Atlas / MCP servers / adityaarsharma / LibreCrawl Technical SEO Audit

LibreCrawl Technical SEO AuditSAFE

mcp/adityaarsharma/librecrawl-technical-seo-audit

Sitewalk: Technical SEO Site Audit. Open-source technical SEO crawler and MCP server for Claude, Cursor and Codex. 50+ checks, PDF and CSV reports, self-hosted. Built on LibreCrawl. MIT.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
37 30r · 4w · 3d
Transport
streamable-http
License
MIT
Stars
42
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Repository: `librecrawl-technical-seo-audit-mcp` · the open-source Sitewalk engine and MCP server · [Hosted Sitewalk → audit.adityaarsharma.com](https://audit.adityaarsharma.com/) (ChatGPT plugin coming soon)

[](https://mcptoplist.com/server/pulsemcp%2Fadityaarsharma-librecrawl-seo)

The AI-native technical SEO crawler.

Run a complete on-site SEO audit on any website — straight from Claude, Cursor, Codex, or any Model Context Protocol (MCP) client. Unlimited pages · 50+ checks · PDF + CSVs · MIT-licensed · self-hosted · ephemeral by design.

Built on the open-source **LibreCrawl** engine, exposed through 38 MCP tools your AI assistant calls directly.

[](LICENSE) [](https://modelcontextprotocol.io) [](https://python.org) [](https://github.com/adityaarsharma/librecrawl-technical-seo-audit-mcp/releases) [](https://github.com/adityaarsharma/librecrawl-technical-seo-audit-mcp/stargazers) [](https://github.com/PhialsBasement/LibreCrawl)

[![Works With](https://img.shields.io/badge/Claude%20Code-suppor

Read from source at commit c187b482dfb7OBSERVED · 2026-10-08
02

Exposed tools (37)

30 read · 4 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
librecrawl_append_gsc_sectionread
librecrawl_auditread
librecrawl_audit_artifactsread
librecrawl_audit_cancelwriteTerminal stop. Upstream crawl is stopped; partial artifacts are kept where written.
librecrawl_audit_confirm_savedread
librecrawl_audit_force_advancedestructive
librecrawl_audit_pausereadPause a crawling session. Resume with librecrawl_audit_resume().
librecrawl_audit_pdfread
librecrawl_audit_resumereadResume a paused or throttled session. Runner picks it back up on the next loop.
librecrawl_audit_statusread
librecrawl_audit_zipread
librecrawl_brain_purge_auditdestructive
librecrawl_export_resultsread
librecrawl_external_links_auditread
librecrawl_filter_issuesread
librecrawl_full_audit_strictread
librecrawl_generate_reportread
librecrawl_get_settingsread
librecrawl_get_statusread
librecrawl_internal_links_analysisread
librecrawl_list_crawlsreadList all saved crawls with URL, crawl_id, and timestamp.
librecrawl_merge_gsc_datawrite
librecrawl_pagespeedread
librecrawl_pagespeed_auditread
librecrawl_pagespeed_audit_all_crawl_pagesread
librecrawl_pause_crawlreadPause the currently running crawl. Resume with librecrawl_resume_crawl().
librecrawl_report_contentread
librecrawl_resume_crawlreadResume a paused crawl in the current session.
librecrawl_resume_from_crawl_idread
librecrawl_schema_auditread
librecrawl_schema_checkread
librecrawl_schema_validateread
librecrawl_site_checkread
librecrawl_start_crawlwrite
librecrawl_stop_crawlwriteStop the currently running crawl.
librecrawl_visualization_dataread
librecrawl_wipe_everythingdestructive
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
librecrawl_audit_force_advance, librecrawl_brain_purge_audit, librecrawl_wipe_everything
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_server_logic.py:41
("ftp://evil/../../x", "evil"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_server_logic.py:44
("../../etc/passwd", "unknown"),
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/test_server_logic.py:116
r = getattr(server, fn)("http://169.254.169.254/")
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/test_url_guard.py:42
"http://169.254.169.254/latest/meta-data/",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/test_url_guard.py:80
url_guard._hook(httpx.Request("GET", "http://169.254.169.254/"))
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:163
docker compose up --build          # MCP at http://127.0.0.1:5081/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:175
"args": ["-y", "mcp-remote", "http://127.0.0.1:5081/mcp"]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:191
LIBRECRAWL_URL=http://127.0.0.1:5080 python server.py
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:201
"args": ["-y", "mcp-remote", "http://127.0.0.1:5081/mcp"]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:445
| `LIBRECRAWL_URL` | `http://127.0.0.1:5080` | Full base URL of the LibreCrawl backend (Docker sets `http://librecrawl:5000`) |
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_server_logic.py:208
local_sha = hashlib.sha256(base64.b64decode(z["content_base64"])).hexdigest()
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, httpx, uvicorn, weasyprint, markdown
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:137
curl -fsSL https://raw.githubusercontent.com/adityaarsharma/librecrawl-technical-seo-audit-mcp/main/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/GETTING-STARTED.md:24
curl -fsSL https://raw.githubusercontent.com/adityaarsharma/librecrawl-technical-seo-audit-mcp/main/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c187b482dfb7full audit observations/trust-audit/mcp-server/adityaarsharma__librecrawl-technical-seo-audit.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c187b482dfb7SAFEB89first audit
05

Questions

What is the LibreCrawl Technical SEO Audit MCP server?

Sitewalk: Technical SEO Site Audit. Open-source technical SEO crawler and MCP server for Claude, Cursor and Codex. 50+ checks, PDF and CSV reports, self-hosted. Built on LibreCrawl. MIT.

What tools does LibreCrawl Technical SEO Audit expose?

37 in total: 30 read-only, 4 that write, and 3 that can delete or overwrite (librecrawl_audit_force_advance, librecrawl_brain_purge_audit, librecrawl_wipe_everything). Every one is listed on this page with its risk.

Is LibreCrawl Technical SEO Audit safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does LibreCrawl Technical SEO Audit need?

It reads PAGESPEED_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does LibreCrawl Technical SEO Audit run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (c187b482dfb7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement