com.groundedaeo/grounded-aeo
REMOTE · GROUNDEDAEO.COM · SCANNED AUG 3
Audit and fix a site for AI citation + SEO, verify it, then publish a v=AEO1 record.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 14 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability62
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 2270 tokens (~162/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage87
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 60% of tool parameters carry a description.Partial
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · groundedaeo.com
claude mcp add --transport http com-groundedaeo-grounded-aeo https://groundedaeo.com/api/mcp
[mcp_servers.com-groundedaeo-grounded-aeo] url = "https://groundedaeo.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-groundedaeo-grounded-aeo": {
"type": "remote",
"url": "https://groundedaeo.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add com-groundedaeo-grounded-aeo --url https://groundedaeo.com/api/mcp --transport streamable-http
mcp_servers:
com-groundedaeo-grounded-aeo:
url: "https://groundedaeo.com/api/mcp" {
"mcpServers": {
"com-groundedaeo-grounded-aeo": {
"type": "http",
"url": "https://groundedaeo.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “check_aeo_record” rewrote its description, which is the text the model reads security
- Tool “check_serp” rewrote its description, which is the text the model reads security
- Tool “get_company_facts” rewrote its description, which is the text the model reads security
- Tool “get_competitive_snapshot” rewrote its description, which is the text the model reads security
- Tool “get_llms_txt” rewrote its description, which is the text the model reads security
- Tool “propose_briefs” rewrote its description, which is the text the model reads security
- Tool “run_audit” rewrote its description, which is the text the model reads security
- Schema quality: 1532 → 2270 ▼ functional
- Tool coverage: 50% → 60% ▲ functional
- New tool “get_citations” functional
- New tool “get_cited_domains” functional
- New tool “get_engine_visibility” functional
- New tool “get_keyword_gap” functional
- 2 Aug 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 125 → 153 ▼ functional
- Tool coverage: 38% → 50% ▲ functional
- New tool “propose_briefs” functional
- New tool “check_serp” functional
- New tool “get_competitive_snapshot” functional
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 −1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 58
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://groundedaeo.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=groundedaeo.com | CN=YE1,O=Let's Encrypt,C=US | 3 Jul 2026 | 1 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 53758d3570584468b9644f9b77e515fbb84 |
| SANs: groundedaeo.com, www.groundedaeo.com | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of groundedaeo.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| groundedaeo.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
| x-content-type-options | nosniff |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://groundedaeo.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://groundedaeo.com/api/mcp | HTTPS enforced | 301 | https://groundedaeo.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
check_aeo_record ~80
Check any domain (cataloged or not) for a v=AEO1 DNS record at _aeo.<domain>, the open standard (aeorecord.org) declaring whether a verified fact record exists and at what trust tier. Verifies the Ed25519 sig= against the live catalog content when present.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | — |
No output schema declared.
No examples provided.
check_serp ~115
Check the live Google search results for any keyword: the top 10 organic results (rank, domain, title), the People Also Ask questions, related searches, and which non-organic blocks occupy the page, so you can tell whether a query has an AI Overview or local pack slot at all. Public data, no catalog entry required. A keyword with genuinely no results returns empty arrays, which is a real finding, not an error.
| Name | Type | Req | Description |
|---|---|---|---|
| keyword | string | yes | Search query, e.g. "roof repair denver" |
No output schema declared.
No examples provided.
generate_free_record ~142
FINAL STEP of making a site AI-citable: generate a free, self-declared v=AEO1 DNS record and .well-known/aeo.json the user publishes on their own domain, so AI engines can verify the facts came from the owner rather than a scrape. Returns the exact TXT record and JSON file with publishing instructions. No crawl, no verification, no account. WRITE action, rate-limited to 10/hour per caller.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | — | — |
| category | string | — | — |
| domain | string | yes | — |
| hours | string | — | — |
| name | string | yes | Business name |
| services | array | — | — |
No output schema declared.
No examples provided.
get_citations ~131
Get the latest citation check per (question, engine) for a cataloged domain: the question asked, the engine, whether the answer cited this domain, the URL of theirs it cited, and the day checked. Claimed domains only, read-only, one row per cell so re-running the checker cannot inflate anything. The engine answers are stored verbatim as the evidence behind each verdict but are NOT served here; the owner sees those in their dashboard. An empty list means no check has run yet, never "never cited".
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain, e.g. acme.com |
No output schema declared.
No examples provided.
get_cited_domains ~137
Get who the answers cited instead: the domains that appeared in the stored answers for a cataloged domain's tracked questions, ranked by how many answers cited them, with the engines that did. Claimed domains only. An appearance means a domain was cited by an answer we asked for: not an endorsement, not a quality ranking, not a claim that an engine prefers it. One appearance per answer however many of that site's pages it cited, latest check per cell only, and answers with no captured evidence contribute nothing rather than counting as "cited nobody".
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain, e.g. acme.com |
No output schema declared.
No examples provided.
get_company_facts ~70
Get the verified fact record for a company by domain from the Grounded AEO catalog. Returns the published (approved) facts with verification state and confidence: the data an AI agent should ground answers about this business on.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain, e.g. acme.com |
No output schema declared.
No examples provided.
get_competitive_snapshot ~119
Get the latest competitive intelligence for a cataloged domain: the owner's most recent ranking-footprint snapshot, the AI-prompt vs Google demand table for its watched keywords, and each tracked competitor with their own latest snapshot. Read-only. Only domains whose owner has claimed them are exposed; anything else returns found:false. Counts are ranking FOOTPRINT, never traffic, and every volume is a modelled estimate. A null means no estimate has been collected, never zero.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain, e.g. acme.com |
No output schema declared.
No examples provided.
get_engine_visibility ~129
Get the per-engine picture for a cataloged domain: whether each AI engine's crawler is allowed by robots.txt to read the site at all, and how many of the tracked questions that engine cited it on. Claimed domains only. Nothing is assumed: an engine with no crawl measurement reports can_read:null ("not measured", never an assumed allow), and an engine with no citation checks reports cited/tracked null ("untested", never a miss and never zero). Access and citations only: this says nothing about traffic.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain, e.g. acme.com |
No output schema declared.
No examples provided.
get_fact ~55
Get a single verified fact for a company by domain and fact key (e.g. "tagline", "description").
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | — |
| key | string | yes | Fact key, e.g. "tagline" |
No output schema declared.
No examples provided.
get_keyword_gap ~146
Get the keyword gap for a cataloged domain: phrases a tracked competitor holds a position for in our stored captures where this domain holds none ("absent"), or holds one at least 20 places further back ("behind"). Claimed domains only, computed from captures already on disk. Nothing is fetched and nothing is spent. The stored lists are a SAMPLE of each domain's footprint (the top rows a capture kept), so absence here is absence from our sample, never from public search; the response carries that sentence and it must be repeated wherever the result is shown. Positions are ranking footprint, never traffic.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain, e.g. acme.com |
No output schema declared.
No examples provided.
get_llms_txt ~40
Get the auto-generated llms.txt for a cataloged company: a curated, AI-readable guide to the business.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | — |
No output schema declared.
No examples provided.
propose_briefs ~191
Propose ranked content briefs for a cataloged domain, built from data already collected for it: tracked questions where the answer did not cite them, keywords with AI-prompt demand no tracked question covers, People Also Ask questions nothing answers, and terms asked far more of AI assistants than of Google. Each brief names the exact question to answer, a format (9:16 UGC video, on-site answer, or short post), an outline, and the ONLY claims that may be made: the owner's published verified facts, verbatim. Deterministic and read-only: no new data is fetched and nothing is generated, so a brief with no evidence behind it is never returned. Claimed domains only; up to 6 briefs; an empty list means there is not yet enough collected data, never that there is no opportunity.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain, e.g. acme.com |
No output schema declared.
No examples provided.
run_audit ~183
Audit AND FIX a site for AI citation + SEO. Crawls the domain, scores AI-readability 0-10, checks for a v=AEO1 record, and returns the material needed to FIX it: `seoReport.headSnippet` is ready-to-paste <head> markup (title, meta description, Organization JSON-LD) and `setup_prompt` is a step-by-step plan covering llms.txt, structured data, and AI-crawler access, plus a ranked list of gaps. Use it to build the fixes, apply them to the site, then CALL THIS AGAIN to verify the score improved and the gaps cleared. WRITE action (queues extracted facts, unverified until a human approves). Free, no account, rate-limited to 5/hour per caller.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to audit, e.g. acme.com |
No output schema declared.
No examples provided.
search_catalog ~44
Search the Grounded AEO catalog by company name or domain. Returns up to 10 matches with tier and verification state.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Name or domain fragment |
No output schema declared.
No examples provided.