Skip to main content
Glama
Jorucmor

superaudit-mcp

by Jorucmor

superaudit-mcp

MCP(模型上下文协议)服务器,将 SuperAudit 真实且免费的审计功能暴露为一个工具,任何兼容 MCP 的 AI 代理都可以调用。

这样,外部开发者可以让自己的代理(Claude 或其他 MCP 客户端)做诸如"用 SuperAudit 审计这个网站"的事情,而无需与 SuperAudit 团队中的任何人沟通——该工具直接调用公共生产端点。

功能

暴露一个单一工具:audit_website。

  • 输入:

    • url(必填):要审计的域名或 URL,例如 "minegocio.es" 或 "https://minegocio.es"。

    • raw_json(可选,boolean,默认 false):如果为 true,除了可读摘要外,还返回 SuperAudit 提供的完整 JSON(所有模块、所有评分、所有方案)。

  • 内部功能: 调用 POST https://superaudit.airpagents.pro/api/quick-audit,参数为 { "web": "<url>" }——与 SuperAudit 落地页目前用于免费扫描的公共端点相同。不需要任何密钥或令牌。

  • 输出: 文本摘要,包含总体得分(0-100)、约 27 个模块中每个模块的评分(SEO、安全性、法律/RGPD、Core Web Vitals、WCAG 可访问性、生成式 AI 中的排名、WordPress/CVE、OWASP Top 10 等)、检测到的主要问题以及 SuperAudit 根据结果推荐的付费方案。

Related MCP server: foglift-mcp

已知限制(重要)

  • 公共端点在 SuperAudit 服务器上设有每 IP 每分钟 10 次请求的限制。如果超出限制,该工具会返回错误提示——不会自动重试,以免使服务过载。

  • 后端会将每个已审计的域名缓存 24 小时,因此在短时间内重新审计同一网站是即时的。

  • "冷"审计(未缓存的域名)可能需要好几秒:客户端会等待最多 90 秒,然后才将尝试判定为失败。

  • 后端会验证 URL 指向真实的公共域名(阻止私有 IP/localhost 作为 SSRF 防护措施)——如果网站不存在或不在线,该工具会返回可读的错误,而不是静默失败。

安装(适用于外部开发者)

要求:Node.js 18 或更高版本。

git clone <este repositorio>   # o simplemente copia esta carpeta
cd superaudit-mcp
npm install
npm run build

这会生成 dist/index.js,即 MCP 服务器的二进制文件(通过 stdio 通信,这是 MCP 的标准传输方式)。

单独测试(可选)

npm run build
node dist/index.js

进程会停留在 stdio 上等待——这是正常的,MCP 服务器就是这样工作的。它从 MCP 客户端连接,不作为交互式 CLI 使用。

如何连接到 MCP 客户端

Claude Code

claude mcp add superaudit -- node "/ruta/completa/a/superaudit-mcp/dist/index.js"

Claude Desktop

编辑 Claude Desktop 的配置文件(claude_desktop_config.json)并添加:

{
  "mcpServers": {
    "superaudit": {
      "command": "node",
      "args": ["/ruta/completa/a/superaudit-mcp/dist/index.js"]
    }
  }
}

重启 Claude Desktop。工具 audit_website 将变为可用,代理可以在对话需要时使用它(例如"用 SuperAudit 审计 minegocio.es")。

任何其他 MCP 客户端

任何支持通过 stdio 运行 MCP 服务器的客户端都可以将 node dist/index.js 作为服务器命令启动——不需要额外配置或环境变量。

环境变量(可选)

  • SUPERAUDIT_BASE_URL:默认值为 https://superaudit.airpagents.pro。只有在指向自己的测试环境时才有必要更改。

不需要任何 API 密钥:此工具使用的端点与 SuperAudit 公共落地页用于免费扫描的端点相同。

开发

npm install
npm run build   # compila TypeScript → dist/

这个初始交付物中没有自动化测试——已使用真实的 MCP 客户端手动验证(握手 initialize + tools/list

  • tools/call)针对生产端点。

Available Tools

1 tool
audit_websiteAudita una web con SuperAuditA

Ejecuta una auditoría real y gratuita de SuperAudit sobre una web: SEO técnico, seguridad, cumplimiento legal (RGPD/LSSI), Core Web Vitals, accesibilidad, posicionamiento en IA generativa (GEO), WordPress/CVEs, y más de 25 módulos en total. Devuelve un score global de 0 a 100, el detalle por módulo y los principales problemas encontrados, priorizados. Útil para responder preguntas como '¿qué falla en la web de mi cliente?' o 'audita esta URL antes de contactarles'. Sujeto a un límite de uso justo (rate limit) en el servidor de SuperAudit.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlYesDominio o URL a auditar, por ejemplo 'minegocio.es' o 'https://minegocio.es'.
raw_jsonNoSi es true, además del resumen legible incluye el JSON completo devuelto por SuperAudit (todos los módulos, scores y planes). Por defecto false para no saturar el contexto.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden, and it discloses important behavior: it is a real and free audit, it respects a fair-use rate limit on SuperAudit's server, and it returns a global score, per-module detail, and prioritized problems. It does not state explicit side-effect/safety information, but an audit is clearly presented as a non-mutating analysis, and the rate-limit caveat is a useful limitation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but not bloated: the first sentence delivers the core purpose and scope, followed by the output format, use cases, and rate limit. Information is front-loaded and every clause earns its place, though the first sentence is long.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having no output schema or annotations, the description covers what the tool does, what it returns, when to use it, and an operational constraint (rate limit). Combined with a fully documented input schema, an agent has enough context to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents 'url' and 'raw_json'. The description itself does not add parameter-specific detail; it only contextualizes the overall output. This meets the baseline but does not exceed it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific action and object: 'Ejecuta una auditoría real y gratuita de SuperAudit sobre una web', and enumerates the audit areas (SEO técnico, seguridad, RGPD/LSSI, Core Web Vitals, accesibilidad, GEO, WordPress/CVEs). It also states the concrete return value (score 0-100, module details, prioritized issues). With no sibling tools to disambiguate, the purpose is fully identifiable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives concrete use cases: '¿qué falla en la web de mi cliente?' or 'audita esta URL antes de contactarles'. This makes the intended invocation context clear. There are no explicit exclusions or alternative tool routing, but no siblings are provided, so this is appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev1.0.0
    • First observedaudit_website

TDQS

A4.2/5.0

Scored across 1 tool

Disambiguation5/5

Only one tool exists, so there is no ambiguity between tools. The single tool has a clear, distinct purpose around website auditing.

Naming Consistency5/5

With a single tool, the naming is trivially consistent. 'audit_website' follows a clear verb_noun pattern.

Tool Count3/5

A single tool feels thin and borderline for a server. It consolidates many audit checks into one call, but offers no auxiliary operations like listing or retrieving past audits.

Completeness4/5

The tool comprehensively covers the core audit workflow, including many modules. Minor gaps exist, such as no ability to fetch historical audits or compare results over time.

Maintenance

ActivitySlowing
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    B
    maintenance
    MCP server that enables AI agents to perform comprehensive web audits using Google Lighthouse with 13+ tools for performance, accessibility, SEO, and security analysis.
    11
    2,641 npm
    71
    MIT
  • A
    license
    Not graded
    quality
    Not graded
    maintenance
    MCP server for website SEO + GEO analysis. Scan any URL to get scores across 5 categories (SEO, GEO, Performance, Security, Accessibility) with actionable fix recommendations. Enables AI coding assistants to audit websites and implement fixes autonomously.
    -
  • A
    license
    A
    quality
    D
    maintenance
    A comprehensive MCP server providing 15 web tools including search, scraping, screenshots, SEO audits, and DNS/SSL checks through a single installation. It delivers clean, LLM-optimized outputs so AI agents can focus on reasoning rather than parsing raw HTML.
    15
    17 npm
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables AI agents to perform comprehensive SEO audits on web pages, including meta tags, headings, links, images, performance, and more, via a CLI or MCP server.
    18
    1
    MIT