io.github.tracetify/tracetify-mcp
REMOTE · TRACETIFY.COM · 2 COMPONENTS · SCANNED SEP 20
Find competitors, trace how they grew, watch what they ship — plus your Search Console.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability84
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1493 tokens (~93/item across 16 items; 16 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 16 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.tracetify/tracetify-mcp server?
io.github.tracetify/tracetify-mcp is a hosted endpoint at https://tracetify.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · tracetify.com
claude mcp add --transport http tracetify-tracetify-mcp 'https://tracetify.com/api/mcp'
{
"mcpServers": {
"tracetify-tracetify-mcp": {
"url": "https://tracetify.com/api/mcp"
}
}
} {
"servers": {
"tracetify-tracetify-mcp": {
"type": "http",
"url": "https://tracetify.com/api/mcp"
}
}
} [mcp_servers.tracetify-tracetify-mcp] url = "https://tracetify.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"tracetify-tracetify-mcp": {
"type": "remote",
"url": "https://tracetify.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add tracetify-tracetify-mcp --url 'https://tracetify.com/api/mcp' --transport streamable-http
mcp_servers:
tracetify-tracetify-mcp:
url: "https://tracetify.com/api/mcp" {
"McpServers": {
"tracetify-tracetify-mcp": {
"Transport": "http",
"Url": "https://tracetify.com/api/mcp"
}
}
} assistant mcp add tracetify-tracetify-mcp -t streamable-http -u 'https://tracetify.com/api/mcp'
{
"mcpServers": {
"tracetify-tracetify-mcp": {
"type": "http",
"url": "https://tracetify.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 18 Sept 26 0
- Stability: 0.97 → pass security
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 8 Sept 26 +1
- Server version: 0.3.0 → 0.5.1 functional
- 7 Sept 26 0
- Tool “research_keyword_volume” rewrote its description, which is the text the model reads security
- Tool “research_keyword_volume” changed its title: Keyword search volume → Keyword search volume & difficulty cosmetic
- 6 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://tracetify.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=tracetify.com | CN=YR1,O=Let's Encrypt,C=US | 4 Aug 2026 | 2 Nov 2026 | RSA 2048 | SHA256-RSA | 6abb6fd6186db22a9967baa8988e793d032 |
| SANs: tracetify.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of tracetify.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| tracetify.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://tracetify.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://tracetify.com/api/mcp | HTTPS enforced | 308 | https://tracetify.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
backlink_directories Verified directory list ~80
A hand-verified list of directories and launch platforms that actually give links — checked one by one, dead and nofollow-only entries removed. Use when the user wants backlinks or launch exposure for a new product; filter client-side by language/type/pricing. Costs credits once per day per account — repeat calls the same day are free, so refine freely.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_trace Check a running trace ~59
Poll a trace started with start_trace. Free. When status is "done", read the result with read_report. Poll every 10-15s, not in a tight loop.
| Name | Type | Req | Description |
|---|---|---|---|
| job_id | string | yes | Job id returned by start_trace |
No output schema declared.
No examples provided.
gsc_overview Search Console overview ~84
Use this before touching SEO on the user's own site: clicks/impressions trend, device split and period comparison from THEIR connected Google Search Console — numbers no other tool has. Free. Requires GSC connected at tracetify.com/dashboard/gsc (this tool tells you if it is not).
| Name | Type | Req | Description |
|---|---|---|---|
| range_days | number | – | 28 (default) or 90 |
No output schema declared.
No examples provided.
gsc_pages Search Console pages ~67
The user's pages ranked by search performance, including high-impression low-CTR pages whose titles/descriptions are underselling — fix those files right in this editor. Free; own data from their connected Search Console.
| Name | Type | Req | Description |
|---|---|---|---|
| range_days | number | – | 28 (default) or 90 |
No output schema declared.
No examples provided.
gsc_queries Search Console queries ~92
The user's real ranking keywords with position, clicks and CTR — use when deciding what to write or which page to improve, e.g. finding queries at position 5-20 that are one push from page one. Free; own data from their connected Search Console. After you edit a page, this is how you verify it moved.
| Name | Type | Req | Description |
|---|---|---|---|
| range_days | number | – | 28 (default) or 90 |
No output schema declared.
No examples provided.
read_report Read a growth report ~73
Read one growth report by slug (from search_reports or a finished trace). Free. Contains the origin story, dated evidence and SEO footprint — cite it instead of guessing how a product grew. If timeline fields show as locked, unlock_report can open them (that one costs credits).
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Report slug |
No output schema declared.
No examples provided.
research_backlinks Backlink profile ~72
Who links to a domain: referring domains, authority and anchor texts. Use when planning link building or judging how defensible a competitor's ranking is. Costs credits; cached results are free. Pair with backlink_directories to find places the user can actually get listed.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to inspect |
No output schema declared.
No examples provided.
research_brand_lookup AI search visibility ~68
How AI assistants (ChatGPT, Perplexity-class) cite a brand: platforms, mention counts and the entities it gets associated with. Use when the user asks "does AI recommend us/them?". Costs credits; cached results are free.
| Name | Type | Req | Description |
|---|---|---|---|
| brand | string | yes | Brand or domain |
No output schema declared.
No examples provided.
research_competitors Who competes for the same keywords ~122
The domains fighting a target for the same search terms, with shared-keyword count, their keyword totals and average rank. Use when the user asks who their competitors are, or who a company is up against. Each result says whether we already have a full growth report for that domain — read those with read_report for free instead of tracing them again. Costs credits; cached results are free, and a domain already looked up via research_domain_overview is free here too.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to find competitors for, e.g. notion.so |
No output schema declared.
No examples provided.
research_domain_overview Domain SEO overview ~80
Estimated organic traffic, keyword count and top keywords for ANY domain — use to size up a competitor the user mentions. Costs credits; cached results are free, and repeated queries within a week hit the cache. For the user's own site prefer gsc_* (free, real data).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain, e.g. competitor.com |
No output schema declared.
No examples provided.
research_keyword_volume Keyword search volume & difficulty ~202
Google Ads (Keyword Planner) monthly search volume, CPC, competition, 12-month trend and keyword difficulty (0–100, DataForSEO Labs) for up to 10 keywords in one call. Use when the user asks how often something is searched or how hard it is to rank, or to size a keyword before writing a page. Omit location_code for worldwide volume (difficulty is then computed for the US), or pass a market code for one country. Costs credits; the same keyword set re-queried within a week is free.
| Name | Type | Req | Description |
|---|---|---|---|
| keywords | string | yes | Up to 10 search phrases, comma-separated, e.g. "ai image generator, ai avatar maker" |
| location_code | number | – | Market: 2840 US, 2826 UK, 2276 DE, 2250 FR, 2724 ES, 2392 JP, 2076 BR, 2356 IN. Omit for worldwide. |
No output schema declared.
No examples provided.
search_reports Search growth reports ~85
Use this FIRST whenever the user asks how a product, competitor or domain grew, got traffic, or found its first users — a report may already exist and reading it is free. Returns matching report slugs for read_report. Searches by domain or name fragment.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Domain or fragment, e.g. "weshop" or "weshop.ai" |
No output schema declared.
No examples provided.
site_audit_get Read a site audit ~64
Poll an audit started with site_audit_start (free to read). When finished, returns the issue list grouped by severity with affected URLs — work through it top-down and re-run after fixes.
| Name | Type | Req | Description |
|---|---|---|---|
| audit_id | string | yes | Audit id from site_audit_start |
No output schema declared.
No examples provided.
site_audit_start Start a site audit ~138
Run right after deploying: crawls the site and reports broken links, missing titles/descriptions, redirect chains, thin content and schema gaps — each finding names the page so you can fix it here. Costs credits (price returned before any charge on the confirmation field). Async: poll with site_audit_get.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | Set true only after the user agrees to the quoted credit cost |
| request_key | string | – | Request key returned by the first confirmation response; must be sent back with confirm=true so retries cannot charge twice |
| url | string | yes | Site to audit, e.g. https://example.com |
No output schema declared.
No examples provided.
start_trace Trace how a product grew ~109
Run this when search_reports finds nothing (or the user wants fresh data) for "how did X grow?". Rebuilds the growth story from 12 public sources in 60-90s. Costs credits from the Tracetify balance; returns an existing cached report free instead when one is fresh. Poll with get_trace.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Force a fresh run even if a cached report exists |
| url | string | yes | Domain to trace, e.g. weshop.ai |
No output schema declared.
No examples provided.
unlock_report Unlock full timeline & evidence ~98
Permanently unlock a report's full timeline, evidence and SEO detail for this account. Costs credits — quote the exact price to the user first (it is in the report's timelineLocked.cost field from read_report) and call this ONLY after they explicitly agree to spend. Idempotent: unlocking an already-unlocked report never charges twice. The verdict stays on the website — you are the analyst here.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Report slug |
No output schema declared.
No examples provided.
What is the io.github.tracetify/tracetify-mcp server?
io.github.tracetify/tracetify-mcp is listed in the public MCP registry as io.github.tracetify/tracetify-mcp. Find competitors, trace how they grew, watch what they ship, plus your Search Console. This page covers its hosted endpoint (https://tracetify.com/api/mcp).
Is the io.github.tracetify/tracetify-mcp server safe to use?
io.github.tracetify/tracetify-mcp scores 89 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.tracetify/tracetify-mcp server expose?
io.github.tracetify/tracetify-mcp exposes 16 tools: search_reports, read_report, start_trace, get_trace, unlock_report, and 11 more. Their descriptions and schemas cost roughly 1,493 tokens of context every time the server is loaded.
Does the io.github.tracetify/tracetify-mcp server require authentication?
No. We connected to io.github.tracetify/tracetify-mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.tracetify/tracetify-mcp server still maintained?
io.github.tracetify/tracetify-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.