link. You want a still image — use twinmotion_renderRecommendationDescriptions must describe only their own tool.
tool: lumion_render
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Errors: 401 APS token expired/invalid — refresh (will apply when pipeRecommendationRemove side-channel parameters; constrain tool inputs.
tool: lumion_render
A tool description tries to alter the model’s use of another tool.
e viewing — use get_viewer_link. You need video — use twinmotion_walkthrough. ARecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
The tool surface changed after prior observation — the rug-pull signal. Flagged for review, not proof of malice.
RecommendationRe-review the server; pin trusted tool descriptions (TOFU).
tool: upload_model
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "upload_model"RecommendationScope tools to the minimum needed.
tool: detect_clashes
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "detect_clashes"RecommendationScope tools to the minimum needed.
tool: get_viewer_link
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "get_viewer_link"RecommendationScope tools to the minimum needed.
tool: list_models
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "list_models"RecommendationScope tools to the minimum needed.
tool: get_model_metadata
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "get_model_metadata"RecommendationScope tools to the minimum needed.
tool: get_supported_formats
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "get_supported_formats"RecommendationScope tools to the minimum needed.
tool: acc_list_projects
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "acc_list_projects"RecommendationScope tools to the minimum needed.
tool: acc_create_issue
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "acc_create_issue"RecommendationScope tools to the minimum needed.
tool: acc_create_rfi
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "acc_create_rfi"RecommendationScope tools to the minimum needed.
tool: acc_list_issues
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "acc_list_issues"RecommendationScope tools to the minimum needed.
tool: acc_list_rfis
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "acc_list_rfis"RecommendationScope tools to the minimum needed.
tool: acc_search_documents
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "acc_search_documents"RecommendationScope tools to the minimum needed.
tool: acc_project_summary
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "acc_project_summary"RecommendationScope tools to the minimum needed.
tool: xr_launch_vr_session
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "xr_launch_vr_session"RecommendationScope tools to the minimum needed.
tool: xr_launch_ar_session
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "xr_launch_ar_session"RecommendationScope tools to the minimum needed.
tool: xr_list_sessions
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "xr_list_sessions"RecommendationScope tools to the minimum needed.
tool: twinmotion_render
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "twinmotion_render"RecommendationScope tools to the minimum needed.
tool: twinmotion_walkthrough
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "twinmotion_walkthrough"RecommendationScope tools to the minimum needed.
tool: lumion_render
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "lumion_render"RecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
List every object currently stored in the scanbim-models OSS bucket, with URN, size in MB, and a viewer URL for each. Returns the raw OSS inventory, not the D1 models table, so freshly uploaded items
Fetch the APS Model Derivative manifest and metadata for a URN, including translation progress, derivative outputs, and a viewer URL. Use this to confirm a model has finished translating (manifest.sta
Return the full matrix of supported input formats organized by subscription tier (free / pro / enterprise). Use to tell a user whether their file type is accepted before calling upload_model, or to su
List every Autodesk Construction Cloud (ACC) / BIM 360 project the configured APS 2-legged app has access to, flattened across all hubs, with hub_id, hub_name, project_id, project_name, and project ty
Create a real issue (punchlist/QC item) in ACC Build's Issues module via the APS Construction Issues v1 API. Returns the ACC-generated issue_id which can be linked back to a model URN or a detected cl
Create a Request For Information in ACC Build's RFIs module via the APS Construction RFIs v1 API, in 'draft' status. Returns the ACC rfi_id. When to use: a trade or subcontractor needs formal informat
List up to 50 issues from an ACC project, optionally filtered by status and priority. Returns a normalized array of {id, title, status, priority, due_date}. When to use: you need a dashboard view of o
List up to 50 RFIs from an ACC project, optionally filtered by status. Returns a normalized array of {id, subject, status}. When to use: you need a quick rollup of outstanding or answered RFIs on a pr
Full-text search the ACC Docs module on a project for drawings, specs, submittals, and other documents matching a query string. Calls the APS Data Management v1 search endpoint scoped to a project. Wh
Fetch a single ACC/BIM 360 project's full attributes (name, type, dates, address, hub) from the APS Data Management project endpoint. If hub_id is omitted, the first hub the app can see is used. When
Create a shareable WebXR VR walkthrough session URL (and Meta Quest oculus:// deep link + QR code) for a translated model. The session_id is generated server-side; rendering happens in the user's Ques
Create a shareable WebXR AR passthrough session URL and QR code. On phone or tablet with WebXR AR support, the model is overlaid on the camera feed at the requested scale. When to use: a field user ne
List the last 20 VR/AR sessions launched via xr_launch_vr_session and xr_launch_ar_session, sorted by creation time desc. Sourced from the D1 usage_log table; returns an empty array if D1 is unavailab
Queue a photorealistic Twinmotion-style still render of a translated model with time-of-day, weather, season, and resolution controls. Returns a render_id and preview_url; the actual render pipeline i
Queue a cinematic Twinmotion-style fly-through video of a translated model. Returns a video_id and download_url; the render pipeline is a ScanBIM roadmap item so today this tool responds synchronously
Queue a Lumion-style architectural visualization still render with landscaping, people, vehicles, and atmospheric effects. Returns a render_id and preview_url; the render pipeline is a ScanBIM roadmap