Skip to main content
Glama
Jorucmor

superaudit-mcp

by Jorucmor

superaudit-mcp

MCP(Model Context Protocol)サーバー。SuperAudit の実際の無料監査を、MCP 互換の AI エージェントが呼び出せるツールとして公開します。

これにより、外部の開発者は自分のエージェント(Claude や他の MCP クライアント)に 「このウェブサイトを SuperAudit で監査して」 のようなことを依頼できます。SuperAudit チームの誰とも話す必要はありません。ツールは本番の公開エンドポイントを直接呼び出します。

何をするか

公開するツールは 1 つだけです: audit_website。

  • 入力:

    • url(必須): 監査するドメインまたは URL。例: "minegocio.es" または "https://minegocio.es"。

    • raw_json(任意、boolean、デフォルト false): true の場合、読みやすい要約に加えて、SuperAudit が返す完全な JSON(すべてのモジュール、すべてのスコア、プラン)を返します。

  • 内部で行うこと: POST https://superaudit.airpagents.pro/api/quick-audit を { "web": "<url>" } で呼び出します。これは SuperAudit のランディングページが無料スキャンに現在使用しているのと同じ公開エンドポイントです。API キーやトークンは不要です。

  • 出力: グローバルスコア(0〜100)、各約27モジュールのスコア(SEO、セキュリティ、法務/RGPD、Core Web Vitals、WCAG アクセシビリティ、生成 AI での検索順位、WordPress/CVE、OWASP Top 10 など)、検出された主な問題、および結果に応じて SuperAudit が推奨する有料プランを含むテキスト要約。

Related MCP server: foglift-mcp

既知の制限(重要)

  • 公開エンドポイントには、SuperAudit サーバー上で IP ごとに毎分 10 リクエストの制限があります。これを超えると、ツールはその旨を示すエラーを返します。サービスに過負荷をかけないよう、自動リトライは行いません。

  • バックエンドは監査済みの各ドメインを 24 時間キャッシュするため、同じウェブサイトを短期間にもう一度監査すると即座に結果が返ります。

  • 「コールド」監査(キャッシュされていないドメイン)は数秒以上かかることがあります。クライアントは試行を失敗と判断するまで最大 90 秒待機します。

  • バックエンドは URL が実際の公開ドメインを指していることを検証します(SSRF 対策としてプライベート IP / localhost をブロックします)。ウェブサイトが存在しないかオンラインでない場合、ツールは読みやすいエラーを返し、黙って失敗することはありません。

インストール(外部開発者向け)

要件: Node.js 18 以上。

git clone <este repositorio>   # o simplemente copia esta carpeta
cd superaudit-mcp
npm install
npm run build

これにより dist/index.js が生成されます。これは MCP サーバーのバイナリです(MCP の標準トランスポートである stdio で通信します)。

単体で試す(任意)

npm run build
node dist/index.js

プロセスは stdio で待機したままになります。これは正常で、MCP サーバーはそのように動作します。MCP クライアントから接続するものであり、対話型 CLI として使うものではありません。

MCP クライアントへの接続方法

Claude Code

claude mcp add superaudit -- node "/ruta/completa/a/superaudit-mcp/dist/index.js"

Claude Desktop

Claude Desktop の設定ファイル(claude_desktop_config.json)を編集して、次を追加します:

{
  "mcpServers": {
    "superaudit": {
      "command": "node",
      "args": ["/ruta/completa/a/superaudit-mcp/dist/index.js"]
    }
  }
}

Claude Desktop を再起動します。会話で必要になったときにエージェントが使用できるよう、audit_website ツールが利用可能になります(例: 「minegocio.es を SuperAudit で監査して」)。

その他の MCP クライアント

stdio による MCP サーバーをサポートするクライアントは、node dist/index.js をサーバーコマンドとして起動できます。追加の設定や環境変数は必要ありません。

環境変数(任意)

  • SUPERAUDIT_BASE_URL: デフォルトは https://superaudit.airpagents.pro。独自のテスト環境を指定する場合にのみ変更する意味があります。

API キーは不要です。このツールが使用するエンドポイントは、SuperAudit の公開ランディングページが無料スキャンに使用しているものと同じです。

開発

npm install
npm run build   # compila TypeScript → dist/

この初期成果物には自動テストはありません。実際の MCP クライアント(ハンドシェイク initialize + tools/list

  • tools/call) を使って本番エンドポイントに対して手動で検証しました。

Available Tools

1 tool
audit_websiteAudita una web con SuperAuditA

Ejecuta una auditoría real y gratuita de SuperAudit sobre una web: SEO técnico, seguridad, cumplimiento legal (RGPD/LSSI), Core Web Vitals, accesibilidad, posicionamiento en IA generativa (GEO), WordPress/CVEs, y más de 25 módulos en total. Devuelve un score global de 0 a 100, el detalle por módulo y los principales problemas encontrados, priorizados. Útil para responder preguntas como '¿qué falla en la web de mi cliente?' o 'audita esta URL antes de contactarles'. Sujeto a un límite de uso justo (rate limit) en el servidor de SuperAudit.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlYesDominio o URL a auditar, por ejemplo 'minegocio.es' o 'https://minegocio.es'.
raw_jsonNoSi es true, además del resumen legible incluye el JSON completo devuelto por SuperAudit (todos los módulos, scores y planes). Por defecto false para no saturar el contexto.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden, and it discloses important behavior: it is a real and free audit, it respects a fair-use rate limit on SuperAudit's server, and it returns a global score, per-module detail, and prioritized problems. It does not state explicit side-effect/safety information, but an audit is clearly presented as a non-mutating analysis, and the rate-limit caveat is a useful limitation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but not bloated: the first sentence delivers the core purpose and scope, followed by the output format, use cases, and rate limit. Information is front-loaded and every clause earns its place, though the first sentence is long.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having no output schema or annotations, the description covers what the tool does, what it returns, when to use it, and an operational constraint (rate limit). Combined with a fully documented input schema, an agent has enough context to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents 'url' and 'raw_json'. The description itself does not add parameter-specific detail; it only contextualizes the overall output. This meets the baseline but does not exceed it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific action and object: 'Ejecuta una auditoría real y gratuita de SuperAudit sobre una web', and enumerates the audit areas (SEO técnico, seguridad, RGPD/LSSI, Core Web Vitals, accesibilidad, GEO, WordPress/CVEs). It also states the concrete return value (score 0-100, module details, prioritized issues). With no sibling tools to disambiguate, the purpose is fully identifiable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives concrete use cases: '¿qué falla en la web de mi cliente?' or 'audita esta URL antes de contactarles'. This makes the intended invocation context clear. There are no explicit exclusions or alternative tool routing, but no siblings are provided, so this is appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev1.0.0
    • First observedaudit_website

TDQS

A4.2/5.0

Scored across 1 tool

Disambiguation5/5

Only one tool exists, so there is no ambiguity between tools. The single tool has a clear, distinct purpose around website auditing.

Naming Consistency5/5

With a single tool, the naming is trivially consistent. 'audit_website' follows a clear verb_noun pattern.

Tool Count3/5

A single tool feels thin and borderline for a server. It consolidates many audit checks into one call, but offers no auxiliary operations like listing or retrieving past audits.

Completeness4/5

The tool comprehensively covers the core audit workflow, including many modules. Minor gaps exist, such as no ability to fetch historical audits or compare results over time.

Maintenance

ActivitySlowing
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    B
    maintenance
    MCP server that enables AI agents to perform comprehensive web audits using Google Lighthouse with 13+ tools for performance, accessibility, SEO, and security analysis.
    11
    2,641 npm
    71
    MIT
  • A
    license
    Not graded
    quality
    Not graded
    maintenance
    MCP server for website SEO + GEO analysis. Scan any URL to get scores across 5 categories (SEO, GEO, Performance, Security, Accessibility) with actionable fix recommendations. Enables AI coding assistants to audit websites and implement fixes autonomously.
    -
  • A
    license
    A
    quality
    D
    maintenance
    A comprehensive MCP server providing 15 web tools including search, scraping, screenshots, SEO audits, and DNS/SSL checks through a single installation. It delivers clean, LLM-optimized outputs so AI agents can focus on reasoning rather than parsing raw HTML.
    15
    17 npm
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables AI agents to perform comprehensive SEO audits on web pages, including meta tags, headings, links, images, performance, and more, via a CLI or MCP server.
    18
    1
    MIT