it.heera/agentimus
REMOTE · HEERA.IT · SCANNED AUG 3
heera.it via Agentimus: AI readiness, traffic, request log, search & index reports, by approval.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability70
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2112 tokens (~140/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · heera.it
claude mcp add --transport http it-heera-agentimus https://heera.it/wp-json/agentimus/v1/mcp
[mcp_servers.it-heera-agentimus] url = "https://heera.it/wp-json/agentimus/v1/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"it-heera-agentimus": {
"type": "remote",
"url": "https://heera.it/wp-json/agentimus/v1/mcp",
"enabled": true
}
}
} openclaw mcp add it-heera-agentimus --url https://heera.it/wp-json/agentimus/v1/mcp --transport streamable-http
mcp_servers:
it-heera-agentimus:
url: "https://heera.it/wp-json/agentimus/v1/mcp" {
"mcpServers": {
"it-heera-agentimus": {
"type": "http",
"url": "https://heera.it/wp-json/agentimus/v1/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 77
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://heera.it/wp-json/agentimus/v1/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=heera.it | CN=YE1,O=Let's Encrypt,C=US | 30 Jul 2026 | 28 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 63d47dde6db6c47bf1747faba63c3752b61 |
| SANs: *.heera.it, heera.it | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of heera.it. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| it. | present | 51765 | 13 | Verified |
| heera.it. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://heera.it/.well-known/oauth-protected-resource/agentimus/mcp"
Bearer resource_metadata="https://heera.it/.well-known/oauth-protected-resource/agentimus/mcp" | Header | Value |
|---|---|
| strict-transport-security | max-age=15552000; includeSubDomains |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | same-origin |
| permissions-policy | geolocation=(), camera=(), microphone=() |
Protected resource metadata
| Document | https://heera.it/.well-known/oauth-protected-resource/agentimus/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://heera.it/wp-json/agentimus/v1/mcp |
| Authorisation server | https://heera.it/agentimus/mcp |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://heera.it/wp-json/agentimus/v1/mcp | Verified | 200 | |
| http (plaintext) | http://heera.it/wp-json/agentimus/v1/mcp | HTTPS enforced | 301 | https://heera.it/wp-json/agentimus/v1/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
agentimus-check-page Check a page’s AI readability ~116
Checks ONE post/page’s readability for AI: grades how easily an AI can read, section and cite it — word count, an opening summary, concrete figures or cited sources, heading structure, quotable passage length, link density, image alt text, and freshness. Returns a pass/warn/fail row per check plus a tally. Use it when asked to check a page’s readability, or to tell an author exactly what to improve on a specific page.
| Name | Type | Req | Description |
|---|---|---|---|
| post_id | integer | yes | The post/page ID to grade. |
| Name | Type | Req | Description |
|---|---|---|---|
| checks | array | — | — |
| summary | object | — | — |
No examples provided.
agentimus-identify-bot Identify a bot by IP ~113
Given an IP address, resolves who it really belongs to via forward-confirmed reverse DNS: the PTR hostname, the owning network/organisation, whether it maps to a known AI engine, and a verdict (0 = no engine match, 1 = forward-confirmed engine, 2 = forged engine hostname — an impersonator). Use it to answer "is this crawler that claims to be GPTBot actually OpenAI?".
| Name | Type | Req | Description |
|---|---|---|---|
| ip | string | yes | The IPv4 or IPv6 address to check. |
| Name | Type | Req | Description |
|---|---|---|---|
| engine | string | — | — |
| host | string | — | — |
| ip | string | — | — |
| network | string | — | — |
| slow | boolean | — | — |
| verdict | integer | — | 0 = no engine / no PTR, 1 = forward-confirmed engine, 2 = forged engine hostname. |
No examples provided.
agentimus-preview-markdown Preview a page’s Markdown twin ~74
Returns the plain-Markdown version of a post — the ".md twin" Agentimus serves to AI clients that prefer clean text over rendered HTML. Read-only preview of a single post; the site-wide index lives at /index.md.
| Name | Type | Req | Description |
|---|---|---|---|
| post_id | integer | yes | The post/page ID to render as Markdown. |
| Name | Type | Req | Description |
|---|---|---|---|
| markdown | string | — | — |
No examples provided.
agentimus-preview-schema Preview a page’s JSON-LD ~97
Returns the JSON-LD @graph Agentimus would emit — for a specific post (pass post_id) or the site-wide identity graph (omit post_id / pass 0). Includes both the structured object and a pretty-printed JSON string. Read-only preview: it reflects the current draft, and changes nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| post_id | integer | — | Post/page ID to preview; omit or 0 for the site-wide identity graph. |
| Name | Type | Req | Description |
|---|---|---|---|
| graph | object|null | — | JSON-LD document { "@context", "@graph": [ …nodes ] }, or null when there is nothing to emit. |
| json | string | — | — |
No examples provided.
agentimus-read-ai-traffic Get AI referral traffic ~160
Returns real visits this site received FROM AI assistants (ChatGPT, Perplexity, Gemini, etc.) over a day range: totals, the per-assistant leaderboard, the landing pages they sent readers to, a daily series, and a diagnostic of unrecognised referrers. Optionally filter to one assistant and/or a landing-path prefix.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | — | Start date (YYYY-MM-DD). Defaults to the retention window. |
| path | string | — | Narrow to a landing-path prefix, e.g. "/blog". |
| source | string | — | Narrow to one assistant, by its exact label (see read-ai-traffic facets). |
| to | string | — | End date (YYYY-MM-DD). Defaults to today. |
| Name | Type | Req | Description |
|---|---|---|---|
| activeDays | integer | — | — |
| beacon | boolean | — | — |
| bySource | array | — | — |
| daily | array | — | — |
| enabled | boolean | — | — |
| filters | object | — | — |
| range | object | — | — |
| sourceCount | integer | — | — |
| topPages | array | — | — |
| total | integer | — | — |
| unknown | object | — | — |
No examples provided.
agentimus-read-ai-visibility Get AI Visibility results ~84
Returns the latest AI Visibility run: whether AI assistants mention and cite each tracked product, the overall visibility score and citation rate, per-product share-of-voice against competitors, and the trend across recent runs. Empty (hasData=false) until a run has completed. Read-only; it does not start a run (running one spends the site’s AI credits).
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| hasData | boolean | — | — |
| lastRunAt | string | — | — |
| products | array | — | — |
| summary | object | — | — |
| trend | array | — | — |
No examples provided.
agentimus-read-edge-traffic Get edge traffic from Cloudflare ~142
Returns what Cloudflare saw from AI crawlers BEFORE this server did, when the owner has connected a Cloudflare zone: per-crawler totals (requests at the edge, served from cache, reached the server, blocked at the edge, bytes out), per-company rollups, and any conflicts between the edge's observed behaviour and the site's declared AI policy — e.g. the edge blocking a crawler the policy welcomes. The request log only sees what reached the server; this is the missing before-the-server half. Returns connected=false when no zone is connected.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | — | Window in days, 1-30. Default 7. |
| Name | Type | Req | Description |
|---|---|---|---|
| companies | array | — | — |
| conflicts | array | — | — |
| connected | boolean | — | False = no Cloudflare zone is connected; the data fields are then absent. |
| connectedAt | integer | — | — |
| crawlers | array | — | — |
| dashUrl | string | — | — |
| days | integer | — | — |
| hiddenConflicts | array | — | — |
| lastError | string | — | The most recent poll failure, empty after a clean poll. |
| lastPollAt | integer | — | Unix time of the newest numbers; 0 = never polled. |
| lastPurgeAt | integer | — | Unix time of the last edge cache purge; 0 = never purged. |
| lastPurgeError | string | — | The most recent purge failure (e.g. the token lacks the Cache Purge permission), empty after a clean purge. Separate from lastError so healthy numbers cannot hide it. |
| totals | object | — | — |
| zoneName | string | — | — |
No examples provided.
agentimus-read-google-index Get Google index status for this site ~178
Returns whether Google's index holds this site's pages, when the owner has connected Google Search Console. Google's index is what AI Overviews, AI Mode and Gemini grounding read — the Google counterpart of "Bing's index is what ChatGPT search reads". Two tiers share Google's 2,000-inspections/day budget (there is no bulk index report): a WATCHLIST (homepage, busiest pages, newest posts — every answer in rows) checked daily, and a WHOLE-SITE ROTATION walking every published URL in daily slices — its healthy pages become the site counts, only its problems appear in site.problems. On sites small enough the rotation covers everything every day; site.cycleDays states the honest cadence. Presence only, no traffic (read-search-performance has the traffic). Returns connected=false with empty rows when no key is connected.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| checkedAt | integer | — | Unix time of the newest sweep; 0 = never checked. |
| connected | boolean | — | False = Google Search Console is not connected; rows is then empty. |
| counts | object | — | — |
| lastError | string | — | The most recent sweep failure, empty after a clean sweep. |
| pending | integer | — | Pages of the current sweep still waiting — the sweep runs in short budgeted chunks so no web request runs long. 0 = the last sweep finished; rows not yet reached carry their previous answers. |
| property | string | — | The Search Console property the answers come from. |
| quotaHit | boolean | — | True when Google's daily inspection budget ran out mid-sweep — unreached rows keep their last good answers (see each row's inspectedAt). |
| rows | array | — | — |
| site | object | — | — |
| sitemaps | object | — | — |
| watched | object | — | — |
No examples provided.
agentimus-read-readiness Get AI readiness & AEO/GEO score ~108
Returns the site’s AI-visibility health: the blended 0–100 AEO/GEO score with its band (Findable, Readable, Trusted, Optimized, Cited pillars), the impact-ranked "do this next" action plan, AND the full list of readiness checks with their pass/warn/fail status and the fix for each. Use this to answer "how ready is my site to be found and cited by AI, and what should I fix first?".
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| checks | array | — | — |
| score | object | — | — |
No examples provided.
agentimus-read-request-log Get the AI request log ~256
Returns individual requests AI crawlers and agents made to this site’s discovery endpoints (llms.txt, the .md twins, JSON-LD, sitemaps), newest first and cursor-paginated. Each row has the endpoint, the detected agent, its user-agent, the owning network, and a verdict (0=unchecked, 1=verified real engine, 2=spoofed impersonator). Filter by agent, endpoint, network, verdict, or a user-agent prefix.
| Name | Type | Req | Description |
|---|---|---|---|
| agent | string | — | Exact detected agent name. |
| before | integer | — | Pagination cursor: return rows with id below this (use the previous page’s "cursor"). |
| endpoint | string | — | Exact endpoint path. |
| from | string | — | Start date (YYYY-MM-DD). |
| network | string | — | Exact owning network (only populated when "identify every bot" is on). |
| per_page | integer | — | Rows per page (the store clamps this). |
| to | string | — | End date (YYYY-MM-DD). |
| ua | string | — | User-agent prefix to match. |
| verdict | integer | — | 0 = unchecked, 1 = verified real engine, 2 = spoofed impersonator. |
| Name | Type | Req | Description |
|---|---|---|---|
| autoPrune | boolean | — | — |
| cursor | integer|null | — | — |
| hasMore | boolean | — | — |
| identifyOn | boolean | — | Whether "identify every bot" (network attribution) is on. |
| maxRows | integer | — | — |
| perPage | integer | — | — |
| retentionDays | integer | — | — |
| rows | array | — | — |
| total | integer | — | — |
| verifyOn | boolean | — | Whether Web Bot Auth signature verification is on. |
No examples provided.
agentimus-read-search-opportunities Get search pages worth improving ~176
Returns the pages that already rank in classic search but under-earn — the worklist behind the Search Opportunities screen. Two groups: "almostThere" (ranking 8–20, one improvement from page one) and "seenNotClicked" (already on page one, but a click rate well under THIS site's own page-one median — never an industry benchmark). Each page carries its searches, its totals, and whether it qualified on a single search or on the page's combined demand. Pair it with write-description / update-content to act on what it finds. Returns state "not_connected", "collecting" or "too_thin" when no honest verdict is possible.
| Name | Type | Req | Description |
|---|---|---|---|
| source | string | — | Which engine to read: "google" or "bing". Omit for the richer one that has data. |
| Name | Type | Req | Description |
|---|---|---|---|
| almostThere | array | — | — |
| counts | object | — | — |
| ctrBar | number|null | — | The click-rate threshold actually applied to "seenNotClicked" (percentage): a page must fall BELOW this, not merely below medianCtr. Quote this, never medianCtr, when stating what "not clicked enough… |
| medianCtr | number|null | — | This site's own page-one median click rate (percentage) — the bar "seenNotClicked" is measured against. Null when no honest bar can be set, in which case that group stays empty and medianReason says… |
| medianNeeds | integer | — | How many it takes before a bar is computed at all. |
| medianReason | string | — | Why there is no bar, when medianCtr is null: "thin" = too few page-one results carry enough views to measure (says nothing about clicking); "unclicked" = enough exist and the middle one earned no cli… |
| medianRows | integer | — | How many page-one results carried enough views to measure a click rate. |
| noise | object | — | — |
| seenNotClicked | array | — | — |
| source | string | — | The engine these numbers came from; empty when none has data yet. |
| sources | object | — | — |
| state | string | — | ready | not_connected | collecting | too_thin | clear. |
No examples provided.
agentimus-read-search-performance Get classic-search performance ~190
Returns what classic search actually sent this site over the reported window: total times shown, visits, click rate and impression-weighted average rank, plus the top searches people used and the top pages they landed on. Numbers are the engine's own — Google Search Console and/or Bing Webmaster Tools, whichever the owner connected — never estimated, and never blended (the two count different searchers). Use it to answer "how is this site doing in search?". Returns source="" when no engine has reported yet. When source="bing", totals and topPages come from two separate Bing reports counted differently — they never quite reconcile, and one page can show more clicks than totals.clicks. Neither is an error: state the split rather than reconciling the numbers.
| Name | Type | Req | Description |
|---|---|---|---|
| source | string | — | Which engine to read: "google" or "bing". Omit for the richer one that has data. |
| Name | Type | Req | Description |
|---|---|---|---|
| counts | object | — | — |
| daily | array | — | Clicks and impressions per day, oldest first — Google only (Bing's API has no daily split; empty there). History accumulates locally beyond Google's own window; the payload ships the most recent 112… |
| discover | object | — | — |
| range | object | — | — |
| source | string | — | The engine these numbers came from; empty when none has data yet. |
| sources | object | — | — |
| topPages | array | — | — |
| topQueries | array | — | — |
| totals | object | — | — |
| updatedAt | integer | — | Unix time the daily series last refreshed successfully; 0 = never. Older than a few days = the trend is last-good data, not current — say so. |
| weekly | object | — | — |
No examples provided.
agentimus-read-search-visibility Get AI-search visibility from Bing ~137
Returns how much of this site sits in Bing's index and how cleanly Bing's crawler gets in, when the owner has connected Bing Webmaster Tools. Bing's index is what ChatGPT search reads today (Microsoft Copilot too), so this is the closest measurable answer to "can AI search find this site": pages in the index (daily trend), pages crawled, crawl errors, robots.txt blocks as Bing sees them, plus conflicts between Bing's view and the site's declared policy. Returns connected=false when no key is connected.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | — | Window in days, 1-90. Default 30. |
| Name | Type | Req | Description |
|---|---|---|---|
| conflicts | array | — | — |
| connected | boolean | — | False = no Bing key is connected; the data fields are then absent. |
| connectedAt | integer | — | — |
| days | integer | — | — |
| hasMsvalidate | boolean | — | Whether the site prints the msvalidate verification tag. |
| lastError | string | — | The most recent poll failure, empty after a clean poll. |
| lastPollAt | integer | — | Unix time of the newest numbers; 0 = never polled. |
| lastQueryError | string | — | The most recent query-stats poll failure, empty after a clean run. Separate from lastError so healthy crawl numbers cannot hide it. |
| siteUrl | string | — | The site as Bing Webmaster Tools stores it. |
| totals | object | — | — |
| trend | array | — | — |
No examples provided.
agentimus-scan-exposed-files List exposed-file risks & debug posture ~103
Returns the list of sensitive paths the exposed-files self-check probes for (config backups, .env, VCS metadata, DB dumps, keys) plus the site’s WordPress debug posture and detected environment. NOTE: this SUPPLIES what to check and flags the debug config — it does not fetch the URLs. The live probe must run same-origin from the admin browser so a server loopback cannot mask a leak the real public URL would reveal.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| debugConfig | object | — | — |
| environment | string | — | — |
| probePaths | array | — | — |
No examples provided.
agentimus-suggest-internal-links Suggest internal links for a page ~138
Suggests which of the site’s OWN posts this post should link to, from local signals only (shared topics, categories/tags, and the candidate’s subject appearing in the text) — no AI call is spent. Each suggestion carries the target post, the exact phrase in this post’s text to link (empty when none exists — append a "See also" line instead), and a one-line reason. READ-ONLY: it suggests; to actually insert a link, edit the post through the governed update tool like any other content change.
| Name | Type | Req | Description |
|---|---|---|---|
| post_id | integer | yes | The post/page ID to suggest links for. |
| Name | Type | Req | Description |
|---|---|---|---|
| suggestions | array | — | — |
No examples provided.