# io.github.pijusz/mcp-gsc (npm · mcp-gsc)

Google Search Console MCP server — query performance, sitemaps, indexing & more

- Trust score: 60/100 (medium)
- Change this week: +18
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `mcp-gsc`: 60/100 (this document), [markdown](https://verifymcp.io/servers/pijusz-mcp-gsc/mcp-gsc.md), [page](https://verifymcp.io/servers/pijusz-mcp-gsc/mcp-gsc)

## Channel facts

- Registry: `npm`
- Package: `mcp-gsc`
- Version: `0.1.7`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 83/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known medium-severity CVE affects @hono/node-server 1.19.17, reached via @modelcontextprotocol/sdk > @hono/node-server. A fixed version is available.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (117 of 121), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 2 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 71/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 1699 tokens (~80/item across 21 items; 21 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 67/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add pijusz-mcp-gsc -- npx -y mcp-gsc
```

### Codex

```bash
codex mcp add pijusz-mcp-gsc -- npx -y mcp-gsc
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "pijusz-mcp-gsc": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "mcp-gsc"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add pijusz-mcp-gsc --command npx --arg -y --arg mcp-gsc
```

### Hermes

```yaml
mcp_servers:
  pijusz-mcp-gsc:
    command: "npx"
    args: ["-y", "mcp-gsc"]
```

### Other

```json
{
  "mcpServers": {
    "pijusz-mcp-gsc": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-gsc"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 60, +14)

- [security regression] Known CVEs: unverified → fail
- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional regression] Tool coverage: 100 → unverified
- [functional regression] Capabilities: pass → unverified
- [functional improvement] License: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional] Licence: MIT

### 2026-08-01 (score 46, +22)

- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional regression] Dependency health: partial → unverified
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Tool coverage: unverified → 100

### 2026-07-31 (score 24, −10)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 34, −38)

- [security regression] Malware scan: pass → unverified
- [security regression] Provenance: fail → unverified
- [security regression] Known CVEs: fail → unverified
- [security regression] Install scripts: pass → unverified
- [security improvement] GHSA-frvp-7c67-39w9 no longer affects this package
- [functional regression] Dependency health: partial → unverified
- [functional regression] License: pass → unverified
- [functional regression] Maintenance: pass → unverified
- [functional] Licence: MIT

### 2026-07-29 (score 72, +46)

- [security regression] GHSA-frvp-7c67-39w9 affects this package: medium
- [security regression] Known CVEs: unverified → fail
- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [functional improvement] Schema quality: unverified → good
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] License: unverified → pass
- [functional improvement] Tool coverage: unverified → 100
- [functional] Licence: MIT

### 2026-07-28 (score 26, −16)

- [functional regression] Tool coverage: 100 → unverified
- [functional improvement] Dependency health: unverified → partial
- [functional] First check of Schema quality: unverified

### 2026-07-27 (score 42)

First indexed and scored.

## MCP tools (21)

### `list_properties` (~26 tokens)

List all Google Search Console properties you have access to, with permission levels and verification status.

### `get_property_details` (~33 tokens)

Get verification info, ownership, and permissions for a specific Google Search Console property.

Input parameters:

- `site_url` (string, required)

### `search_analytics` (~335 tokens)

Query Google Search Console search performance data (clicks, impressions, CTR, position) with filtering and grouping.

DIMENSIONS: query, page, country, device, date, searchAppearance, hour
\- "hour" requires data_state="hourly_all" and is limited to the last 10 days
\- "searchAppearance" CANNOT be combined with "query" or "page" (API restriction)

TYPE: web (default), image, video, news, discover, googleNews
\- "discover" = Google Discover feed. "googleNews" = Google News tab (distinct from "news")

DATA STATE: Controls data freshness.
\- "all" (default) includes recent incomplete data matching the GSC dashboard
\- "final" returns only confirmed data with a 2-3 day lag, useful for stable reporting
\- "hourly_all" enables hourly granularity but data may be incomplete for the current day

BRAND FILTER: Set to "brand_only" or "non_brand_only" to auto-filter queries by your domain name.

Country codes use ISO 3166-1 alpha-3 format (e.g., 'usa', 'gbr', 'deu') — NOT alpha-2.

Input parameters:

- `brand_filter` (string)
- `data_state` (string)
- `dimension_filters` (array)
- `dimensions` (array)
- `end_date` (string, required)
- `row_limit` (number)
- `site_url` (string)
- `start_date` (string, required)
- `start_row` (number)
- `type` (string)

### `list_sitemaps` (~47 tokens)

List all sitemaps for a property with status, type, indexed URL counts, errors/warnings.

Input parameters:

- `site_url` (string)
- `sitemap_index` (string)

### `get_sitemap` (~46 tokens)

Get detailed info for a specific sitemap including content breakdown by type (web, image, video, etc.).

Input parameters:

- `site_url` (string)
- `sitemap_url` (string, required)

### `inspect_url` (~60 tokens)

Inspect a URL's indexing status, crawl info, rich results, mobile usability, and canonical URLs. Counts against the daily 2,000 and per-minute 600 URL Inspection limits.

Input parameters:

- `site_url` (string)
- `url` (string, required)

### `batch_inspect_urls` (~63 tokens)

Inspect up to 10 URLs simultaneously. Returns categorized results (indexed, not indexed, issues). Each URL counts against the daily 2,000 and per-minute 600 URL Inspection limits.

Input parameters:

- `site_url` (string)
- `urls` (array, required)

### `export_csv` (~160 tokens)

Export search analytics data to a CSV file. Auto-paginates internally (25K rows per API call) to write the full dataset, bypassing the tool response row cap.

IMPORTANT: The GSC API has an absolute ceiling of 25,000 rows per query (sorted by impressions descending). For very large sites, this means the export will contain the top 25K query/page combinations, not the complete long tail. This is a Google API limitation, not a tool limitation.

Input parameters:

- `dimension_filters` (array)
- `dimensions` (array)
- `end_date` (string, required)
- `output_path` (string)
- `site_url` (string)
- `start_date` (string, required)
- `type` (string)

### `performance_overview` (~67 tokens)

Aggregate metrics (total clicks, impressions, avg CTR, avg position) plus a daily trend breakdown for a property. Single API call.

Input parameters:

- `end_date` (string, required)
- `site_url` (string)
- `start_date` (string, required)
- `type` (string)

### `compare_periods` (~89 tokens)

Compare two date ranges with delta calculations (absolute change + percentage change) for each dimension value. Makes 2 API calls.

Input parameters:

- `dimensions` (array)
- `end_date_1` (string, required)
- `end_date_2` (string, required)
- `site_url` (string)
- `start_date_1` (string, required)
- `start_date_2` (string, required)

### `top_movers` (~88 tokens)

Biggest gains and drops in clicks/impressions/position between two periods. Period A = start_date to end_date. Period B = the comparison_days before start_date.

Input parameters:

- `comparison_days` (number)
- `end_date` (string, required)
- `limit` (number)
- `metric` (string)
- `site_url` (string)
- `start_date` (string, required)

### `device_country_breakdown` (~50 tokens)

Performance breakdown by device type and/or country.

Input parameters:

- `breakdown` (string, required)
- `end_date` (string, required)
- `site_url` (string)
- `start_date` (string, required)

### `quick_wins` (~100 tokens)

Find high-impression, low-CTR queries in striking distance (position 4-20). These are opportunities to improve rankings and CTR with small content or SEO tweaks.

Input parameters:

- `end_date` (string, required)
- `max_ctr` (number)
- `max_position` (number)
- `min_impressions` (number)
- `min_position` (number)
- `site_url` (string)
- `start_date` (string, required)

### `cannibalization` (~72 tokens)

Detect keyword cannibalization — multiple pages ranking for the same query. Uses query + page dimensions to find overlap.

Input parameters:

- `end_date` (string, required)
- `min_impressions` (number)
- `mode` (string)
- `site_url` (string)
- `start_date` (string, required)

### `opportunity_finder` (~67 tokens)

Find queries with improving impressions but low clicks, new emerging queries, and declining performers. Makes 2 API calls to compare periods.

Input parameters:

- `comparison_days` (number)
- `end_date` (string, required)
- `site_url` (string)
- `start_date` (string, required)

### `position_tracking` (~79 tokens)

Track position changes for specific queries or pages over time. Uses date dimension with query/page filters. Returns daily or weekly averages.

Input parameters:

- `end_date` (string, required)
- `granularity` (string)
- `pages` (array)
- `queries` (array)
- `site_url` (string)
- `start_date` (string, required)

### `ctr_anomalies` (~69 tokens)

Detect queries/pages with abnormally low or high CTR relative to their position. Uses expected CTR curves per position bucket and flags deviations.

Input parameters:

- `end_date` (string, required)
- `min_impressions` (number)
- `site_url` (string)
- `start_date` (string, required)

### `content_decay` (~78 tokens)

Detect pages/queries where impressions have dropped significantly compared to their historical peak within the 16-month API window.

Input parameters:

- `decay_threshold` (number)
- `dimension` (string)
- `end_date` (string, required)
- `min_impressions` (number)
- `site_url` (string)
- `start_date` (string, required)

### `weekly_seo_report` (~68 tokens)

All-in-one SEO report: runs performance overview + quick wins + top movers + indexing issues summary. Returns a combined markdown report.

Input parameters:

- `comparison_days` (number)
- `end_date` (string, required)
- `site_url` (string)
- `start_date` (string, required)

### `indexing_coverage` (~60 tokens)

Batch-inspect user-provided URLs and categorize by indexing status: indexed, not indexed, canonical mismatch, robots blocked, fetch error, other. Respects URL Inspection rate limits.

Input parameters:

- `site_url` (string)
- `urls` (array, required)

### `sitemap_health` (~42 tokens)

Analyze all sitemaps: error/warning patterns, submission freshness (days since last submitted), indexed vs submitted ratio per sitemap.

Input parameters:

- `site_url` (string)

## Diagnostics

Captured diagnostic sections: Provenance, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/pijusz-mcp-gsc/mcp-gsc#diagnostics

## Score history

- 2026-08-03: 60
- 2026-08-02: 60
- 2026-08-01: 46
- 2026-07-31: 24
- 2026-07-30: 34
- 2026-07-29: 72
- 2026-07-28: 26
- 2026-07-27: 42

## Links

- npm package: https://www.npmjs.com/package/mcp-gsc
- Socket report: https://socket.dev/npm/package/mcp-gsc
- Repository: https://github.com/pijusz/mcp-gsc
- Changelog RSS feed: https://verifymcp.io/servers/pijusz-mcp-gsc/mcp-gsc/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/pijusz-mcp-gsc/mcp-gsc/changelog.json
- HTML version of this page: https://verifymcp.io/servers/pijusz-mcp-gsc/mcp-gsc
