Atlas / MCP servers / squirrelscan / Squirrelscan

SquirrelscanBLOCK

mcp/squirrelscan/squirrelscan

The website QA tool for your coding agent. 295+ audit rules across SEO, performance, security, accessibility and agent experience.

Verdict
BLOCK
Grade
F
Trust score
26 /100
Exposed tools
90 74r · 13w · 3d
Transport
stdio · streamable-http
License
MIT
Stars
271
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The website QA tool for your coding agent

squirrelscan is an Open Source cli tool that audits websites for SEO, performance, security, accessibility, agent experience and other issues, and gives your coding agent exact fixes. Run it from the CLI, inside your coding agent, in the cloud, or over MCP.

Combine your coding agent with a deterministic and extensible audit tool.

[](https://squirrelscan.com/add/cursor) [](https://squirrelscan.com/add/claude) [](https://squirrelscan.com/add/codex) [](https://squirrelscan.com/add/opencode) [](https://registry.modelcontextprotocol.io)

[](https://github.com/squirrelscan/squirrelscan/actions/workflows/ci.yml) [](https://github.com/squirrelscan/squirrelscan/actions/workflows/codeql.yml) [](https://www.npmjs.com/package/squirrelscan) [](LICENSE)

Features

  • 295 Rules, 21 Categories - Comprehensive coverage across SEO, accessibility, performance, and security
  • Fast crawler - Highly optimized memory efficient crawler
  • Agent Experience - Audit agent experience to assist agents in using your site
  • **Securi
Read from source at commit 61e964208bcaOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add waf-detect --env ACCESS_TOKEN=${ACCESS_TOKEN} --env API_KEY=${API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} --env GOOGLE_PSI_API_KEY=${GOOGLE_PSI_API_KEY} -- npx -y @squirrelscan/[email protected]
claude-desktop
{
  "mcpServers": {
    "waf-detect": {
      "command": "npx",
      "args": [
        "-y",
        "@squirrelscan/[email protected]"
      ],
      "env": {
        "ACCESS_TOKEN": "${ACCESS_TOKEN}",
        "API_KEY": "${API_KEY}",
        "AUTH_TOKEN": "${AUTH_TOKEN}",
        "GOOGLE_PSI_API_KEY": "${GOOGLE_PSI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (90)

74 read · 13 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
Aread
AGENTS.mdreadDetects /AGENTS.md (and variants) — plain-Markdown instructions for coding agents working against the site
AccessibilityreadAccessibility for users with disabilities
AnalyticsreadTracking and measurement implementation
Bread
BlockingreadContent, links, and trackers that ad blockers and privacy filters block
Boomread
Cread
CharsetreadChecks for proper character encoding declaration
CitationsreadChecks for citations to authoritative external sources
CompressionreadChecks for Gzip or Brotli compression
ContentreadText quality, readability, and content structure
Counterreadcounts its own invocations
CrawlabilityreadRobots.txt, sitemaps, and crawl directives
DisclaimersreadChecks for appropriate disclaimers on sensitive content
DoctypereadChecks for valid HTML5 doctype declaration
E-E-A-TreadExperience, expertise, authority, trust signals
ExamplereadExample rule
FAQreadFAQ structured data
FaviconreadChecks for favicon presence
HTTPSreadCheck HTTPS
ImagesreadImage optimization and accessibility
InternationalizationreadLanguage declarations and multi-region support
InterstitialsreadDetects potentially intrusive mobile interstitials
LinksreadInternal and external link health and structure
MobilereadMobile-friendliness and responsive design
OtherreadUncategorized or legacy rules
PaginationreadChecks that paginated pages have proper canonicals
PerformancereadPage speed and loading performance
Permissions-PolicyreadChecks for Permissions-Policy (Feature-Policy) header
Referrer-PolicyreadChecks for Referrer-Policy header
Robots.txtreadRobots.txt check
SRIreadd
SecurityreadHTTPS, headers, and safe link practices
TTFBreadPages should respond quickly
Uncloneablereademits a check structuredClone refuses
VideoreadVideo content markup and accessibility
X-Content-Type-OptionsreadChecks for MIME type sniffing protection
X-Frame-OptionsreadChecks for clickjacking protection header
analyzewriteRun audit rules on stored crawl
auditwriteRun audit on a URL
audit_websiteread
authreadAuthentication commands
comment_on_issueread
compare_entitiesread
completionreadGenerate shell completions
configwriteShow or edit configuration
crawlreadCrawl a website (no analysis)
createwriteMint an org API key for headless / CI use (requires a login session)
creditsreadShow cloud credit balance and feature pricing
diskreadReport what ~/.squirrel is using, per project and in total
doctorwriteRun health checks
entitiesreadQuery the entity map of a stored audit
feedbackwriteSend feedback to the squirrelscan team
get_entityread
get_entity_findingsread
get_entity_graphread
get_issueread
get_reportread
get_ruleread
httpsread
initwriteCreate squirrel.toml
installwriteBootstrap local installation
keysreadManage org API keys
listreadList org API keys (requires a login session)
list_auditsread
list_entitiesread
list_issuesread
list_rulesread
llms.txtreadDetects /llms.txt (and /llms-full.txt) at the domain root and checks its basic Markdown format — an emerging standard giving AI agents a curated, machine-readable map of your site
loginreadAuthenticate with squirrelscan
logoutdestructiveSign out and revoke token
mcpwriteRun the local MCP server (stdio) for agents like Claude Code and Cursor
pathreadShow config file path
quick_checkread
reportreadQuery and view stored audit reports
revokedestructiveRevoke an org API key by prefix or id (requires a login session)
selfreadSelf-management commands
send_feedbackwrite
setwriteSet config value
settingsreadManage CLI settings
setupwriteSign in, install the agent skills and pick your defaults
showreadShow current config
skillsreadManage agent skills (Claude Code, Cursor, Codex, and more)
statusreadShow authentication status (source, scopes, org)
uninstalldestructiveRemove squirrel from the system
updatewriteCheck and apply updates
validatereadValidate config file
versionreadShow version information
whoamireadShow the active credential (source, scopes, org)
04

Trust audit

BLOCKgrade F · trust 26/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (6 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
packages/rules/src/integrity/signals.ts:310
atob( ... "eval(
Why it matters. decodes a payload and executes it
CRITICALHard-coded secrets · secret.aws · CWE-798, CWE-321
packages/rules/src/security/leaked-secrets.ts:891
* `AKIA0000000000000000`. Counted by a walk rather than `/(?:x{3,}|0{16,})$/`, // pragma: allowlist secret
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/rules/src/security/leaked-secrets.ts:545
pattern: /-----BEGIN RSA PRIVATE KEY-----/g,
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/rules/src/security/leaked-secrets.ts:546
keywords: ["-----begin rsa private key-----"],
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/rules/src/security/leaked-secrets.ts:551
pattern: /-----BEGIN DSA PRIVATE KEY-----/g,
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/rules/src/security/leaked-secrets.ts:552
keywords: ["-----begin dsa private key-----"],
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/rules/src/security/leaked-secrets.ts:557
pattern: /-----BEGIN EC PRIVATE KEY-----/g,
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
apps/cli/src/types/bun-sqlite.d.ts:17
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/crawler/src/types/bun-sqlite.d.ts:17
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/rules/src/integrity/signals.ts:307
"eval(",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/rules/src/integrity/signals.ts:308
'function("return this")',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
apps/cli/src/lib/non-public-host.ts:41
"metadata.google.internal",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/cli/src/cli/commands/auth.ts:179
if (apiKey.name) console.log(`  Key: ${apiKey.name}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/cli/src/cli/commands/auth.ts:183
if (apiKey.keyEnv) console.log(`  Key env: ${apiKey.keyEnv}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/cli/src/cli/commands/auth.ts:186
console.log(`  Device: ${token.deviceName}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/cli/src/cli/commands/auth.ts:189
console.log(`  Expires: ${new Date(token.expiresAt).toLocaleDateString()}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
apps/cli/src/cli/commands/keys.ts:133
console.log(`  ${exportLine(key.token)}`);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
packages/tech-detect/src/fingerprints/generated.ts:393
{ type: "script-url", pattern: new RegExp("static\\.cloudflareinsights\\.com/beacon(\\.min)?\\.js", "i") },
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
apps/cli/tests/commands/self-settings-redaction.test.ts:10
const TOKEN = "session-token-probe-value-1399";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
apps/cli/tests/controllers/auth-status-org-api-key.test.ts:131
token: "sq_notarealkeynotarealkeynotareal", // pragma: allowlist secret
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/rules/integrity/known-malicious-url.mdx:47
api_key = "your-safe-browsing-key" # pragma: allowlist secret
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/rules/src/ax/ai-crawlers.ts:52
{ token: "Meta-ExternalFetcher", vendor: "Meta", purpose: "user-triggered fetch", crawlerClass: "user-action" },
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
logout, revoke, uninstall
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mailmap
.mailmap
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.secrets.baseline
.secrets.baseline
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 61e964208bcafull audit observations/trust-audit/mcp-server/squirrelscan__squirrelscan.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0661e964208bcaBLOCKF26first audit
06

Questions

What is the Squirrelscan MCP server?

The website QA tool for your coding agent. 295+ audit rules across SEO, performance, security, accessibility and agent experience.

What tools does Squirrelscan expose?

90 in total: 74 read-only, 13 that write, and 3 that can delete or overwrite (logout, revoke, uninstall). Every one is listed on this page with its risk.

Is Squirrelscan safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (26/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Squirrelscan need?

It reads ACCESS_TOKEN, API_KEY, AUTH_TOKEN, GOOGLE_PSI_API_KEY, PASSWORD, SECRET, SECRET_KEY, SQUIRRELSCAN_API_KEY, SQUIRREL_API_TOKEN, SQUIRREL_AUTH_URL, TOKEN and UPDATE_SECRETS_SNAPSHOT from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Squirrelscan run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @squirrelscan/waf-detect at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (61e964208bca), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement