Skip to content

Gemini CLI ScanLabsAI Security Scanner lookup_cves

How to: Gemini CLI ScanLabsAI Security Scanner lookup_cves

client:Gemini CLI transport:streamable-http tool:lookup_cves

Add ScanLabsAI Security Scanner to Gemini CLI

  1. 01

    Open ~/.gemini/settings.json and merge this in. Keep any servers already there.

{
  "mcpServers": {
    "scanner": {
      "httpUrl": "https://scanlabsai.com/api/mcp"
    }
  }
}
  1. 02

    Save the file and restart Gemini CLI.

  2. 03

    Ask for something lookup_cves does. Gemini CLI lists the server's tools on connect and calls lookup_cves itself — you do not invoke it by name.

  3. 04

    If nothing happens, check the server is running and that ScanLabsAI Security Scanner's identifier in your config matches the one above exactly.

Gemini expands $VAR and ${VAR} inside env values, so a secret can live in your shell rather than this file. Gemini CLI docs

Set these first

ScanLabsAI Security Scanner will not start until these are set, so lookup_cves never becomes available.

  • SCANLABS_API_KEY

Same tool, other clients

This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what the server actually exposes, not what its listing claims.

Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.