superaudit-mcp
superaudit-mcp
SuperAudit의 실제 무료 감사를 MCP 호환 AI 에이전트가 호출할 수 있는 tool로 노출하는 MCP(Model Context Protocol) 서버입니다.
이를 통해 외부 개발자는 SuperAudit 팀과 상담 없이 자신의 에이전트(Claude 또는 기타 MCP 클라이언트)에게 *"이 웹사이트를 SuperAudit으로 감사해줘"*라고 요청할 수 있습니다 — tool이 공개 프로덕션 엔드포인트를 직접 호출합니다.
기능
단일 tool인 audit_website 를 노출합니다.
입력:
url(필수): 감사할 도메인 또는 URL (예:"minegocio.es"또는"https://minegocio.es").raw_json(선택 사항,boolean, 기본값false):true로 설정하면 읽기 쉬운 요약 외에도 SuperAudit이 반환하는 전체 JSON(모든 모듈, 모든 점수, 플랜)을 그대로 반환합니다.
내부 동작:
POST https://superaudit.airpagents.pro/api/quick-audit를{ "web": "<url>" }와 함께 호출합니다 — SuperAudit 랜딩 페이지가 무료 스캔에 사용하는 것과 동일한 공개 엔드포인트입니다. API 키나 토큰이 필요 없습니다.출력: 전체 점수(0-100), 각각의 ~27개 모듈 점수(SEO, 보안, 법률/RGPD, Core Web Vitals, WCAG 접근성, 생성형 AI 내 포지셔닝, WordPress/CVE, OWASP Top 10 등), 감지된 주요 문제, 그리고 결과에 따라 SuperAudit이 권장하는 유료 플랜을 포함한 텍스트 요약입니다.
Related MCP server: foglift-mcp
알려진 제한 사항(중요)
공개 엔드포인트에는 SuperAudit 서버의 IP당 분당 10회 요청 제한이 있습니다. 초과 시 tool은 이를 알리는 오류를 반환합니다 — 서비스에 과부하를 주지 않기 위해 자동 재시도하지 않습니다.
백엔드는 감사된 각 도메인을 24시간 동안 캐시하므로, 같은 웹사이트를 짧은 시간 내에 다시 감사하면 즉시 완료됩니다.
"콜드" 감사(캐시되지 않은 도메인)는 수 초 이상 걸릴 수 있습니다: 클라이언트는 실패로 간주하기 전에 최대 90초까지 대기합니다.
백엔드는 URL이 실제 공개 도메인을 가리키는지 검증합니다(SSRF 대책으로 사설 IP/localhost 차단) — 웹사이트가 존재하지 않거나 온라인 상태가 아니면 tool은 조용한 실패 대신 읽기 가능한 오류를 반환합니다.
설치(외부 개발자용)
요구 사항: Node.js 18 이상.
git clone <este repositorio> # o simplemente copia esta carpeta
cd superaudit-mcp
npm install
npm run build이 명령은 MCP 서버 바이너리인 dist/index.js를 생성합니다(MCP의 표준 전송인 stdio로 통신).
단독 실행 테스트(선택 사항)
npm run build
node dist/index.js프로세스는 stdio에서 대기 상태로 유지됩니다 — 이는 정상이며 MCP 서버의 동작 방식입니다. MCP 클라이언트에서 연결하며, 대화형 CLI로 사용하지 않습니다.
MCP 클라이언트에 연결하는 방법
Claude Code
claude mcp add superaudit -- node "/ruta/completa/a/superaudit-mcp/dist/index.js"Claude Desktop
Claude Desktop 구성 파일(claude_desktop_config.json)을 편집하고 다음을 추가합니다:
{
"mcpServers": {
"superaudit": {
"command": "node",
"args": ["/ruta/completa/a/superaudit-mcp/dist/index.js"]
}
}
}Claude Desktop을 재시작합니다. audit_website tool이 대화에서 필요할 때 에이전트가 사용할 수 있게 표시됩니다(예: "SuperAudit으로 minegocio.es를 감사해줘").
기타 MCP 클라이언트
stdio를 통한 MCP 서버를 지원하는 모든 클라이언트는 서버 명령으로 node dist/index.js를 실행할 수 있습니다 — 추가 구성이나 환경 변수가 필요 없습니다.
환경 변수(선택 사항)
SUPERAUDIT_BASE_URL: 기본값은https://superaudit.airpagents.pro입니다. 자체 테스트 환경을 가리키려는 경우에만 변경하는 것이 의미가 있습니다.
API 키는 필요 없습니다: 이 tool이 사용하는 엔드포인트는 SuperAudit 공개 랜딩 페이지가 무료 스캔에 사용하는 것과 동일합니다.
개발
npm install
npm run build # compila TypeScript → dist/이 초기 배포본에는 자동화된 테스트가 없습니다 — 실제 MCP 클라이언트(핸드셰이크 initialize + tools/list + tools/call)로 프로덕션 엔드포인트에 대해 수동으로 검증했습니다.
Available Tools
1 toolaudit_websiteAudita una web con SuperAuditA
Ejecuta una auditoría real y gratuita de SuperAudit sobre una web: SEO técnico, seguridad, cumplimiento legal (RGPD/LSSI), Core Web Vitals, accesibilidad, posicionamiento en IA generativa (GEO), WordPress/CVEs, y más de 25 módulos en total. Devuelve un score global de 0 a 100, el detalle por módulo y los principales problemas encontrados, priorizados. Útil para responder preguntas como '¿qué falla en la web de mi cliente?' o 'audita esta URL antes de contactarles'. Sujeto a un límite de uso justo (rate limit) en el servidor de SuperAudit.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | Dominio o URL a auditar, por ejemplo 'minegocio.es' o 'https://minegocio.es'. | |
| raw_json | No | Si es true, además del resumen legible incluye el JSON completo devuelto por SuperAudit (todos los módulos, scores y planes). Por defecto false para no saturar el contexto. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden, and it discloses important behavior: it is a real and free audit, it respects a fair-use rate limit on SuperAudit's server, and it returns a global score, per-module detail, and prioritized problems. It does not state explicit side-effect/safety information, but an audit is clearly presented as a non-mutating analysis, and the rate-limit caveat is a useful limitation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense but not bloated: the first sentence delivers the core purpose and scope, followed by the output format, use cases, and rate limit. Information is front-loaded and every clause earns its place, though the first sentence is long.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Despite having no output schema or annotations, the description covers what the tool does, what it returns, when to use it, and an operational constraint (rate limit). Combined with a fully documented input schema, an agent has enough context to invoke it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents 'url' and 'raw_json'. The description itself does not add parameter-specific detail; it only contextualizes the overall output. This meets the baseline but does not exceed it.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific action and object: 'Ejecuta una auditoría real y gratuita de SuperAudit sobre una web', and enumerates the audit areas (SEO técnico, seguridad, RGPD/LSSI, Core Web Vitals, accesibilidad, GEO, WordPress/CVEs). It also states the concrete return value (score 0-100, module details, prioritized issues). With no sibling tools to disambiguate, the purpose is fully identifiable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives concrete use cases: '¿qué falla en la web de mi cliente?' or 'audita esta URL antes de contactarles'. This makes the intended invocation context clear. There are no explicit exclusions or alternative tool routing, but no siblings are provided, so this is appropriate.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v1.0.0- First observed
audit_website
TDQS
Scored across 1 tool
Only one tool exists, so there is no ambiguity between tools. The single tool has a clear, distinct purpose around website auditing.
With a single tool, the naming is trivially consistent. 'audit_website' follows a clear verb_noun pattern.
A single tool feels thin and borderline for a server. It consolidates many audit checks into one call, but offers no auxiliary operations like listing or retrieving past audits.
The tool comprehensively covers the core audit workflow, including many modules. Minor gaps exist, such as no ability to fetch historical audits or compare results over time.
Maintenance
Related MCP Connectors
Find, compare, and audit software for AI agents. Scored registry of tools and MCP servers.
Turn any public website into an MCP server for agents to search, read and navigate.
Free public MCP for AI agents — 193 tools, 44 workflows. No API key.
- UnifAPIOAuthcom.unifapi
Hosted MCP server for live public-data APIs and Skills for AI agents.
Related MCP Servers
- AlicenseBqualityBmaintenanceMCP server that enables AI agents to perform comprehensive web audits using Google Lighthouse with 13+ tools for performance, accessibility, SEO, and security analysis.112,641 npm71MIT
- AlicenseNot gradedqualityNot gradedmaintenanceMCP server for website SEO + GEO analysis. Scan any URL to get scores across 5 categories (SEO, GEO, Performance, Security, Accessibility) with actionable fix recommendations. Enables AI coding assistants to audit websites and implement fixes autonomously.-
- AlicenseAqualityDmaintenanceA comprehensive MCP server providing 15 web tools including search, scraping, screenshots, SEO audits, and DNS/SSL checks through a single installation. It delivers clean, LLM-optimized outputs so AI agents can focus on reasoning rather than parsing raw HTML.1517 npmMIT
- AlicenseAqualityDmaintenanceEnables AI agents to perform comprehensive SEO audits on web pages, including meta tags, headings, links, images, performance, and more, via a CLI or MCP server.181MIT