SquirrelscanBLOCK
The website QA tool for your coding agent. 295+ audit rules across SEO, performance, security, accessibility and agent experience.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The website QA tool for your coding agent
squirrelscan is an Open Source cli tool that audits websites for SEO, performance, security, accessibility, agent experience and other issues, and gives your coding agent exact fixes. Run it from the CLI, inside your coding agent, in the cloud, or over MCP.
Combine your coding agent with a deterministic and extensible audit tool.
[](https://squirrelscan.com/add/cursor) [](https://squirrelscan.com/add/claude) [](https://squirrelscan.com/add/codex) [](https://squirrelscan.com/add/opencode) [](https://registry.modelcontextprotocol.io)
[](https://github.com/squirrelscan/squirrelscan/actions/workflows/ci.yml) [](https://github.com/squirrelscan/squirrelscan/actions/workflows/codeql.yml) [](https://www.npmjs.com/package/squirrelscan) [](LICENSE)
Features
- 295 Rules, 21 Categories - Comprehensive coverage across SEO, accessibility, performance, and security
- Fast crawler - Highly optimized memory efficient crawler
- Agent Experience - Audit agent experience to assist agents in using your site
- **Securi
61e964208bcaOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add waf-detect --env ACCESS_TOKEN=${ACCESS_TOKEN} --env API_KEY=${API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} --env GOOGLE_PSI_API_KEY=${GOOGLE_PSI_API_KEY} -- npx -y @squirrelscan/[email protected]{
"mcpServers": {
"waf-detect": {
"command": "npx",
"args": [
"-y",
"@squirrelscan/[email protected]"
],
"env": {
"ACCESS_TOKEN": "${ACCESS_TOKEN}",
"API_KEY": "${API_KEY}",
"AUTH_TOKEN": "${AUTH_TOKEN}",
"GOOGLE_PSI_API_KEY": "${GOOGLE_PSI_API_KEY}"
}
}
}
}Exposed tools (90)
74 read · 13 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
A | read | |
AGENTS.md | read | Detects /AGENTS.md (and variants) — plain-Markdown instructions for coding agents working against the site |
Accessibility | read | Accessibility for users with disabilities |
Analytics | read | Tracking and measurement implementation |
B | read | |
Blocking | read | Content, links, and trackers that ad blockers and privacy filters block |
Boom | read | |
C | read | |
Charset | read | Checks for proper character encoding declaration |
Citations | read | Checks for citations to authoritative external sources |
Compression | read | Checks for Gzip or Brotli compression |
Content | read | Text quality, readability, and content structure |
Counter | read | counts its own invocations |
Crawlability | read | Robots.txt, sitemaps, and crawl directives |
Disclaimers | read | Checks for appropriate disclaimers on sensitive content |
Doctype | read | Checks for valid HTML5 doctype declaration |
E-E-A-T | read | Experience, expertise, authority, trust signals |
Example | read | Example rule |
FAQ | read | FAQ structured data |
Favicon | read | Checks for favicon presence |
HTTPS | read | Check HTTPS |
Images | read | Image optimization and accessibility |
Internationalization | read | Language declarations and multi-region support |
Interstitials | read | Detects potentially intrusive mobile interstitials |
Links | read | Internal and external link health and structure |
Mobile | read | Mobile-friendliness and responsive design |
Other | read | Uncategorized or legacy rules |
Pagination | read | Checks that paginated pages have proper canonicals |
Performance | read | Page speed and loading performance |
Permissions-Policy | read | Checks for Permissions-Policy (Feature-Policy) header |
Referrer-Policy | read | Checks for Referrer-Policy header |
Robots.txt | read | Robots.txt check |
SRI | read | d |
Security | read | HTTPS, headers, and safe link practices |
TTFB | read | Pages should respond quickly |
Uncloneable | read | emits a check structuredClone refuses |
Video | read | Video content markup and accessibility |
X-Content-Type-Options | read | Checks for MIME type sniffing protection |
X-Frame-Options | read | Checks for clickjacking protection header |
analyze | write | Run audit rules on stored crawl |
audit | write | Run audit on a URL |
audit_website | read | |
auth | read | Authentication commands |
comment_on_issue | read | |
compare_entities | read | |
completion | read | Generate shell completions |
config | write | Show or edit configuration |
crawl | read | Crawl a website (no analysis) |
create | write | Mint an org API key for headless / CI use (requires a login session) |
credits | read | Show cloud credit balance and feature pricing |
disk | read | Report what ~/.squirrel is using, per project and in total |
doctor | write | Run health checks |
entities | read | Query the entity map of a stored audit |
feedback | write | Send feedback to the squirrelscan team |
get_entity | read | |
get_entity_findings | read | |
get_entity_graph | read | |
get_issue | read | |
get_report | read | |
get_rule | read | |
https | read | |
init | write | Create squirrel.toml |
install | write | Bootstrap local installation |
keys | read | Manage org API keys |
list | read | List org API keys (requires a login session) |
list_audits | read | |
list_entities | read | |
list_issues | read | |
list_rules | read | |
llms.txt | read | Detects /llms.txt (and /llms-full.txt) at the domain root and checks its basic Markdown format — an emerging standard giving AI agents a curated, machine-readable map of your site |
login | read | Authenticate with squirrelscan |
logout | destructive | Sign out and revoke token |
mcp | write | Run the local MCP server (stdio) for agents like Claude Code and Cursor |
path | read | Show config file path |
quick_check | read | |
report | read | Query and view stored audit reports |
revoke | destructive | Revoke an org API key by prefix or id (requires a login session) |
self | read | Self-management commands |
send_feedback | write | |
set | write | Set config value |
settings | read | Manage CLI settings |
setup | write | Sign in, install the agent skills and pick your defaults |
show | read | Show current config |
skills | read | Manage agent skills (Claude Code, Cursor, Codex, and more) |
status | read | Show authentication status (source, scopes, org) |
uninstall | destructive | Remove squirrel from the system |
update | write | Check and apply updates |
validate | read | Validate config file |
version | read | Show version information |
whoami | read | Show the active credential (source, scopes, org) |
Trust audit
BLOCKgrade F · trust 26/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
atob( ... "eval(
* `AKIA0000000000000000`. Counted by a walk rather than `/(?:x{3,}|0{16,})$/`, // pragma: allowlist secretpattern: /-----BEGIN RSA PRIVATE KEY-----/g,
keywords: ["-----begin rsa private key-----"],
pattern: /-----BEGIN DSA PRIVATE KEY-----/g,
keywords: ["-----begin dsa private key-----"],
pattern: /-----BEGIN EC PRIVATE KEY-----/g,
exec(sql: string): void;
exec(sql: string): void;
"eval(",'function("return this")',"metadata.google.internal",
if (apiKey.name) console.log(` Key: ${apiKey.name}`);if (apiKey.keyEnv) console.log(` Key env: ${apiKey.keyEnv}`);console.log(` Device: ${token.deviceName}`);console.log(` Expires: ${new Date(token.expiresAt).toLocaleDateString()}`);console.log(` ${exportLine(key.token)}`);{ type: "script-url", pattern: new RegExp("static\\.cloudflareinsights\\.com/beacon(\\.min)?\\.js", "i") },const TOKEN = "session-token-probe-value-1399";
token: "sq_notarealkeynotarealkeynotareal", // pragma: allowlist secret
api_key = "your-safe-browsing-key" # pragma: allowlist secret
{ token: "Meta-ExternalFetcher", vendor: "Meta", purpose: "user-triggered fetch", crawlerClass: "user-action" },logout, revoke, uninstall
.mailmap
.secrets.baseline
Gates applied: critical_finding, no_behavioural_pass.
61e964208bcafull audit observations/trust-audit/mcp-server/squirrelscan__squirrelscan.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 61e964208bca | BLOCK | F | 26 | first audit |
Questions
What is the Squirrelscan MCP server?
The website QA tool for your coding agent. 295+ audit rules across SEO, performance, security, accessibility and agent experience.
What tools does Squirrelscan expose?
90 in total: 74 read-only, 13 that write, and 3 that can delete or overwrite (logout, revoke, uninstall). Every one is listed on this page with its risk.
Is Squirrelscan safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (26/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Squirrelscan need?
It reads ACCESS_TOKEN, API_KEY, AUTH_TOKEN, GOOGLE_PSI_API_KEY, PASSWORD, SECRET, SECRET_KEY, SQUIRRELSCAN_API_KEY, SQUIRREL_API_TOKEN, SQUIRREL_AUTH_URL, TOKEN and UPDATE_SECRETS_SNAPSHOT from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Squirrelscan run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @squirrelscan/waf-detect at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (61e964208bca), read on 2026-10-06. The repository is watched and re-audited when it changes.