geoaeoSAFE
Scores a site 0-100 and generates GEO/AEO files for owners who want AI citations.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Scores a site 0-100 and generates GEO/AEO files for owners who want AI citations.
npx geoaeo audit https://usegeoaeo.com
https://usegeoaeo.com: 85/100 PASS /llms.txt: Short site map is present. PASS /llms-full.txt: Full site map is present. PASS /sitemap.xml: A sitemap artifact is present. PASS /robots.txt: Robots policy includes a sitemap URL. PASS AI crawler access: No named AI crawler is disallowed from /. PASS WebMCP manifest: A WebMCP-style tool manifest is present. FAIL Markdown mirrors: Missing: no page markdown mirrors were found. PASS Page titles: Every inspected page has a title. ... 17 more checks ... Top fixes: 1. Markdown mirrors 2. MCP server card 3. hreflang alternates
Contents
Try it · Set up in your agent · Install · Quick start · Why · Usage · How it works · Run it locally · Contributing · License
Try it
Each path runs the same audit. Start at the top.
- Run it in the browser. No install: usegeoaeo.com/tools.
- Run one command. No install:
npx geoaeo audit https://example.com
- Add it to a project, and call it from a build script or CI. See Install.
- Drive it from your agent over MCP. In Claude Code, Cursor, or Codex:
/plu
0c896dab77beOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add geoaeo -- npx -y [email protected] mcp
Exposed tools (6)
4 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
audit | read | Audit a live URL or local site directory for GEO and AEO gaps. |
gen | read | Generate one GEO or AEO artifact from the local site config. |
geoaeo | read | Free, open-source CLI, MCP server, and library that audits any site 0-100 for SEO, GEO, and AEO and generates llms.txt, sitemaps, JSON-LD, WebMCP, and Markdown mirrors. |
humanize | write | Find AI-writing tells in prose files. Set write to update them. |
trello.create_card | write | |
web_fetch | read | Fetch a URL |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
.cursorignore
.jscpd.json
.oxfmtrc.json
.oxlintrc.json
import { serverCardJson } from "../../../src/generated/server-card.generated";import { skillMarkdown } from "../../../../../src/generated/agent-skills.generated";import { agentSkillsIndex } from "../../../../src/generated/agent-skills.generated";import { serverCardJson } from "../../../../src/generated/server-card.generated";import { agentsMd } from "../../src/generated/agents-md.generated";const target = "http://127.0.0.1:1/";
const target = "http://127.0.0.1:4141";
return withResponseUrl(new Response(htmlPage("Home")), "https://127.0.0.1:4141/");@opennextjs/cloudflare, @paralleldrive/cuid2, better-auth, class-variance-authority, clsx, drizzle-orm, lucide-react, next
turbo, typescript
@cloudflare/workers-types, typescript
@cloudflare/workers-types, @types/node
@modelcontextprotocol/sdk, cheerio, commander, jiti, zod, @types/node, tsup, typescript
Gates applied: no_behavioural_pass.
0c896dab77befull audit observations/trust-audit/mcp-server/pooriaarab__geoaeo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0c896dab77be | SAFE | B | 89 | first audit |
Questions
What is the geoaeo MCP server?
Scores a site 0-100 and generates GEO/AEO files for owners who want AI citations.
What tools does geoaeo expose?
6 in total: 4 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is geoaeo safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does geoaeo need?
It reads CLOUDFLARE_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does geoaeo run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @template/queue-consumer at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (0c896dab77be), read on 2026-10-08. The repository is watched and re-audited when it changes.