superaudit-mcp
superaudit-mcp
Сервер MCP (Model Context Protocol), который предоставляет реальный и бесплатный аудит SuperAudit как инструмент (tool), который может вызывать любой ИИ-агент, совместимый с MCP.
Благодаря этому внешний разработчик может попросить своего собственного агента (Claude или другой MCP-клиент) сделать что-то вроде "проведи аудит этого сайта с помощью SuperAudit", не общаясь ни с кем из команды SuperAudit — инструмент напрямую вызывает публичный production-эндпоинт.
Что делает
Предоставляет единственный инструмент: audit_website.
Входные данные:
url(обязательно): домен или URL для аудита, напр."minegocio.es"или"https://minegocio.es".raw_json(необязательно,boolean, по умолчаниюfalse): еслиtrue, помимо читаемого резюме возвращает полный JSON в том виде, в котором его отдаёт SuperAudit (все модули, все оценки, планы).
Что делает внутри: вызывает
POST https://superaudit.airpagents.pro/api/quick-auditс{ "web": "<url>" }— тот же публичный эндпоинт, который сегодня использует лендинг SuperAudit для бесплатного сканирования. Не требует никаких ключей или токенов.Выходные данные: текстовое резюме с общим баллом (0-100), оценкой каждого из ~27 модулей (SEO, безопасность, юридические вопросы/GDPR, Core Web Vitals, доступность WCAG, позиционирование в генеративном ИИ, WordPress/CVE, OWASP Top 10 и т.д.), основными обнаруженными проблемами и платным планом, который SuperAudit рекомендует по результату.
Related MCP server: foglift-mcp
Известные ограничения (важно)
Публичный эндпоинт имеет лимит 10 запросов в минуту на IP на сервере SuperAudit. При превышении инструмент возвращает ошибку с указанием причины — он не повторяет попытки автоматически, чтобы не перегружать сервис.
Бэкенд кэширует каждый проверенный домен в течение 24 часов, поэтому повторный аудит того же сайта в ближайшее время происходит мгновенно.
«Холодный» аудит (домен не в кэше) может занять несколько секунд: клиент ждёт до 90 секунд, прежде чем считать попытку неудачной.
Бэкенд проверяет, что URL указывает на реальный публичный домен (блокирует частные IP/localhost как меру против SSRF) — если сайт не существует или не в сети, инструмент возвращает понятную ошибку, а не тихий сбой.
Установка (для внешнего разработчика)
Требования: Node.js 18 или выше.
git clone <este repositorio> # o simplemente copia esta carpeta
cd superaudit-mcp
npm install
npm run buildЭто создаёт dist/index.js — бинарный файл MCP-сервера (общается через
stdio, стандартный транспорт MCP).
Проверить отдельно (необязательно)
npm run build
node dist/index.jsПроцесс остаётся ожидающим в stdio — это нормально, так работают MCP-серверы. Подключение происходит через MCP-клиент, а не через интерактивный CLI.
Как подключить к MCP-клиенту
Claude Code
claude mcp add superaudit -- node "/ruta/completa/a/superaudit-mcp/dist/index.js"Claude Desktop
Отредактировать файл конфигурации Claude Desktop (claude_desktop_config.json)
и добавить:
{
"mcpServers": {
"superaudit": {
"command": "node",
"args": ["/ruta/completa/a/superaudit-mcp/dist/index.js"]
}
}
}Перезапустить Claude Desktop. Инструмент audit_website станет доступен,
чтобы агент мог использовать его, когда этого потребует разговор (напр.
"проведи аудит minegocio.es с помощью SuperAudit").
Любой другой MCP-клиент
Любой клиент, поддерживающий MCP-серверы через stdio, может запустить
node dist/index.js как команду сервера — не требуется дополнительная
настройка или переменные окружения.
Переменные окружения (необязательные)
SUPERAUDIT_BASE_URL: по умолчаниюhttps://superaudit.airpagents.pro. Менять имеет смысл только для указания на собственное тестовое окружение.
Никакой API-ключ не нужен: эндпоинт, который использует этот инструмент, — тот же, что публичный лендинг SuperAudit использует для бесплатного сканирования.
Разработка
npm install
npm run build # compila TypeScript → dist/В этой начальной версии нет автоматизированных тестов — проверка выполнялась
вручную с реальным MCP-клиентом (рукопожатие initialize + tools/list +
tools/call) против production-эндпоинта.
Available Tools
1 toolaudit_websiteAudita una web con SuperAuditA
Ejecuta una auditoría real y gratuita de SuperAudit sobre una web: SEO técnico, seguridad, cumplimiento legal (RGPD/LSSI), Core Web Vitals, accesibilidad, posicionamiento en IA generativa (GEO), WordPress/CVEs, y más de 25 módulos en total. Devuelve un score global de 0 a 100, el detalle por módulo y los principales problemas encontrados, priorizados. Útil para responder preguntas como '¿qué falla en la web de mi cliente?' o 'audita esta URL antes de contactarles'. Sujeto a un límite de uso justo (rate limit) en el servidor de SuperAudit.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | Dominio o URL a auditar, por ejemplo 'minegocio.es' o 'https://minegocio.es'. | |
| raw_json | No | Si es true, además del resumen legible incluye el JSON completo devuelto por SuperAudit (todos los módulos, scores y planes). Por defecto false para no saturar el contexto. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden, and it discloses important behavior: it is a real and free audit, it respects a fair-use rate limit on SuperAudit's server, and it returns a global score, per-module detail, and prioritized problems. It does not state explicit side-effect/safety information, but an audit is clearly presented as a non-mutating analysis, and the rate-limit caveat is a useful limitation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense but not bloated: the first sentence delivers the core purpose and scope, followed by the output format, use cases, and rate limit. Information is front-loaded and every clause earns its place, though the first sentence is long.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Despite having no output schema or annotations, the description covers what the tool does, what it returns, when to use it, and an operational constraint (rate limit). Combined with a fully documented input schema, an agent has enough context to invoke it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents 'url' and 'raw_json'. The description itself does not add parameter-specific detail; it only contextualizes the overall output. This meets the baseline but does not exceed it.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific action and object: 'Ejecuta una auditoría real y gratuita de SuperAudit sobre una web', and enumerates the audit areas (SEO técnico, seguridad, RGPD/LSSI, Core Web Vitals, accesibilidad, GEO, WordPress/CVEs). It also states the concrete return value (score 0-100, module details, prioritized issues). With no sibling tools to disambiguate, the purpose is fully identifiable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives concrete use cases: '¿qué falla en la web de mi cliente?' or 'audita esta URL antes de contactarles'. This makes the intended invocation context clear. There are no explicit exclusions or alternative tool routing, but no siblings are provided, so this is appropriate.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v1.0.0- First observed
audit_website
TDQS
Scored across 1 tool
Only one tool exists, so there is no ambiguity between tools. The single tool has a clear, distinct purpose around website auditing.
With a single tool, the naming is trivially consistent. 'audit_website' follows a clear verb_noun pattern.
A single tool feels thin and borderline for a server. It consolidates many audit checks into one call, but offers no auxiliary operations like listing or retrieving past audits.
The tool comprehensively covers the core audit workflow, including many modules. Minor gaps exist, such as no ability to fetch historical audits or compare results over time.
Maintenance
Related MCP Connectors
Find, compare, and audit software for AI agents. Scored registry of tools and MCP servers.
Turn any public website into an MCP server for agents to search, read and navigate.
Free public MCP for AI agents — 193 tools, 44 workflows. No API key.
- UnifAPIOAuthcom.unifapi
Hosted MCP server for live public-data APIs and Skills for AI agents.
Related MCP Servers
- AlicenseBqualityBmaintenanceMCP server that enables AI agents to perform comprehensive web audits using Google Lighthouse with 13+ tools for performance, accessibility, SEO, and security analysis.112,641 npm71MIT
- AlicenseNot gradedqualityNot gradedmaintenanceMCP server for website SEO + GEO analysis. Scan any URL to get scores across 5 categories (SEO, GEO, Performance, Security, Accessibility) with actionable fix recommendations. Enables AI coding assistants to audit websites and implement fixes autonomously.-
- AlicenseAqualityDmaintenanceA comprehensive MCP server providing 15 web tools including search, scraping, screenshots, SEO audits, and DNS/SSL checks through a single installation. It delivers clean, LLM-optimized outputs so AI agents can focus on reasoning rather than parsing raw HTML.1517 npmMIT
- AlicenseAqualityDmaintenanceEnables AI agents to perform comprehensive SEO audits on web pages, including meta tags, headings, links, images, performance, and more, via a CLI or MCP server.181MIT