io.aeotool/mcp
REMOTE · AEOTOOL.IO · SCANNED AUG 3
Pilot AEO/GEO from Claude: bulk audits, server-side fixes via WordPress plugin, AI citations.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability68
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 2735 tokens (~118/item across 23 items; 23 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · aeotool.io
claude mcp add --transport http io-aeotool-mcp https://aeotool.io/api/mcp
[mcp_servers.io-aeotool-mcp] url = "https://aeotool.io/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-aeotool-mcp": {
"type": "remote",
"url": "https://aeotool.io/api/mcp",
"enabled": true
}
}
} openclaw mcp add io-aeotool-mcp --url https://aeotool.io/api/mcp --transport streamable-http
mcp_servers:
io-aeotool-mcp:
url: "https://aeotool.io/api/mcp" {
"mcpServers": {
"io-aeotool-mcp": {
"type": "http",
"url": "https://aeotool.io/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +6
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 0
- Tool “aeo_citations” rewrote its description, which is the text the model reads security
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 72
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://aeotool.io/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=aeotool.io | CN=YR1,O=Let's Encrypt,C=US | 28 Jun 2026 | 26 Sept 2026 | RSA 2048 | SHA256-RSA | 5c2cb35b344d21d38043192cc14553b7cee |
| SANs: aeotool.io | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of aeotool.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| aeotool.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://aeotool.io/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://aeotool.io/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://www.googletagmanager.com https://js.stripe.com https://va.vercel-scripts.com https://vercel.live; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https:; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://*.supabase.co https://*.stripe.com https://www.google-analytics.com https://*.googletagmanager.com https://*.vercel-insights.com https://va.vercel-scripts.com https://api.firecrawl.dev; frame-src https://js.stripe.com https://hooks.stripe.com https://vercel.live; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), interest-cohort=(), browsing-topics=() |
Protected resource metadata
| Document | https://aeotool.io/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://aeotool.io/api/mcp |
| Authorisation server | https://aeotool.io |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://aeotool.io/api/mcp | Verified | 200 | |
| http (plaintext) | http://aeotool.io/api/mcp | HTTPS enforced | 308 | https://aeotool.io/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
ads_ad_status Pause / réactivation d’annonce ~132
ÉCRITURE GARDÉE — met une annonce individuelle en pause ou la réactive (réversible). ids via ads_list_ads. Dry-run Google puis confirm:true. Pilotage requis (write_enabled) ; journalisé.
| Name | Type | Req | Description |
|---|---|---|---|
| ad_group_id | string | yes | Groupe d’annonces (voir ads_list_ads) |
| ad_id | string | yes | Id de l’annonce (voir ads_list_ads) |
| confirm | boolean | — | true = appliquer (après dry-run) |
| customer_id | string | — | Compte Ads (optionnel) |
| status | string | yes | PAUSED ou ENABLED |
No output schema declared.
No examples provided.
ads_add_keywords Ajouter des mots-clés ~141
ÉCRITURE GARDÉE — ajoute des mots-clés POSITIFS (1-20) à un groupe d’annonces. ad_group_id via ads_keywords. Dry-run Google puis confirm:true. Pilotage requis (write_enabled) ; journalisé.
| Name | Type | Req | Description |
|---|---|---|---|
| ad_group_id | string | yes | Groupe d’annonces cible |
| confirm | boolean | — | true = appliquer (après dry-run) |
| customer_id | string | — | Compte Ads (optionnel) |
| keywords | array | yes | 1-20 mots-clés |
| match_type | string | — | EXACT | PHRASE | BROAD (défaut EXACT) |
No output schema declared.
No examples provided.
ads_add_negative_keywords Ajouter des mots-clés négatifs ~162
ÉCRITURE GARDÉE — ajoute des mots-clés négatifs (1-50) à une campagne. Sans confirm:true : dry-run validé par Google (rien n’est appliqué). Nécessite le pilotage activé pour ce compte (ads_list_accounts → write_enabled). Chaque application est journalisée.
| Name | Type | Req | Description |
|---|---|---|---|
| campaign_id | string | yes | Campagne cible (voir ads_performance) |
| confirm | boolean | — | false/absent = dry-run ; true = appliquer |
| customer_id | string | — | Compte Ads (optionnel) |
| keywords | array | yes | 1-50 termes à exclure |
| match_type | string | — | EXACT (défaut) | PHRASE | BROAD |
No output schema declared.
No examples provided.
ads_audit Audit Google Ads (18 critères) ~69
Audit complet du compte Google Ads : score /100, grade, € gaspillés/mois, manque à gagner, quick wins par catégorie (tracking, gaspillage, enchères, structure, RSA…). Lecture seule, gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | — | Compte Ads (optionnel) |
No output schema declared.
No examples provided.
ads_campaign_status Pause / réactivation de campagne ~116
ÉCRITURE GARDÉE — met une campagne en pause ou la réactive (réversible). Sans confirm:true : dry-run validé par Google. Pilotage requis (write_enabled) ; journalisé.
| Name | Type | Req | Description |
|---|---|---|---|
| campaign_id | string | yes | Campagne cible (voir ads_performance) |
| confirm | boolean | — | true = appliquer (après dry-run) |
| customer_id | string | — | Compte Ads (optionnel — défaut : le plus récent) |
| status | string | yes | PAUSED ou ENABLED |
No output schema declared.
No examples provided.
ads_keywords Mots-clés Ads (avec ids) ~92
Mots-clés actifs avec leurs métriques (N jours) et les ids nécessaires aux actions (ad_group_id + criterion_id pour ads_pause_keyword). Gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | — | Compte Ads (optionnel) |
| days | number | — | Période en jours (défaut 30) |
| limit | number | — | Max lignes (défaut 100, max 300) |
No output schema declared.
No examples provided.
ads_list_accounts Comptes Google Ads connectés ~74
Liste les comptes Google Ads connectés au compte aeotool (OAuth) : customer_id, nom, statut, is_manager (MCC — non requêtable directement, ses comptes clients apparaissent aussi dans la liste), write_enabled (pilotage en écriture — activable par compte dans le Cockpit Google Ads).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
ads_list_ads Annonces du compte ~85
Annonces (RSA…) avec métriques N jours et ids (ad_group_id + ad_id) nécessaires à ads_ad_status. Gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | — | Compte Ads (optionnel) |
| days | number | — | Période en jours (défaut 30) |
| limit | number | — | 1-200, défaut 100 |
No output schema declared.
No examples provided.
ads_pause_keyword Mettre un mot-clé en pause ~125
ÉCRITURE GARDÉE — met un mot-clé en pause (réversible dans Google Ads). ids via ads_keywords. Sans confirm:true : dry-run validé par Google. Pilotage requis (write_enabled) ; journalisé.
| Name | Type | Req | Description |
|---|---|---|---|
| ad_group_id | string | yes | Groupe d’annonces (voir ads_keywords) |
| confirm | boolean | — | false/absent = dry-run ; true = appliquer |
| criterion_id | string | yes | Id du mot-clé (voir ads_keywords) |
| customer_id | string | — | Compte Ads (optionnel) |
No output schema declared.
No examples provided.
ads_performance Performance des campagnes Ads ~90
Performance des campagnes Google Ads sur N jours (défaut 30) : impressions, clics, coût, conversions, CTR, CPC moyen, budget/jour — triées par coût. Gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | — | Compte Ads (optionnel — défaut : le plus récent) |
| days | number | — | Période en jours (1-365, défaut 30) |
No output schema declared.
No examples provided.
ads_search_terms Termes de recherche Ads ~103
Termes de recherche réels ayant déclenché les annonces (N jours, triés par coût) avec le flag wasted=true (coût sans conversion) — candidats directs pour ads_add_negative_keywords. Gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| customer_id | string | — | Compte Ads (optionnel) |
| days | number | — | Période en jours (défaut 30) |
| limit | number | — | Max lignes (défaut 50, max 200) |
No output schema declared.
No examples provided.
ads_update_budget Modifier le budget quotidien d’une campagne ~145
ÉCRITURE GARDÉE — modifie le budget quotidien d’une campagne. Caps : ±20 % max par appel, plafond absolu (env ADS_MAX_DAILY_BUDGET_EUR, défaut 200 €/j), budgets partagés refusés. Sans confirm:true : dry-run validé par Google. Pilotage requis ; journalisé.
| Name | Type | Req | Description |
|---|---|---|---|
| campaign_id | string | yes | Campagne cible (voir ads_performance) |
| confirm | boolean | — | false/absent = dry-run ; true = appliquer |
| customer_id | string | — | Compte Ads (optionnel) |
| new_daily_budget_eur | number | yes | Nouveau budget quotidien en euros |
No output schema declared.
No examples provided.
aeo_apply Appliquer les correctifs ~172
APPLIQUE la sélection d’améliorations niveau 1 (jsonld/robots/llms/meta) sur un site connecté : génère + archive les correctifs et bump le bundle → le plugin les injecte au prochain sync. Optionnel : faqs[] (ajoute un FAQPage au JSON-LD), title/description (meta). Le site doit être connecté (aeo_list_sites).
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | — | optionnel : description meta/OG |
| domain | string | yes | domaine du site connecté |
| faqs | array | — | optionnel : Q&A pour le FAQPage (jsonld) |
| improvement_ids | array | yes | ids des améliorations (cf. aeo_improvements.autoApplicableIds) |
| title | string | — | optionnel : titre meta/OG |
No output schema declared.
No examples provided.
aeo_audit Auditer une URL (AEO/GEO) ~105
Lance un audit AEO/GEO d’une URL (asynchrone, ~2 min) et renvoie immédiatement l’audit_id. Suivre avec aeo_audit_status jusqu’à completed, puis aeo_report / aeo_improvements. Coûte 50 GTO, débités à la complétion. NE PAS relancer le même audit pendant qu’un run est en cours.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | URL ou domaine à auditer |
No output schema declared.
No examples provided.
aeo_audit_status Statut d’un audit ~69
Statut d’un audit lancé par aeo_audit : pending/processing → completed (avec le score) ou failed. Gratuit — poll toutes les 20-30 s.
| Name | Type | Req | Description |
|---|---|---|---|
| audit_id | string | yes | id de l’audit (renvoyé par aeo_audit) |
No output schema declared.
No examples provided.
aeo_batch_audit Auditer plusieurs sites ~88
Lance l’audit de plusieurs sites en une commande (le « killer agence »), en asynchrone : renvoie immédiatement un audit_id par URL. Suivre chaque id avec aeo_audit_status. Coûte 50 GTO par site, débités à la complétion.
| Name | Type | Req | Description |
|---|---|---|---|
| urls | array | yes | Liste d’URLs/domaines à auditer |
No output schema declared.
No examples provided.
aeo_citations Historique de citations IA ~134
Historique de citation d’un domaine dans les moteurs IA : taux de citation par date, détail par moteur, part de voix. Renvoie `series[].basis` = "measured" ou "derived" (dénominateur reconstitué sur les scans anciens, le taux est alors un plancher — voir `caveat`). `share_of_voice` vaut null si aucun concurrent n’est suivi : la part de voix n’est pas mesurable, ce n’est pas 0. Nécessite un Monitoring IA sur ce domaine. Gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | domaine à inspecter |
No output schema declared.
No examples provided.
aeo_generate Générer un artefact AEO ~329
Génère (sans appliquer) un artefact AEO, déterministe et gratuit. Types : jsonld, robots, llms, meta, faq (params faqs[]), ai-txt, humans-txt, security-txt, sitemap. jsonld/robots/llms/meta/faq sont applicables (cf. aeo_apply) ; ai-txt/humans-txt/security-txt/sitemap sont à publier par l’agence.
| Name | Type | Req | Description |
|---|---|---|---|
| aiCrawlingPolicy | string | — | ai-txt : politique de crawl IA (défaut allow-with-attribution) |
| contact | string | — | security-txt/ai-txt : email de contact (optionnel) |
| description | string | — | meta : description (optionnel) |
| disclosure | string | — | ai-txt : mention de divulgation de contenu IA (optionnel) |
| faqs | array | — | faq : questions/réponses [{q,a}] |
| language | string | — | security-txt : langues préférées / humans-txt : langue (optionnel) |
| paths | array | — | sitemap : chemins à inclure (optionnel) |
| policy | string | — | security-txt : URL de la politique de sécurité (optionnel) |
| team | array | — | humans-txt : équipe [{name,role}] (optionnel) |
| tech | array | — | humans-txt : technologies (optionnel) |
| title | string | — | meta : titre (optionnel) |
| type | string | yes | type d’artefact |
| url | string | yes | URL ou domaine cible |
No output schema declared.
No examples provided.
aeo_improvements Checklist d’améliorations ~118
La CHECKLIST d’améliorations d’un audit : groupées par niveau (1=auto-applicable plugin, 2=générable, 3=rebuild/lead), triées par gain projeté. Fournit les ids à passer à aeo_apply. Passer audit_id OU domain (= dernier audit terminé du domaine). Gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| audit_id | string | — | id de l’audit (optionnel si domain fourni) |
| domain | string | — | domaine — utilise le dernier audit terminé (alternative à audit_id) |
No output schema declared.
No examples provided.
aeo_list_sites Lister les sites connectés ~37
Liste les sites WordPress connectés au compte (plugin Everlange Connect) : domaine, statut, modules actifs, version du bundle.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
aeo_monitor Monitoring citations programmé ~149
Programme un scan de citations récurrent côté serveur (10 moteurs IA, part de voix vs watchlist, alertes email). action=create {domain, brand_name?, frequency: daily|weekly|biweekly} · list · delete {schedule_id}. Chaque scan programmé coûte 25 GTO à l’exécution.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | create | list | delete |
| brand_name | string | — | nom de marque (défaut : racine du domaine) |
| domain | string | — | domaine à monitorer (create) |
| frequency | string | — | daily | weekly | biweekly (défaut weekly) |
| schedule_id | string | — | id du schedule (delete) |
No output schema declared.
No examples provided.
aeo_proof Preuve avant/après d’un domaine ~65
La PREUVE : compare les 2 derniers audits complétés d’un domaine — delta de score, critères améliorés, critères régressés. L’argument client en un appel. Gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | domaine audité au moins 2 fois |
No output schema declared.
No examples provided.
aeo_report Détail d’un audit ~65
Renvoie le détail complet d’un audit existant (par audit_id) : score global, scores par catégorie et tous les critères (score + recommandation). Gratuit.
| Name | Type | Req | Description |
|---|---|---|---|
| audit_id | string | yes | id de l’audit (renvoyé par aeo_audit) |
No output schema declared.
No examples provided.