Atlas / MCP servers / houtini-ai / seo-audit

seo-auditSAFE

mcp/houtini-ai/seo-audit

Free SEO Audit MCP server for Claude - captures and stores all the raw data you need for a complete technical SEO audit. Google Search Console + a first-party crawl + DataForSEO + Majestic SEO merged into one prioritised audit.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
49 44r · 5w · 0d
Transport
stdio
License
Apache-2.0
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A technical SEO audit you can hold a conversation with - built from your own Search Console data and a live crawl of your site, run inside Claude.

[](https://www.npmjs.com/package/@houtini/seo-audit-console) [](./LICENSE) [](https://modelcontextprotocol.io) [](https://nodejs.org)

Almost every technical SEO audit I've been handed in twenty years is a crawler's opinion, and a crawler only ever sees half the picture. It tells you what your site says. It has nothing to say about what Google did about it: which queries you rank for, which pages earn the impressions, where the clicks land.

This one brings the other half. SEO Audit Console runs inside Claude, pulls your Google Search Console history, crawls your site properly, and joins the two so every finding carries the traffic at stake. Ninety-nine checks, ranked by the clicks the fix could recover rather than how alarming the check sounds, and it writes the fix for you: the 301 rule, the JSON-LD, the internal links. The core audit needs nothing but your own Search Console; DataForSEO and Majestic slot in later, when your questions grow into competitors and link building. Your data stays on your machine.

Built by [Houtini](https://houtini.com). We build automation for the grunt work of digital marketing - the data collection, the crawling, the merging, the checking - so your t

Read from source at commit fd3d3cdb96c4OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add seo-audit-console --env DATAFORSEO_PASSWORD=${DATAFORSEO_PASSWORD} --env FIRECRAWL_API_KEY=${FIRECRAWL_API_KEY} --env SUPADATA_API_KEY=${SUPADATA_API_KEY} --env MAJESTIC_API_KEY=${MAJESTIC_API_KEY} -- npx -y @houtini/[email protected]
03

Exposed tools (49)

44 read · 5 write · 0 destructive.

ToolRiskDescription
check_agent_readinessread
check_crawl_statusread
check_sync_statuswrite
competitors_domainread
composition_cookbookread
content_opportunitiesread
data_locationread
data_storageread
detect_changesread
domain_visibilityread
draft_contentread
export_reportread
fix_findingread
inspect_urlsread
keyword_listread
keyword_volumeread
link_intersectread
list_checksread
list_propertiesread
list_templatesread
market_sizingread
news_discoveryread
normalize_urlread
page_intersectionread
page_lighthouseread
pull_backlinksread
query_auditread
query_dataread
ranked_keywordsread
recon_targetsread
recon_todosread
related_termsread
resolve_entitiesread
run_auditwrite
save_recon_todowrite
score_passagesread
search_intentread
seo_audit_helpread
serp_featuresread
serve_dashboardread
start_crawlwrite
suggest_pagesread
sync_gscwrite
top_pagesread
topic_gapsread
topic_trendread
track_ranksread
trend_categoriesread
youtube_discoveryread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMInventory / provenance · inv.binary · CWE-1104
src/core/paths.ts
paths.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/probe-drift-fixes.mjs:103
ok(!sanitizeProperty('https://evil.com/../../etc/passwd').includes('/'), 'path separators never survive the stem');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@fontsource-variable/rubik, @fontsource-variable/work-sans, @huggingface/transformers, @modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, better-sqlite3, cheerio, echarts
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha fd3d3cdb96c4full audit observations/trust-audit/mcp-server/houtini-ai__seo-audit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08fd3d3cdb96c4SAFEB89first audit
06

Questions

What is the seo-audit MCP server?

Free SEO Audit MCP server for Claude - captures and stores all the raw data you need for a complete technical SEO audit. Google Search Console + a first-party crawl + DataForSEO + Majestic SEO merged into one prioritised audit.

What tools does seo-audit expose?

49 in total: 44 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is seo-audit safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does seo-audit need?

It reads DATAFORSEO_PASSWORD, FIRECRAWL_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, MAJESTIC_API_KEY and SUPADATA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does seo-audit run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @houtini/seo-audit-console at 0.12.1.

How current is this page?

The grade is for one exact copy of the source (fd3d3cdb96c4), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement