Atlas / MCP servers / ruslanlap / pagespeed-insights-mcp

pagespeed-insights-mcpCAUTION

mcp/ruslanlap/pagespeed-insights-mcp

Six-tool MCP server for Google PageSpeed Insights & Chrome UX Report APIs. Analyze, compare, and optimize web performance directly through Claude, Cursor, or any MCP-compatible AI client.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
6 5r · 0w · 1d
Transport
stdio
License
Apache-2.0
Stars
68
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://ruslanlap.github.io/ruslanlap_buymeacoffe/)

Six-tool MCP server for Google PageSpeed Insights & Chrome UX Report APIs. Analyze, compare, and optimize web performance directly through Claude, Cursor, or any MCP-compatible AI client.

⚡ Quick Start (Copy & Paste)

{
"mcpServers": {
"pagespeed-insights": {
"command": "npx",
"args": ["-y", "pagespeed-insights-mcp"],
"env": { "GOOGLE_API_KEY": "your-google-api-key" }
}
}
}

Get a free API key at Google Cloud Console → paste into Claude Desktop's claude_desktop_config.json → restart. Done. (Codex/OpenAI config, Docker)

[](https://www.npmjs.com/package/pagespeed-insights-mcp) [](https://www.npmjs.com/package/pagespeed-insights-mcp) [](https://mcptoplist.com/server/io.github.ruslanlap%2Fpagespeed-insights-mcp) [](https://glama.ai/mcp/servers/ruslanlap/pagespeed-insights-mcp)

[](https://github.com/ruslanlap/pagespeed-insights-mcp/pkgs/npm

Read from source at commit 9c55776b143eOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add pagespeed-insights-mcp --env GOOGLE_API_KEY=${GOOGLE_API_KEY} -- npx -y [email protected]
03

Exposed tools (6)

5 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
pagespeed_analyze_batchreadBatch analysis
pagespeed_analyze_pagereadConcise Lighthouse health check
pagespeed_clear_cachedestructiveClear local cache
pagespeed_compare_pagesreadSide-by-side page comparison
pagespeed_diagnose_pagereadFocused render-blocking diagnosis
pagespeed_get_field_datareadPage-level CrUX field data
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/test-tools.js:26
console.log(`API Key: ${apiKey.substring(0, 10)}...`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
pagespeed_clear_cache
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, p-limit, p-retry, pino, pino-pretty, zod, @semantic-release/changelog, @semantic-release/git
Why it matters. 21 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:246
curl -sSL https://raw.githubusercontent.com/ruslanlap/pagespeed-insights-mcp/master/scripts/install.sh | bash
INFOInventory / provenance · inv.oversize · CWE-1104
assets/3.png
assets/3.png
Why it matters. 1380746 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/3.png
docs/assets/3.png
Why it matters. 1380746 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 9c55776b143efull audit observations/trust-audit/mcp-server/ruslanlap__pagespeed-insights-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-079c55776b143eCAUTIONB89first audit
06

Questions

What is the pagespeed-insights-mcp MCP server?

Six-tool MCP server for Google PageSpeed Insights & Chrome UX Report APIs. Analyze, compare, and optimize web performance directly through Claude, Cursor, or any MCP-compatible AI client.

What tools does pagespeed-insights-mcp expose?

6 in total: 5 read-only, 0 that write, and 1 that can delete or overwrite (pagespeed_clear_cache). Every one is listed on this page with its risk.

Is pagespeed-insights-mcp safe to connect to an agent?

With care. The audit graded it B (89/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does pagespeed-insights-mcp need?

It reads GOOGLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does pagespeed-insights-mcp run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @ruslanlap/pagespeed-insights-mcp at 2.0.2.

How current is this page?

The grade is for one exact copy of the source (9c55776b143e), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement