Moonlings — Local Business Intelligence
REMOTE · MOONLINGS.AI · SCANNED SEP 20
AI visibility + fact-checks (ChatGPT/Perplexity), review gaps & competitor scans, local SEO.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 7 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1381 tokens (~172/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Moonlings — Local Business Intelligence MCP server?
Moonlings — Local Business Intelligence is a hosted endpoint at https://moonlings.ai/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · moonlings.ai
claude mcp add --transport http ai-moonlings-moonlings 'https://moonlings.ai/api/mcp'
{
"mcpServers": {
"ai-moonlings-moonlings": {
"url": "https://moonlings.ai/api/mcp"
}
}
} {
"servers": {
"ai-moonlings-moonlings": {
"type": "http",
"url": "https://moonlings.ai/api/mcp"
}
}
} [mcp_servers.ai-moonlings-moonlings] url = "https://moonlings.ai/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-moonlings-moonlings": {
"type": "remote",
"url": "https://moonlings.ai/api/mcp",
"enabled": true
}
}
} openclaw mcp add ai-moonlings-moonlings --url 'https://moonlings.ai/api/mcp' --transport streamable-http
mcp_servers:
ai-moonlings-moonlings:
url: "https://moonlings.ai/api/mcp" {
"McpServers": {
"ai-moonlings-moonlings": {
"Transport": "http",
"Url": "https://moonlings.ai/api/mcp"
}
}
} assistant mcp add ai-moonlings-moonlings -t streamable-http -u 'https://moonlings.ai/api/mcp'
{
"mcpServers": {
"ai-moonlings-moonlings": {
"type": "http",
"url": "https://moonlings.ai/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 23 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://moonlings.ai/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=moonlings.ai | CN=YR2,O=Let's Encrypt,C=US | 13 Aug 2026 | 11 Nov 2026 | RSA 2048 | SHA256-RSA | 5b408f9185bbedf063b6fd706657a840a26 |
| SANs: moonlings.ai | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of moonlings.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| moonlings.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://moonlings.ai/api/mcp | Verified | 200 | |
| http (plaintext) | http://moonlings.ai/api/mcp | HTTPS enforced | 308 | https://moonlings.ai/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_facts AI Fact-Check ~263
Find what AI assistants get WRONG about a local business. Asks ChatGPT and Perplexity live (with web search) about the business's hours, address, phone, and category, then verifies each stated fact against Google Business ground truth. Returns a severity-ranked list of conflicts (with the AI's value vs. the trusted value and source) plus discrepancies to check. Conservative by design: a claim with no trusted source is 'unverifiable' (never an error), and a conflict is only counted when it reproduces across engines — so it won't cry wolf. Call this when a user asks whether AI has the right info about a business, or 'why does ChatGPT say we're closed'. Takes ~15-30 seconds. Price: $1.49 per delivered check.
| Name | Type | Req | Description |
|---|---|---|---|
| businessName | string | yes | The local business to fact-check |
| businessType | string | – | Optional category anchor, e.g. "restaurant" — helps resolve the business; not required |
| location | string | yes | City and state/region, e.g. "Cincinnati, OH" |
| website | string | – | Optional: the business website — if an AI answer cites this domain, a mismatch is treated as a possibly-stale discrepancy rather than an error |
No output schema declared.
No examples provided.
check_report_status Check Report Status ~76
Poll a deep research report by slug. Free. Returns status (generating / ready / failed); a failed report triggers the automatic refund of its launch charge. Deep reports typically take 10-20 minutes — poll every few minutes, not every few seconds.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | The slug returned by start_deep_report |
No output schema declared.
No examples provided.
check_visibility AI Visibility Check ~212
Ask ChatGPT and Perplexity live (with web search) who they'd recommend in a business's category and city, and report whether THIS business appears. Returns honest appearance counts (never an invented metric), a per-engine split, who gets recommended instead, and which local sites the AI answers cite. AI answers vary substantially between runs — one check is a snapshot, not a stable measurement; re-check over time for the real picture. Call this when a user wants to know if AI assistants recommend a local business. Takes ~10-30 seconds. Price: $0.79 per delivered check.
| Name | Type | Req | Description |
|---|---|---|---|
| businessName | string | yes | The local business to check |
| businessType | string | yes | Category anchor, e.g. "gym" — the AI assistants are asked category questions, so this is required |
| location | string | yes | City and state/region, e.g. "Cincinnati, OH" |
| website | string | – | Optional: the business website — a cited domain counts as an appearance |
No output schema declared.
No examples provided.
get_report_result Get Report Result ~82
Fetch a completed deep research report by slug. Free. Returns the long-form report (markdown), a structured-findings JSON block, the action list, and the report card. If the report is still generating you get its status instead; if it failed, the launch charge is refunded automatically.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | The slug returned by start_deep_report |
No output schema declared.
No examples provided.
ping Ping Moonlings ~38
Returns server status, the price list, and (when authenticated) your credit balance. Free — call it to check connectivity and see what this server offers.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
review_gap Review Gap Check ~212
Compare a local business's Google rating and review count against the top same-category rivals nearby, with the gap math done: who leads, the rating delta, the review-volume ratio, and a verdict (leading / rated_equal_or_better_but_outreviewed / trailing). Live Google Maps lookup at call time. Call this when a user wants to know how a business's reviews stack up against local competitors. Takes a few seconds. Price: $0.39 per delivered comparison.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Optional: street address of the SPECIFIC location to compare, e.g. "332 Ludlow Ave" — use for chains/multi-location businesses so the right branch anchors the comparison |
| businessName | string | yes | The local business to check |
| businessType | string | yes | Category anchor, e.g. "dentist" — rivals are the top Google Maps results for this category nearby |
| location | string | yes | City and state/region, e.g. "Cincinnati, OH" |
No output schema declared.
No examples provided.
run_scan Competitor Quick Scan ~264
A live competitor scan: a research agent finds the business's strongest same-category rival nearby and scouts it (offer, pricing signals, review positioning, what they do that this business doesn't), while two ground-truth lookups run in parallel: ChatGPT/Perplexity sampling for AI-assistant visibility, and a direct Google Places review comparison (reviewSnapshot — the authoritative numbers; finding source URLs are verified against what the agent actually retrieved). The AI-visibility portion is a single-run snapshot — AI answers vary substantially between runs. BLOCKING and slow: typically 2-4 minutes — only call it from contexts that tolerate a long tool call. Price: $1.99 per delivered scan; a failed scan is never charged.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | Optional: street address of the SPECIFIC location to scan, e.g. "332 Ludlow Ave" — use for chains/multi-location businesses so the right branch anchors the review comparison |
| businessName | string | yes | The local business to scan |
| businessType | string | yes | Category anchor, e.g. "ice cream shop" — rival discovery and AI sampling are both category-anchored |
| location | string | yes | City and state/region, e.g. "Cincinnati, OH" |
No output schema declared.
No examples provided.
start_deep_report Start Deep Research Report ~234
Launch a full overnight-grade research report on a local business: an autonomous research crew maps the competitive landscape, reads the business's and rivals' web presence, and delivers a long-form graded report with structured findings and an action list. ASYNC: this tool returns a slug immediately; the report takes roughly 10-20 minutes. Poll check_report_status, then fetch with get_report_result. Price: $9.99, charged when the report launches; if the report fails, the charge is refunded automatically. Each call starts a NEW report — do not retry a call that already returned a slug.
| Name | Type | Req | Description |
|---|---|---|---|
| brief | string | – | Optional research focus, e.g. "we're losing weekend foot traffic — figure out why" |
| businessName | string | yes | The local business to research |
| businessType | string | yes | Category anchor, e.g. "dentist" — competitor discovery is category-anchored |
| location | string | yes | City and state/region, e.g. "Cincinnati, OH" |
| website | string | – | Optional: the business website, read to ground services and positioning |
No output schema declared.
No examples provided.
What is the Moonlings — Local Business Intelligence MCP server?
Moonlings — Local Business Intelligence is an MCP server listed in the public MCP registry as ai.moonlings/moonlings. AI visibility + fact-checks (ChatGPT/Perplexity), review gaps & competitor scans, local SEO. This page covers its hosted endpoint (https://moonlings.ai/api/mcp).
Is the Moonlings — Local Business Intelligence MCP server safe to use?
Moonlings — Local Business Intelligence scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Moonlings — Local Business Intelligence MCP server expose?
Moonlings — Local Business Intelligence exposes 8 tools: ping, check_visibility, review_gap, check_facts, run_scan, and 3 more. Their descriptions and schemas cost roughly 1,381 tokens of context every time the server is loaded.
Does the Moonlings — Local Business Intelligence MCP server require authentication?
No. We connected to Moonlings — Local Business Intelligence without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Moonlings — Local Business Intelligence MCP server still maintained?
Moonlings — Local Business Intelligence is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.