squirrelscan
REMOTE · MCP.SQUIRRELSCAN.COM · SCANNED AUG 3
Website QA for your coding agent: audit SEO, performance, security, accessibility over MCP.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security81
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS not yet verified: we couldn't determine whether a plaintext access path exists. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2843 tokens (~167/item across 17 items; 17 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.squirrelscan.com
claude mcp add --transport http com-squirrelscan-squirrelscan https://mcp.squirrelscan.com/mcp
[mcp_servers.com-squirrelscan-squirrelscan] url = "https://mcp.squirrelscan.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-squirrelscan-squirrelscan": {
"type": "remote",
"url": "https://mcp.squirrelscan.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-squirrelscan-squirrelscan --url https://mcp.squirrelscan.com/mcp --transport streamable-http
mcp_servers:
com-squirrelscan-squirrelscan:
url: "https://mcp.squirrelscan.com/mcp" {
"mcpServers": {
"com-squirrelscan-squirrelscan": {
"type": "http",
"url": "https://mcp.squirrelscan.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 2 Aug 26 −6
- HTTPS: pass → unverified ▼ security
- HSTS header: pass → fail ▼ security
- 31 Jul 26 +6
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 28 Jul 26 +62
- Authorization: unverified → pass ▲ security
- HTTPS: unverified → pass ▲ security
- HSTS header: fail → pass ▲ security
- Transport: fail → pass ▲ security
- MCP protocol: unverified → pass ▲ functional
- Stability: unverified → 0.07 ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- 27 Jul 26 −56
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 68
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://mcp.squirrelscan.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=squirrelscan.com | CN=WE1,O=Google Trust Services,C=US | 1 Aug 2026 | 30 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | baab9f782db334270e5b08cc1bb103d4 |
| SANs: squirrelscan.com, *.squirrelscan.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC insecure
Validation of mcp.squirrelscan.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| squirrelscan.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer error="invalid_token", error_description="Authentication required. Pass a squirrelscan API key as a Bearer token.", resource_metadata="https://mcp.squirrelscan.com/.well-known/oauth-protected-resource"
Bearer error="invalid_token", error_description="Authentication required. Pass a squirrelscan API key as a Bearer token.", resource_metadata="https://mcp.squirrelscan.com/.well-known/oauth-protected-resource" Protected resource metadata
| Document | https://mcp.squirrelscan.com/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.squirrelscan.com/mcp |
| Authorisation server | https://mcp.squirrelscan.com |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.squirrelscan.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.squirrelscan.com/mcp | Inconclusive | 401 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
add_website Add a website ~82
Register a website with the organization without running an audit (run_audit registers automatically, so this is only needed to set a site up ahead of time). Returns the website_id; idempotent per domain, so calling it again returns the existing website.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | Website URL to register, e.g. https://example.com (scheme optional). |
No output schema declared.
No examples provided.
comment_on_issue Comment on an issue ~87
Post a comment on a website issue — use it to record analysis, a proposed fix, or what you changed, so the team sees it in the dashboard issue thread. Markdown is supported.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Comment body (markdown supported). |
| issue_number | integer | yes | Issue number from list_issues. |
| website_id | string | yes | Website id the issue belongs to. |
No output schema declared.
No examples provided.
create_api_key Create an API key ~183
Mint a new squirrelscan API key for this organization (requires credentials carrying the keys:write scope, which OAuth sign-in grants). The key is returned EXACTLY ONCE: show it to the user immediately and suggest saving it as the SQUIRRELSCAN_API_KEY environment variable for the CLI, CI, and MCP. Minted keys cannot themselves mint keys.
| Name | Type | Req | Description |
|---|---|---|---|
| expires_in_days | integer | — | Expire the key after this many days (default: never expires). |
| name | string | yes | Human-readable label shown in the dashboard, e.g. "ci" or "claude-code". |
| scopes | array | — | Scopes to grant (default: audits:write, audits:read, credits:read, org:read). Grantable: audits:write, audits:read, credits:read, org:read, org:write. |
No output schema declared.
No examples provided.
delete_website Delete a website ~137
Delete a website from the organization (soft delete: past audits, reports, and issues are preserved, and published report links keep working). Frees a slot under the plan's website limit. Re-adding the same domain later registers a fresh website with a new website_id. Call once without confirm to see what will happen; call again with confirm: true to delete.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | — | Approve the deletion. Omit on the first call to see the effect; set true to delete after the user approves. |
| website_id | string | yes | Website id from list_websites, run_audit, or add_website. |
No output schema declared.
No examples provided.
get_audit_status Get audit status ~113
Poll a running audit by run_id (from run_audit or list_audits). Status pending/running means keep polling (every 15-30 seconds) — the response includes a progress field (phase, message, page/link counts) when available. Status completed means the report is ready: call get_report with the same run_id. Status failed/cancelled includes the error and completion reason.
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | Run id returned by run_audit or listed by list_audits. |
No output schema declared.
No examples provided.
get_credit_balance Get credit balance ~69
Get the organization's credit balance: monthly credits (reset each billing period) and pack credits (purchased, never expire). Audits spend credits pay-as-you-go while they run; run_audit shows an upper-bound estimate before starting. Top up at https://app.squirrelscan.com/billing.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_issue Get issue detail ~112
Fetch one issue by website_id + issue number, including its full description, recommendation, affected pages, occurrence detail from the latest report (which page/image/URL, snippets), and comment thread. Use comment_on_issue to add analysis or a fix note to the thread.
| Name | Type | Req | Description |
|---|---|---|---|
| issue_number | integer | yes | Issue number from list_issues. |
| occurrence_limit | integer | — | Max occurrences to include (default 20); see occurrence_count/truncated. |
| website_id | string | yes | Website id the issue belongs to. |
No output schema declared.
No examples provided.
get_report Get audit report ~321
Fetch the finished report for an audit run (use the run_id from run_audit once get_audit_status shows completed). Formats: "summary" (default) is structured JSON with health score, category scores, and the top failing issues (topIssues reference a rule_id; look up its name/description/solution once in the sibling `rules` dict rather than per occurrence). Each topIssues row carries `provenance`: "carried" means the finding is re-injected from a page not re-crawled this run (not a fresh result) — check `lastSeenAt` for when it was last actually observed. `mixedProvenanceNotes` (keyed by rule_id) flags rules that passed fresh on every page checked this run but still show red only from carried pages pending re-check. Also includes a `history` array of prior audits of this website with score/issue deltas when available; "llm" is a compact text rendering optimized for LLM context (carried findings marked inline); "markdown" is a full human-readable report. Start with summary, then pull llm or markdown when you need every issue and page detail.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | — | summary (default): JSON scores + top issues. llm: compact text for LLM context. markdown: full report. |
| run_id | string | yes | Run id returned by run_audit or listed by list_audits. |
| top_issue_limit | integer | — | summary format only: max top issues to include (default 25). |
No output schema declared.
No examples provided.
get_rule Get rule detail ~93
Fetch one audit rule by id (e.g. "meta/title-length"), including what it checks, how to fix it (recommendation), its severity and score weight, a docs link, and whether it is a cloud (credit-billed) rule. Rule ids appear in report topIssues and issue rule_id fields.
| Name | Type | Req | Description |
|---|---|---|---|
| rule_id | string | yes | Rule id like "crawl/canonical-chain" (category/slug). |
No output schema declared.
No examples provided.
list_audits List audits ~69
List the organization's audit runs: currently active (pending/running) plus the most recent runs of any status. Use the run ids with get_audit_status or get_report, and website ids with list_issues.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Max recent runs to return (default 20). |
No output schema declared.
No examples provided.
list_credit_transactions List credit transactions ~153
Audit the organization's credit accounting log: grants (signup/monthly/pack/promo), debits (audit_base 50cr + render 2cr/page + folded 0-cost services), refunds, and adjustments — newest first, paginated. Each debit/refund carries `run_id` so you can group a single audit's spend. Use this to explain why an audit cost what it cost or to reconcile a balance. For one audit's per-feature breakdown, use get_report (its `cost` field). Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque pagination cursor from a previous page's `next_cursor`. |
| limit | integer | — | Max transactions to return (default 25, max 100). |
No output schema declared.
No examples provided.
list_issues List website issues ~169
List a website's open audit issues (like a bug tracker: each issue is one failing rule with occurrences across pages, numbered per website). Returns issues sorted by severity, plus severity and status summaries. Use the issue number with get_issue for full detail and comments. Filter by status/severity/category to narrow down.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | — | Filter by rule category code (e.g. seo, performance, security). |
| limit | integer | — | Page size (default 50). |
| offset | integer | — | Pagination offset (default 0). |
| severity | string | — | Filter by severity. |
| status | string | — | Filter by issue status (omit for all statuses). |
| website_id | string | yes | Website id from list_websites, run_audit, or list_audits. |
No output schema declared.
No examples provided.
list_rules List audit rules ~110
Browse the catalog of 260+ audit rules that run during an audit, grouped into categories (crawlability, meta tags, performance, security, accessibility, content, and more). Filter by category code or search by keyword to find what a specific rule checks. Use get_rule for one rule's full detail.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | — | Filter to one category code (see the categories list in the response). |
| search | string | — | Case-insensitive keyword match on rule id, name, and description. |
No output schema declared.
No examples provided.
list_websites List websites ~91
List websites the organization has audited, with their latest run status and health score. Use the website_id with list_issues/get_issue. Websites registered but never audited do not appear; run_audit or add_website registers a new one. Returns total/has_more for pagination.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Page size (default 50). |
| offset | integer | — | Pagination offset (default 0). |
No output schema declared.
No examples provided.
run_audit Run a cloud audit ~243
Run a cloud audit of a website (crawl + 260+ rule analysis + report). Credits are spent as the audit runs (pay-as-you-go). Call once without confirm to get a credit estimate; if the response has status "confirmation_required", show the estimate to the user and call again with confirm: true. Audits are asynchronous and take minutes: poll get_audit_status with the returned run_id, then fetch results with get_report. The website is registered automatically on first audit.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | — | Approve the credit spend. Omit on the first call to see the estimate; set true to start the audit after the user approves. |
| coverage | string | — | Crawl coverage profile (default fast). Deeper coverage crawls more pages and costs more credits. |
| max_credits | integer | — | Spend guard: refuse to start if the upper-bound estimate exceeds this many credits. |
| render | boolean | — | Render pages in a headless browser (default true). Catches JavaScript-dependent issues; costs extra credits per page. |
| url | string | yes | Website URL to audit, e.g. https://example.com (scheme optional). |
No output schema declared.
No examples provided.
send_feedback Send feedback ~249
Report your experience using squirrelscan mid-session: a bug, a missing feature, what worked, what confused you, missing report data, or tool ergonomics. Reviewed by the team to improve the product — use it any time something surprises you, not just at the end of a session. Works with any authenticated credentials, including read-only API keys.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | bug_report (a defect in squirrelscan itself — wrong or missing rule result, crash, broken tool), feature_request (something squirrelscan should do but doesn't), what_worked (something worked well), c… |
| message | string | yes | Free-text feedback (truncated at 2000 chars). |
| run_id | string | — | Audit run id this feedback relates to, if any (from run_audit/get_report). Verified against your credentials' runs before being attached. |
| website_id | string | — | Website id this feedback relates to, if any (from list_websites). Verified against your org's websites before being attached. |
No output schema declared.
No examples provided.
whoami Who am I ~46
Identify the current credentials: how you are authenticated, which organization you act for, the plan, and the current credit balance. Call this first in a session to orient yourself before running audits.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.