Atlas / MCP servers / akzar1el / mcp-geo

mcp-geoSAFE

mcp/akzar1el/mcp-geo

Track brand citations across seven AI search surfaces. Free OSS/self-host; optional EUR 99 client-ready audit.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
7 5r · 2w · 0d
Transport
stdio
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/AKzar1el/mcp-geo/actions/workflows/ci.yml) [](https://www.npmjs.com/package/@digestseo/mcp-geo) [](https://registry.modelcontextprotocol.io/v0.1/servers?search=io.github.AKzar1el/mcp-geo) [](./LICENSE) [](https://www.typescriptlang.org/) [](https://workers.cloudflare.com/) [](https://modelcontextprotocol.io/) [](https://glama.ai/mcp/servers/AKzar1el/mcp-geo) [](https://wellknown.network/agents/geo-tracker-by-digestseo) [](https://github.com/AKzar1el/mcp-geo/stargazers) [](https://geo-mcp.digestseo.com/audit)

Quick Install

Runs locally over stdio with your own API keys — all data stays on your machine (see Privacy Policy). Set at least one engine key (OPENAI_API_KEY, ANTHROPIC_API_KEY, GEMINI_API_KEY, PERPLEXITY_API_KEY, XAI_API_KEY, SERPAPI_API_KEY); engines without a key skip gracefully.

Runtime: Node.js 22.13+ (CI exercises Node 22 and 24).

Claude Desktop / any MCP client (npx):

{
"mcpServers": {
"digestseo": {
"command": "npx"
Read from source at commit 938c4490fff4OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-geo --env OPENAI_API_KEY=${OPENAI_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env PERPLEXITY_API_KEY=${PERPLEXITY_API_KEY} -- npx -y @digestseo/[email protected]
03

Exposed tools (7)

5 read · 2 write · 0 destructive.

ToolRiskDescription
digestseo-mcpreadTrack brand citations across seven AI search surfaces. Free OSS; optional EUR 99 client-ready audit.
generate_promptsread
list_brandsread
list_promptsread
set_promptswrite
track_brandread
update_brandwrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.dev.vars.example
.dev.vars.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/db/sqlite.ts:57
return fileURLToPath(new URL('../../migrations/', import.meta.url));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/admin-set-prompts.test.ts:7
} from '../../src/core/admin-prompt-set.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/admin-set-prompts.test.ts:8
import type { Brand, Db, NewPromptInput, Prompt } from '../../src/db/types.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/ai-mode.test.ts:3
import { chatCompletion, MODEL, runLive } from '../../src/core/ai-mode.ts';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/ai-mode.test.ts:4
import type { Brand, Db, EnginePromptResult, Prompt } from '../../src/db/types.ts';
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:389
[![Add to Cursor](https://cursor.com/deeplink/mcp-install-dark.svg)](https://cursor.com/en/install-mcp?name=digestseo&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBkaWdlc3RzZW8vbWNwLWdlbyJdLCJlbnY
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/unit/ai-mode.test.ts:1
import { test } from 'node:test';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @cloudflare/workers-oauth-provider, @cloudflare/workers-types, @modelcontextprotocol/client, @types/node, agents, tsx
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CODE_OF_CONDUCT.md:50
To report a possible violation, use the private email contact published on the [DigestSEO contact page](https://digestseo.com/contact/). Use the subject **`mcp-geo Code of Conduct report`** and includ
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:483
The report above was generated by Claude through the digestseo-mcp MCP server. The conversation chained five hosted tools — `visibility.check`, `visibility.compare`, `visibility.citations` (Perplexity
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
docs/demo-report-full.png
docs/demo-report-full.png
Why it matters. 2525560 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 938c4490fff4full audit observations/trust-audit/mcp-server/akzar1el__mcp-geo.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08938c4490fff4SAFEB89first audit
06

Questions

What is the mcp-geo MCP server?

Track brand citations across seven AI search surfaces. Free OSS/self-host; optional EUR 99 client-ready audit.

What tools does mcp-geo expose?

7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is mcp-geo safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does mcp-geo need?

It reads ANTHROPIC_API_KEY, GEMINI_API_KEY, MCP_ACCESS_TOKEN, OPENAI_API_KEY, PERPLEXITY_API_KEY, SEED_SECRET, SERPAPI_API_KEY and XAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does mcp-geo run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @digestseo/mcp-geo at 0.3.26.

How current is this page?

The grade is for one exact copy of the source (938c4490fff4), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement