io.github.huxleypeckham/found-by-ai-monitor
REMOTE · AREYOUFOUNDBYAI.COM · SCANNED SEP 22
Live AI-visibility measurements across 7 answer engines, queryable by the business owner's own AI.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 16 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability88
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1654 tokens (~97/item across 17 items; 17 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
- Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 17 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 18 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.github.huxleypeckham/found-by-ai-monitor MCP server?
io.github.huxleypeckham/found-by-ai-monitor is a hosted endpoint at https://areyoufoundbyai.com/mcp/demo, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · areyoufoundbyai.com
claude mcp add --transport http huxleypeckham-found-by-ai-monitor 'https://areyoufoundbyai.com/mcp/demo'
{
"mcpServers": {
"huxleypeckham-found-by-ai-monitor": {
"url": "https://areyoufoundbyai.com/mcp/demo"
}
}
} {
"servers": {
"huxleypeckham-found-by-ai-monitor": {
"type": "http",
"url": "https://areyoufoundbyai.com/mcp/demo"
}
}
} [mcp_servers.huxleypeckham-found-by-ai-monitor] url = "https://areyoufoundbyai.com/mcp/demo"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"huxleypeckham-found-by-ai-monitor": {
"type": "remote",
"url": "https://areyoufoundbyai.com/mcp/demo",
"enabled": true
}
}
} openclaw mcp add huxleypeckham-found-by-ai-monitor --url 'https://areyoufoundbyai.com/mcp/demo' --transport streamable-http
mcp_servers:
huxleypeckham-found-by-ai-monitor:
url: "https://areyoufoundbyai.com/mcp/demo" {
"McpServers": {
"huxleypeckham-found-by-ai-monitor": {
"Transport": "http",
"Url": "https://areyoufoundbyai.com/mcp/demo"
}
}
} assistant mcp add huxleypeckham-found-by-ai-monitor -t streamable-http -u 'https://areyoufoundbyai.com/mcp/demo'
{
"mcpServers": {
"huxleypeckham-found-by-ai-monitor": {
"type": "http",
"url": "https://areyoufoundbyai.com/mcp/demo"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 22 Sept 26 +1
- Tool “get_fix_plan” rewrote its description, which is the text the model reads security
- The server now declares the “prompts” capability functional
- First check of Schema quality: 100 functional
- New prompt “review-answers” functional
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
- Tool “get_answers” rewrote its description, which is the text the model reads security
- Tool “get_visibility” rewrote its description, which is the text the model reads security
- Schema quality: 84 → 97 ▼ functional
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://areyoufoundbyai.com/mcp/demo
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=areyoufoundbyai.com | CN=WE1,O=Google Trust Services,C=US | 20 Sept 2026 | 19 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 8de1a9f7568be2be13447eaa2fabebf6 |
| SANs: areyoufoundbyai.com, workspace-preview.areyoufoundbyai.com, *.workspace-preview.areyoufoundbyai.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of areyoufoundbyai.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| areyoufoundbyai.com. | present | 2371 | 13 | Verified |
| areyoufoundbyai.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=15552000 |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://areyoufoundbyai.com/mcp/demo | Verified | 200 | |
| http (plaintext) | http://areyoufoundbyai.com/mcp/demo | HTTPS enforced | 301 | https://areyoufoundbyai.com/mcp/demo |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_agent_view How an agent browser reads the site ~69
A headless agent-browser read of the site (refreshed daily): full, partial or blank, with how many characters of real content an agent can extract. A site that renders blank to agents is invisible to agentic AI regardless of content quality. No other tool in this lane measures it.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_ai_traffic AI-sent visitors (30 days) ~61
Visitors the AI engines actually sent to the business's site in the last 30 days, recorded by the site's own beacon: totals by engine and by week, with the tracking wiring status. This closes the loop from being named in answers to humans arriving.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_answers Verbatim engine answers, question by question ~295
The exact answer each engine gave to each tracked buyer question in the latest deep measurement for areyoufoundbyai.com: engine, model, date, whether this business was named and on how many samples, live web search or model memory, the competitors named in that answer, the web searches the engine ran before answering (fan-out), and the question's Google demand. This is the receipt behind every score. Filter by a question substring or an engine; answers are trimmed to `chars` characters. Named: your business name is recorded in the answer prose. Cited: your website is linked in the answer’s sources. Listed: your name appears in a list, heading or source title rather than in the prose. Found via search: a page appears in recorded search results; that alone is not a citation or recommendation. These can overlap. A web-search flag only records that search was used. Older positive flags may not distinguish these types; read the retained answer. Unavailable is not a negative result.
| Name | Type | Req | Description |
|---|---|---|---|
| chars | integer | – | Maximum characters per answer, default 700, max 4000 |
| engine | string | – | One of ChatGPT, Perplexity, Gemini, Claude, Grok, DeepSeek, Google AI Overviews |
| limit | integer | – | Maximum question rows, default 12, max 25 |
| question | string | – | Substring of a tracked question, case-insensitive |
No output schema declared.
No examples provided.
get_benchmark Rank against the measured category ~40
Where this business sits against every other measured business in its category: rank, percentile, and the distribution above and below. Real corpus, not an estimate.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_citation_sources Where the engines read ~46
The domains AI engines actually cite in answers matching this category, most-cited first, with whether this business appears on each. Getting mentioned there moves visibility more than on-site changes.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_cited_queries Where a competitor is named or cited ~174
Reverse lookup over every measurement we have already run: give a competitor's brand name or domain and get the buyer questions where the answer engines named them, which engines, how often, when they were last seen, and who else was named on those questions. Also reports where that domain was cited as a source. Coverage is the questions we have measured, so a thin result means we have not asked those questions yet, never that the competitor is absent from AI.
| Name | Type | Req | Description |
|---|---|---|---|
| competitor | string | yes | A brand name or domain, e.g. Rocketlane or rocketlane.com |
| engine | string | – | Optional: only questions where this engine named them |
| limit | integer | – | Maximum questions, default 25, max 100 |
| since | string | – | Optional ISO date, only measurements on or after it |
No output schema declared.
No examples provided.
get_context Full context pack ~42
The complete weekly context document: scores, every tracked question with its verbatim answer status, mentions, and what to do next. Same content as the downloadable context.md.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_fix_plan Priority fix plan ~36
The prioritised fix list from the latest deep scan: the specific changes that move this business up in AI answers, highest impact first.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_mentions Recent web mentions ~54
New pages on the web that mention the business, from the daily sweep. Independent mentions are the strongest signal that moves AI answers.
| Name | Type | Req | Description |
|---|---|---|---|
| days | number | – | Look-back window in days (1-90, default 30) |
No output schema declared.
No examples provided.
get_personas Buyer personas driving the tracked questions ~46
The 2-4 buyer personas inferred from this business's measured questions, the way AI models would describe each buyer type, with the exact tracked questions each persona asks. Read-only.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_post_brief Post brief from verified data ~97
Everything an AI needs to draft social posts that move AI visibility, assembled from this week's measured data: fresh third-party mentions to anchor on, the exact buyer questions the engines answer without naming the business (and who they name instead), the domains the engines actually read, and the entity rules that make a post retrievable. Returns a drafting brief, never generated copy: the drafting happens in your AI, in the business's own voice.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_question_trajectories Per-question trajectories ~50
Every tracked buyer question with its measured history: how many of the 7 engines named the business on each measured day. This is where visibility is actually won or lost, question by question.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_rivals Competitors AI names instead ~29
The competitor names the answer engines actually gave in the latest scan when they did not name this business.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_share_of_voice Share of voice, two instruments ~81
Two measurements, kept apart. First, your share of mentions in your own tracked answers against the rivals the engines named there. Second, web mention share: how often a web-scale index of ChatGPT answers mentions you against the brands we compare you with, which is not a rival list. Use get_rivals for who the engines name instead of you.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_source_profile What a cited source is and how to get on it ~131
A profile of any domain the answer engines cite: how often our measurements saw engines read it and across how many businesses and categories, what the site says it is (title and description from our crawl of its homepage), the co-read pack it travels in (sources the engines read together), and, where our crawler found one, the page where a business gets listed on it. Aggregate market data from our measurement corpus; a thin result means the engines rarely cite it in what we have measured so far.
| Name | Type | Req | Description |
|---|---|---|---|
| source | string | yes | The source domain, e.g. canstar.com.au or yelp.com |
No output schema declared.
No examples provided.
get_visibility Current visibility + readiness scores ~216
The latest AI Visibility and AI Readiness scores (each /100) for areyoufoundbyai.com, with the previous week's scores, the separate off-site Footprint score, and the subscores (citability, E-E-A-T, technical, schema, platform compose Readiness; Footprint sits beside it). Being named in the answer prose counts in full toward your visibility score. A positive result recorded only as a list entry, citation or source title counts half. Older results without this distinction retain their recorded scoring basis. Named: your business name is recorded in the answer prose. Cited: your website is linked in the answer’s sources. Listed: your name appears in a list, heading or source title rather than in the prose. Found via search: a page appears in recorded search results; that alone is not a citation or recommendation. These can overlap. A web-search flag only records that search was used. Older positive flags may not distinguish these types; read the retained answer. Unavailable is not a negative result.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
request_rescan Re-measure now ~72
DEMO: returns a worked example of the response and queues nothing. Queue a fresh deep measurement right now instead of waiting for the weekly scan. Uses one of the plan's capped on-demand re-measures; runs the measurement and changes nothing else. Results land in a few minutes, then read get_visibility again.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the io.github.huxleypeckham/found-by-ai-monitor MCP server?
io.github.huxleypeckham/found-by-ai-monitor is an MCP server listed in the public MCP registry as io.github.huxleypeckham/found-by-ai-monitor. Live AI-visibility measurements across 7 answer engines, queryable by the business owner's own AI. This page covers its hosted endpoint (https://areyoufoundbyai.com/mcp/demo).
Is the io.github.huxleypeckham/found-by-ai-monitor MCP server safe to use?
io.github.huxleypeckham/found-by-ai-monitor scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.huxleypeckham/found-by-ai-monitor MCP server expose?
io.github.huxleypeckham/found-by-ai-monitor exposes 17 tools: get_visibility, get_question_trajectories, get_personas, get_mentions, get_rivals, and 12 more. Their descriptions and schemas cost roughly 1,539 tokens of context every time the server is loaded.
Does the io.github.huxleypeckham/found-by-ai-monitor MCP server require authentication?
No. We connected to io.github.huxleypeckham/found-by-ai-monitor without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.huxleypeckham/found-by-ai-monitor MCP server still maintained?
io.github.huxleypeckham/found-by-ai-monitor is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.