Atlas / MCP servers / neozi12 / dispatchseo

dispatchseoBLOCK

mcp/neozi12/dispatchseo

Turn your AI agent into your SEO manager - works today with Claude Code, Codex, and Cursor. The open-source alternative to SEObot and Outrank

Verdict
BLOCK
Grade
D
Trust score
65 /100
Exposed tools
75 53r · 22w · 0d
Transport
streamable-http
License
AGPL-3.0
Stars
81
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

DispatchSEO

Turn your AI agent into your SEO manager DispatchSEO: an open-source alternative to SEObot and Outrank.

Works today with Claude Code, Codex, and Cursor - all first-class, including the unattended overnight builder. Other SEO tools learn about your product by crawling your homepage. Your agent already knows it,so DispatchSEO gives that agent the missing half: keyword research, content that ships as pull requests, and rank tracking.

Read from source at commit 7b28d878a573OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add dispatchseo --env CRON_SECRET=${CRON_SECRET} --env CURSOR_TOKEN=${CURSOR_TOKEN} --env DASHBOARD_PASSWORD=${DASHBOARD_PASSWORD} --env DATAFORSEO_ENC_KEY=${DATAFORSEO_ENC_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "dispatchseo": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CRON_SECRET": "${CRON_SECRET}",
        "CURSOR_TOKEN": "${CURSOR_TOKEN}",
        "DASHBOARD_PASSWORD": "${DASHBOARD_PASSWORD}",
        "DATAFORSEO_ENC_KEY": "${DATAFORSEO_ENC_KEY}"
      }
    }
  }
}
03

Exposed tools (75)

53 read · 22 write · 0 destructive.

ToolRiskDescription
add_backlink_prospectwrite
approve_draftread
build_suggestion_nowread
check_samenessread
check_serpread
defer_setup_stepread
detect_site_launchread
discard_draftread
disconnect_reporead
expand_trend_topicread
get_activityread
get_ai_visibilityread
get_automationsread
get_backlink_prospectsread
get_briefingread
get_build_briefread
get_changelogread
get_content_prefsread
get_conventionsread
get_cron_healthread
get_dataforseo_usageread
get_domain_rankread
get_draftsread
get_feedbackread
get_instructionsread
get_next_actionsread
get_overviewread
get_pagesread
get_pipeline_packread
get_playbookread
get_projectread
get_rankingsread
get_research_notesread
get_setup_stepread
get_site_digestread
get_site_profileread
get_site_statsread
get_suggestionsread
get_trend_topicsread
join_waitlistread
keyword_ideasread
log_pageread
mark_cron_fixedread
mark_indexing_requestedread
mark_install_stepwrite
mark_pipeline_installedread
merge_prwrite
propose_suggestionread
propose_trend_topicread
record_ai_citationsread
record_trend_scanread
reorder_queueread
rescan_siteread
save_research_noteswrite
set_agentwrite
set_content_path_hintwrite
set_content_prefswrite
set_conventionswrite
set_github_repowrite
set_gsc_propertywrite
set_internal_linkingwrite
set_marketwrite
set_playbook_statuswrite
set_publish_targetwrite
set_site_profilewrite
submit_articlewrite
submit_feedbackwrite
suggest_keywordsread
track_keywordsread
trigger_trend_scanwrite
update_backlink_prospectwrite
update_feedbackwrite
update_suggestionwrite
update_trend_topicwrite
vote_feedbackread
04

Trust audit

BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (9 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/components/blog/container-boundary-split.tsx:27
"Processes, and the host's own ~/.ssh and cloud keys - unless you mount them",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/components/blog/container-credential-path-table.tsx:12
{ way: "Bind-mounting the host's ~/.ssh or cloud credential files", leaves: "The whole host key is reachable from the container", verdict: "Avoid - use a scoped token" },
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/lib/ai-visibility.ts
ai-visibility.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:33
CMD ["node", "-e", "fetch('http://127.0.0.1:3000/api/health').then(r=>process.exit(r.status===200?0:1)).catch(()=>process.exit(1))"]
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/app/api/onboarding/status/route.ts:47
const base = process.env.POSTGREST_URL ? "http://127.0.0.1:3000" : await backendBaseUrl();
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/lib/job-handlers/publish.ts:245
const resolved = `${process.env.POSTGREST_URL ? "http://127.0.0.1:3000" : await backendBaseUrl()}${url}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
start.sh:158
curl -s -o /dev/null --max-time 1 "http://127.0.0.1:$PORT" || rc=$?
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
.dispatchseo/generate-cover.mjs:235
.replace(/^/, "")
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/announce-changelog.mjs:244
name: "",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/lib/repo-publish.ts:251
if (i >= lines.length || lines[i].replace(/^/, "").trim() !== "---") return empty;
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
templates/pipeline/.dispatchseo/generate-cover.mjs:235
.replace(/^/, "")
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
src/content/docs/docker-compose.mdx:172
echo "CLAUDE_CODE_OAUTH_TOKEN=sk-ant-oat-PASTE-YOUR-TOKEN-HERE" >> .env ||
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/agent-golden.mjs:92
const TOKEN = "fixture-token-do-not-use";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.docker.example
.env.docker.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.local.example
.env.local.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/seo-auto-merge.yml:102
http://localhost*|http://127.*|http://0.0.0.0*|http://10.*|http://192.168.*|http://172.1[6-9].*|http://172.2[0-9].*|http://172.3[0-1].*)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@polar-sh/sdk, @sentry/nextjs, @supabase/ssr, @supabase/supabase-js, @tailwindcss/postcss, @vercel/analytics, googleapis, gray-matter
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
LATER.md:55
porting this needs the report endpoint to accept project-token auth (scoped to a
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/content/blog/claude-code-auto-compact.mdx:15
Search for this and the second result is usually Anthropic's own [compaction overview](https://platform.claude.com/docs/en/build-with-claude/compaction) - and it's about a different product. That page
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/content/blog/claude-code-headless-mode.mdx:67
That's the literal branch logic in `seo-daily.yml`'s own "Classify the outcome" step, which runs after `claude-code-action` with `continue-on-error: true` so this step is reachable either way. It read
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/content/blog/claude-code-routines-vs-cron.mdx:15
A routine is a saved configuration, not a background process you manage: a prompt, the repositories Claude works in, an environment, and a set of MCP connectors, packaged once at [claude.ai/code/routi
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/content/blog/claude-code-subagents.mdx:43
Step three is the one a one-off session never needs and an unattended one can't skip. Without it, two cold starts on the same morning - a retry, a manually re-triggered workflow, an overlapping schedu
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
SECURITY.md:74
- Treat your secrets as equal-weight full access to their surface. On a
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
src/content/docs/security.mdx:171
Treat all six as equal-weight, full access to their surface - none of
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
src/content/blog/claude-code-environment-variables.mdx:95
**Does Claude Code read a project's `.env` file automatically?**
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7b28d878a573full audit observations/trust-audit/mcp-server/neozi12__dispatchseo.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087b28d878a573BLOCKD65first audit
06

Questions

What is the dispatchseo MCP server?

Turn your AI agent into your SEO manager - works today with Claude Code, Codex, and Cursor. The open-source alternative to SEObot and Outrank

What tools does dispatchseo expose?

75 in total: 53 read-only, 22 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is dispatchseo safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does dispatchseo need?

It reads CRON_SECRET, CURSOR_TOKEN, DASHBOARD_PASSWORD, DATAFORSEO_ENC_KEY, DATAFORSEO_PASSWORD, DATAFORSEO_PLATFORM_PASSWORD, DISPATCHSEO_TOKEN, GH_MERGE_TOKEN, GH_MERGE_TOKEN_PROJECTS, GITHUB_APP_CLIENT_SECRET, GITHUB_APP_PRIVATE_KEY and GITHUB_APP_WEBHOOK_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does dispatchseo run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as dispatchseo at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (7b28d878a573), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement