dispatchseoBLOCK
Turn your AI agent into your SEO manager - works today with Claude Code, Codex, and Cursor. The open-source alternative to SEObot and Outrank
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
DispatchSEO
Turn your AI agent into your SEO manager DispatchSEO: an open-source alternative to SEObot and Outrank.
Works today with Claude Code, Codex, and Cursor - all first-class, including the unattended overnight builder. Other SEO tools learn about your product by crawling your homepage. Your agent already knows it,so DispatchSEO gives that agent the missing half: keyword research, content that ships as pull requests, and rank tracking.
7b28d878a573OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add dispatchseo --env CRON_SECRET=${CRON_SECRET} --env CURSOR_TOKEN=${CURSOR_TOKEN} --env DASHBOARD_PASSWORD=${DASHBOARD_PASSWORD} --env DATAFORSEO_ENC_KEY=${DATAFORSEO_ENC_KEY} -- npx -y [email protected]{
"mcpServers": {
"dispatchseo": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CRON_SECRET": "${CRON_SECRET}",
"CURSOR_TOKEN": "${CURSOR_TOKEN}",
"DASHBOARD_PASSWORD": "${DASHBOARD_PASSWORD}",
"DATAFORSEO_ENC_KEY": "${DATAFORSEO_ENC_KEY}"
}
}
}
}Exposed tools (75)
53 read · 22 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_backlink_prospect | write | |
approve_draft | read | |
build_suggestion_now | read | |
check_sameness | read | |
check_serp | read | |
defer_setup_step | read | |
detect_site_launch | read | |
discard_draft | read | |
disconnect_repo | read | |
expand_trend_topic | read | |
get_activity | read | |
get_ai_visibility | read | |
get_automations | read | |
get_backlink_prospects | read | |
get_briefing | read | |
get_build_brief | read | |
get_changelog | read | |
get_content_prefs | read | |
get_conventions | read | |
get_cron_health | read | |
get_dataforseo_usage | read | |
get_domain_rank | read | |
get_drafts | read | |
get_feedback | read | |
get_instructions | read | |
get_next_actions | read | |
get_overview | read | |
get_pages | read | |
get_pipeline_pack | read | |
get_playbook | read | |
get_project | read | |
get_rankings | read | |
get_research_notes | read | |
get_setup_step | read | |
get_site_digest | read | |
get_site_profile | read | |
get_site_stats | read | |
get_suggestions | read | |
get_trend_topics | read | |
join_waitlist | read | |
keyword_ideas | read | |
log_page | read | |
mark_cron_fixed | read | |
mark_indexing_requested | read | |
mark_install_step | write | |
mark_pipeline_installed | read | |
merge_pr | write | |
propose_suggestion | read | |
propose_trend_topic | read | |
record_ai_citations | read | |
record_trend_scan | read | |
reorder_queue | read | |
rescan_site | read | |
save_research_notes | write | |
set_agent | write | |
set_content_path_hint | write | |
set_content_prefs | write | |
set_conventions | write | |
set_github_repo | write | |
set_gsc_property | write | |
set_internal_linking | write | |
set_market | write | |
set_playbook_status | write | |
set_publish_target | write | |
set_site_profile | write | |
submit_article | write | |
submit_feedback | write | |
suggest_keywords | read | |
track_keywords | read | |
trigger_trend_scan | write | |
update_backlink_prospect | write | |
update_feedback | write | |
update_suggestion | write | |
update_trend_topic | write | |
vote_feedback | read |
Trust audit
BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"Processes, and the host's own ~/.ssh and cloud keys - unless you mount them",
{ way: "Bind-mounting the host's ~/.ssh or cloud credential files", leaves: "The whole host key is reachable from the container", verdict: "Avoid - use a scoped token" },ai-visibility.ts
CMD ["node", "-e", "fetch('http://127.0.0.1:3000/api/health').then(r=>process.exit(r.status===200?0:1)).catch(()=>process.exit(1))"]const base = process.env.POSTGREST_URL ? "http://127.0.0.1:3000" : await backendBaseUrl();
const resolved = `${process.env.POSTGREST_URL ? "http://127.0.0.1:3000" : await backendBaseUrl()}${url}`;curl -s -o /dev/null --max-time 1 "http://127.0.0.1:$PORT" || rc=$?
.replace(/^/, "")
name: "",
if (i >= lines.length || lines[i].replace(/^/, "").trim() !== "---") return empty;
.replace(/^/, "")
echo "CLAUDE_CODE_OAUTH_TOKEN=sk-ant-oat-PASTE-YOUR-TOKEN-HERE" >> .env ||
const TOKEN = "fixture-token-do-not-use";
.env.docker.example
.env.local.example
http://localhost*|http://127.*|http://0.0.0.0*|http://10.*|http://192.168.*|http://172.1[6-9].*|http://172.2[0-9].*|http://172.3[0-1].*)
@polar-sh/sdk, @sentry/nextjs, @supabase/ssr, @supabase/supabase-js, @tailwindcss/postcss, @vercel/analytics, googleapis, gray-matter
porting this needs the report endpoint to accept project-token auth (scoped to a
Search for this and the second result is usually Anthropic's own [compaction overview](https://platform.claude.com/docs/en/build-with-claude/compaction) - and it's about a different product. That page
That's the literal branch logic in `seo-daily.yml`'s own "Classify the outcome" step, which runs after `claude-code-action` with `continue-on-error: true` so this step is reachable either way. It read
A routine is a saved configuration, not a background process you manage: a prompt, the repositories Claude works in, an environment, and a set of MCP connectors, packaged once at [claude.ai/code/routi
Step three is the one a one-off session never needs and an unattended one can't skip. Without it, two cold starts on the same morning - a retry, a manually re-triggered workflow, an overlapping schedu
- Treat your secrets as equal-weight full access to their surface. On a
Treat all six as equal-weight, full access to their surface - none of
**Does Claude Code read a project's `.env` file automatically?**
Gates applied: no_behavioural_pass.
7b28d878a573full audit observations/trust-audit/mcp-server/neozi12__dispatchseo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7b28d878a573 | BLOCK | D | 65 | first audit |
Questions
What is the dispatchseo MCP server?
Turn your AI agent into your SEO manager - works today with Claude Code, Codex, and Cursor. The open-source alternative to SEObot and Outrank
What tools does dispatchseo expose?
75 in total: 53 read-only, 22 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is dispatchseo safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does dispatchseo need?
It reads CRON_SECRET, CURSOR_TOKEN, DASHBOARD_PASSWORD, DATAFORSEO_ENC_KEY, DATAFORSEO_PASSWORD, DATAFORSEO_PLATFORM_PASSWORD, DISPATCHSEO_TOKEN, GH_MERGE_TOKEN, GH_MERGE_TOKEN_PROJECTS, GITHUB_APP_CLIENT_SECRET, GITHUB_APP_PRIVATE_KEY and GITHUB_APP_WEBHOOK_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does dispatchseo run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as dispatchseo at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (7b28d878a573), read on 2026-10-08. The repository is watched and re-audited when it changes.