websec-auditor
by sheiscypher
README.md
# Website Trust & Exposure Auditor
Passive, non-intrusive Website Trust & Exposure Auditor tool connected to Claude Desktop via MCP.
š **Live dashboard** ā [sheiscypher.github.io/websec-search-auditor](https://sheiscypher.github.io/websec-search-auditor/)
**Main command:**
```
audit https://example.com
```
Produces: global score, risk prioritisation, remediation plan, HTML report, business impact, technical evidence.
---
## Audit modules
| Module | Checks |
|---|---|
| Security | HTTP Headers, TLS, Exposed Files, CMS + CVE |
| SEO | Meta tags, E-E-A-T, JSON-LD, Technical SEO |
| AI Surface | llms.txt, AI crawlers, MCP endpoint |
| Email | SPF, DKIM, DMARC |
| Vibe Coding Risk | 15 signals of AI-developed code without security review |
| GDPR / RGPD | CMP, Trackers, Legal pages |
| Supply Chain | JS Libraries, CDN, SRI |
| Accessibility | WCAG / RGAA |
| DNS Security | DNSSEC, CAA |
| Secrets Exposure | API Keys, JWT, Sensitive files |
---
## Local installation (Claude Desktop)
```bash
git clone https://github.com/sheiscypher/websec-search-auditor
cd websec-search-auditor
pip install -r requirements.txt
cp .env.example .env
# Fill in .env if needed
```
Add to `~/Library/Application Support/Claude/claude_desktop_config.json`:
```json
{
"mcpServers": {
"websec-auditor": {
"command": "python",
"args": ["/absolute/path/to/websec-search-auditor/server.py"],
"env": {}
}
}
}
```
Restart Claude Desktop. Type `audit https://yoursite.com`.
---
## Deployment
### Backend (Render)
1. Create a Web Service on [render.com](https://render.com)
2. Connect this GitHub repo
3. Render auto-detects `render.yaml`
4. Add `JWT_SECRET` env variable in Render Dashboard
5. Optional: `NVD_API_KEY` for CVE lookups
### Dashboard (GitHub Pages)
1. Go to **Settings > Pages** in the repo
2. Source: **GitHub Actions**
3. Add `VITE_API_URL` variable in **Settings > Environments > github-pages**
4. Build triggers automatically on every push to `main`
---
## Security
- **Passive audit only** ā no modification of the target site
- Built-in SSRF protection
- Built-in indirect prompt injection protection
- 28/28 security tests passing
---
## Licence
AGPL v3 ā see [SPEC-LICENSE](./SPEC-LICENSE)
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessSyncing