Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

squirrelscan

REMOTE · MCP.SQUIRRELSCAN.COM · SCANNED AUG 3

Website QA for your coding agent: audit SEO, performance, security, accessibility over MCP.

+64 this week 76 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security81
Transport & Reachability100
Schema Quality & AI Usability72
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2843 tokens (~167/item across 17 items; 17 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · mcp.squirrelscan.com

# add to Claude Code
claude mcp add --transport http com-squirrelscan-squirrelscan https://mcp.squirrelscan.com/mcp
# ~/.codex/config.toml
[mcp_servers.com-squirrelscan-squirrelscan]
url = "https://mcp.squirrelscan.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-squirrelscan-squirrelscan": {
      "type": "remote",
      "url": "https://mcp.squirrelscan.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-squirrelscan-squirrelscan --url https://mcp.squirrelscan.com/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-squirrelscan-squirrelscan:
    url: "https://mcp.squirrelscan.com/mcp"
// mcp.json
{
  "mcpServers": {
    "com-squirrelscan-squirrelscan": {
      "type": "http",
      "url": "https://mcp.squirrelscan.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 2 Aug 26 −6
    • HTTPS: pass → unverified security
    • HSTS header: pass → fail security
  • 31 Jul 26 +6
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 28 Jul 26 +62
    • Authorization: unverified → pass security
    • HTTPS: unverified → pass security
    • HSTS header: fail → pass security
    • Transport: fail → pass security
    • MCP protocol: unverified → pass functional
    • Stability: unverified → 0.07 functional
    • Tool coverage: unverified → 100 functional
  • 27 Jul 26 −56
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 68

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://mcp.squirrelscan.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=squirrelscan.com CN=WE1,O=Google Trust Services,C=US 1 Aug 2026 30 Oct 2026 ECDSA 256 ECDSA-SHA256 baab9f782db334270e5b08cc1bb103d4
SANs: squirrelscan.com, *.squirrelscan.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b
DNSSEC insecure

Validation of mcp.squirrelscan.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
squirrelscan.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer error="invalid_token", error_description="Authentication required. Pass a squirrelscan API key as a Bearer token.", resource_metadata="https://mcp.squirrelscan.com/.well-known/oauth-protected-resource"

Bearer error="invalid_token", error_description="Authentication required. Pass a squirrelscan API key as a Bearer token.", resource_metadata="https://mcp.squirrelscan.com/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://mcp.squirrelscan.com/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://mcp.squirrelscan.com/mcp
Authorisation server https://mcp.squirrelscan.com
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.squirrelscan.com/mcp Verified 200
http (plaintext) http://mcp.squirrelscan.com/mcp Inconclusive 401
MCP tools — 17 exposed · ~2,327 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
add_website ~82

Register a website with the organization without running an audit (run_audit registers automatically, so this is only needed to set a site up ahead of time). Returns the website_id; idempotent per domain, so calling it again returns the existing website.

NameTypeReqDescription
urlstringyesWebsite URL to register, e.g. https://example.com (scheme optional).

No output schema declared.

No examples provided.

comment_on_issue ~87

Post a comment on a website issue — use it to record analysis, a proposed fix, or what you changed, so the team sees it in the dashboard issue thread. Markdown is supported.

NameTypeReqDescription
bodystringyesComment body (markdown supported).
issue_numberintegeryesIssue number from list_issues.
website_idstringyesWebsite id the issue belongs to.

No output schema declared.

No examples provided.

create_api_key ~183

Mint a new squirrelscan API key for this organization (requires credentials carrying the keys:write scope, which OAuth sign-in grants). The key is returned EXACTLY ONCE: show it to the user immediately and suggest saving it as the SQUIRRELSCAN_API_KEY environment variable for the CLI, CI, and MCP. Minted keys cannot themselves mint keys.

NameTypeReqDescription
expires_in_daysintegerExpire the key after this many days (default: never expires).
namestringyesHuman-readable label shown in the dashboard, e.g. "ci" or "claude-code".
scopesarrayScopes to grant (default: audits:write, audits:read, credits:read, org:read). Grantable: audits:write, audits:read, credits:read, org:read, org:write.

No output schema declared.

No examples provided.

delete_website ~137

Delete a website from the organization (soft delete: past audits, reports, and issues are preserved, and published report links keep working). Frees a slot under the plan's website limit. Re-adding the same domain later registers a fresh website with a new website_id. Call once without confirm to see what will happen; call again with confirm: true to delete.

NameTypeReqDescription
confirmbooleanApprove the deletion. Omit on the first call to see the effect; set true to delete after the user approves.
website_idstringyesWebsite id from list_websites, run_audit, or add_website.

No output schema declared.

No examples provided.

get_audit_status ~113

Poll a running audit by run_id (from run_audit or list_audits). Status pending/running means keep polling (every 15-30 seconds) — the response includes a progress field (phase, message, page/link counts) when available. Status completed means the report is ready: call get_report with the same run_id. Status failed/cancelled includes the error and completion reason.

NameTypeReqDescription
run_idstringyesRun id returned by run_audit or listed by list_audits.

No output schema declared.

No examples provided.

get_credit_balance ~69

Get the organization's credit balance: monthly credits (reset each billing period) and pack credits (purchased, never expire). Audits spend credits pay-as-you-go while they run; run_audit shows an upper-bound estimate before starting. Top up at https://app.squirrelscan.com/billing.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_issue ~112

Fetch one issue by website_id + issue number, including its full description, recommendation, affected pages, occurrence detail from the latest report (which page/image/URL, snippets), and comment thread. Use comment_on_issue to add analysis or a fix note to the thread.

NameTypeReqDescription
issue_numberintegeryesIssue number from list_issues.
occurrence_limitintegerMax occurrences to include (default 20); see occurrence_count/truncated.
website_idstringyesWebsite id the issue belongs to.

No output schema declared.

No examples provided.

get_report ~321

Fetch the finished report for an audit run (use the run_id from run_audit once get_audit_status shows completed). Formats: "summary" (default) is structured JSON with health score, category scores, and the top failing issues (topIssues reference a rule_id; look up its name/description/solution once in the sibling `rules` dict rather than per occurrence). Each topIssues row carries `provenance`: "carried" means the finding is re-injected from a page not re-crawled this run (not a fresh result) — check `lastSeenAt` for when it was last actually observed. `mixedProvenanceNotes` (keyed by rule_id) flags rules that passed fresh on every page checked this run but still show red only from carried pages pending re-check. Also includes a `history` array of prior audits of this website with score/issue deltas when available; "llm" is a compact text rendering optimized for LLM context (carried findings marked inline); "markdown" is a full human-readable report. Start with summary, then pull llm or markdown when you need every issue and page detail.

NameTypeReqDescription
formatstringsummary (default): JSON scores + top issues. llm: compact text for LLM context. markdown: full report.
run_idstringyesRun id returned by run_audit or listed by list_audits.
top_issue_limitintegersummary format only: max top issues to include (default 25).

No output schema declared.

No examples provided.

get_rule ~93

Fetch one audit rule by id (e.g. "meta/title-length"), including what it checks, how to fix it (recommendation), its severity and score weight, a docs link, and whether it is a cloud (credit-billed) rule. Rule ids appear in report topIssues and issue rule_id fields.

NameTypeReqDescription
rule_idstringyesRule id like "crawl/canonical-chain" (category/slug).

No output schema declared.

No examples provided.

list_audits ~69

List the organization's audit runs: currently active (pending/running) plus the most recent runs of any status. Use the run ids with get_audit_status or get_report, and website ids with list_issues.

NameTypeReqDescription
limitintegerMax recent runs to return (default 20).

No output schema declared.

No examples provided.

list_credit_transactions ~153

Audit the organization's credit accounting log: grants (signup/monthly/pack/promo), debits (audit_base 50cr + render 2cr/page + folded 0-cost services), refunds, and adjustments — newest first, paginated. Each debit/refund carries `run_id` so you can group a single audit's spend. Use this to explain why an audit cost what it cost or to reconcile a balance. For one audit's per-feature breakdown, use get_report (its `cost` field). Read-only.

NameTypeReqDescription
cursorstringOpaque pagination cursor from a previous page's `next_cursor`.
limitintegerMax transactions to return (default 25, max 100).

No output schema declared.

No examples provided.

list_issues ~169

List a website's open audit issues (like a bug tracker: each issue is one failing rule with occurrences across pages, numbered per website). Returns issues sorted by severity, plus severity and status summaries. Use the issue number with get_issue for full detail and comments. Filter by status/severity/category to narrow down.

NameTypeReqDescription
categorystringFilter by rule category code (e.g. seo, performance, security).
limitintegerPage size (default 50).
offsetintegerPagination offset (default 0).
severitystringFilter by severity.
statusstringFilter by issue status (omit for all statuses).
website_idstringyesWebsite id from list_websites, run_audit, or list_audits.

No output schema declared.

No examples provided.

list_rules ~110

Browse the catalog of 260+ audit rules that run during an audit, grouped into categories (crawlability, meta tags, performance, security, accessibility, content, and more). Filter by category code or search by keyword to find what a specific rule checks. Use get_rule for one rule's full detail.

NameTypeReqDescription
categorystringFilter to one category code (see the categories list in the response).
searchstringCase-insensitive keyword match on rule id, name, and description.

No output schema declared.

No examples provided.

list_websites ~91

List websites the organization has audited, with their latest run status and health score. Use the website_id with list_issues/get_issue. Websites registered but never audited do not appear; run_audit or add_website registers a new one. Returns total/has_more for pagination.

NameTypeReqDescription
limitintegerPage size (default 50).
offsetintegerPagination offset (default 0).

No output schema declared.

No examples provided.

run_audit ~243

Run a cloud audit of a website (crawl + 260+ rule analysis + report). Credits are spent as the audit runs (pay-as-you-go). Call once without confirm to get a credit estimate; if the response has status "confirmation_required", show the estimate to the user and call again with confirm: true. Audits are asynchronous and take minutes: poll get_audit_status with the returned run_id, then fetch results with get_report. The website is registered automatically on first audit.

NameTypeReqDescription
confirmbooleanApprove the credit spend. Omit on the first call to see the estimate; set true to start the audit after the user approves.
coveragestringCrawl coverage profile (default fast). Deeper coverage crawls more pages and costs more credits.
max_creditsintegerSpend guard: refuse to start if the upper-bound estimate exceeds this many credits.
renderbooleanRender pages in a headless browser (default true). Catches JavaScript-dependent issues; costs extra credits per page.
urlstringyesWebsite URL to audit, e.g. https://example.com (scheme optional).

No output schema declared.

No examples provided.

send_feedback ~249

Report your experience using squirrelscan mid-session: a bug, a missing feature, what worked, what confused you, missing report data, or tool ergonomics. Reviewed by the team to improve the product — use it any time something surprises you, not just at the end of a session. Works with any authenticated credentials, including read-only API keys.

NameTypeReqDescription
categorystringyesbug_report (a defect in squirrelscan itself — wrong or missing rule result, crash, broken tool), feature_request (something squirrelscan should do but doesn't), what_worked (something worked well), c…
messagestringyesFree-text feedback (truncated at 2000 chars).
run_idstringAudit run id this feedback relates to, if any (from run_audit/get_report). Verified against your credentials' runs before being attached.
website_idstringWebsite id this feedback relates to, if any (from list_websites). Verified against your org's websites before being attached.

No output schema declared.

No examples provided.

whoami ~46

Identify the current credentials: how you are authenticated, which organization you act for, the plan, and the current credit balance. Call this first in a session to orient yourself before running audits.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.