Screaming Frog SEO SpiderBLOCK
Headless MCP server for Screaming Frog SEO Spider – run crawls, export and analyze crawl data via the CLI. Small locked-down tool surface for scheduled audits, CI, and unattended AI agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A headless MCP (Model Context Protocol) server for Screaming Frog SEO Spider. It drives the SF command line and saved crawl database directly, so Claude (or any MCP-compatible client) can run crawls, export crawl data, and analyze the results with the Screaming Frog GUI closed: on your laptop, on a server, or inside scheduled audits and CI pipelines.
This is a community project, not affiliated with Screaming Frog. Since SEO Spider v24 there is also an official MCP built into the app. The two work differently and solve different problems.
How this differs from the official Screaming Frog MCP
Screaming Frog shipped an official MCP server in SEO Spider v24. It's substantial: around 29 tools covering crawl control (start, pause, resume, progress), reports and bulk exports with field selection, URL-level inspection, screenshots, embeddings exports, and optionally a Node.js script runner with npm and filesystem read/write tools. It runs in two modes, either a Streamable HTTP server inside the open app, or a STDIO mode where the MCP client launches the Spider itself, headless. Setup is documented for Claude Desktop and LM Studio.
If you want maximum capability in an interactive session (visualizations, crawl comparison, screenshots, scripted post-processing of exports), use the official MCP. It does far more, and it's maintained by the vendor.
This server makes a different trade: it's a small, deliberately limited wrapper around SF's CLI and the saved crawl database, built for runs where nobody is watching.
Locked-down by design. Nine read-and-export tools, nothing else. No script runner, no npm install, no filesystem write access. The official MCP offers all three, and its own docs note that enabling the Node runtime "allows
dcb188666b19OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add screaming-frog-mcp -- None screaming-frog-mcp==0.4.1
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
"metadata.google.internal",
"169.254.169.254",
assert _path_is_contained(Path("/etc/passwd"), tmp_path) is False("http://169.254.169.254/", "link-local / cloud metadata"),("http://metadata.google.internal/", "GCP metadata"),("http://127.0.0.1/", "loopback IPv4"),("http://10.0.0.1/", "private IPv4 class A"),("http://192.168.1.1/", "private IPv4 class C"),("http://172.16.0.1/", "private IPv4 class B"),("http://169.254.169.254/", "link-local / cloud metadata"),mcp, python-dotenv
Gates applied: no_behavioural_pass.
dcb188666b19full audit observations/trust-audit/mcp-server/bzsasson__screaming-frog-seo-spider.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | dcb188666b19 | BLOCK | D | 69 | first audit |
Questions
What is the Screaming Frog SEO Spider MCP server?
Headless MCP server for Screaming Frog SEO Spider – run crawls, export and analyze crawl data via the CLI. Small locked-down tool surface for scheduled audits, CI, and unattended AI agents.
Is Screaming Frog SEO Spider safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Screaming Frog SEO Spider need?
No credential environment variables were found in its source, so it appears to need none.
How does Screaming Frog SEO Spider run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as screaming-frog-mcp.
How current is this page?
The grade is for one exact copy of the source (dcb188666b19), read on 2026-10-07. The repository is watched and re-audited when it changes.