PluginBench
MCP Server
Active
MIT

squirrelscan MCP Server

com.squirrelscan/squirrelscan

Website QA tool for coding agents: audit SEO, performance, security, accessibility with 273 rules and exact fixes over MCP.

What is the squirrelscan MCP server?

The squirrelscan MCP server is a website quality assurance tool that audits sites across 21 categories including SEO, performance, security, accessibility, and agent experience. It provides 273 rules with deterministic results and actionable fixes, designed to integrate with coding agents like Claude and Cursor via MCP protocol.

squirrelscan audits websites for quality issues across SEO, performance, security, accessibility, and agent experience. It runs as a CLI tool, within coding agents, or over MCP, giving your AI agent exact fixes for detected problems. Use it to catch regressions, improve site quality scores, and ensure your site is ready for both search engines and AI agents.

How to install squirrelscan

Copy-paste configuration for popular MCP clients.

transport: http
Config generated by PluginBench — verify against the source before use.
~/.cursor/mcp.json
{
  "mcpServers": {
    "squirrelscan": {
      "url": "https://mcp.squirrelscan.com/mcp"
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • audit — Run comprehensive website audits across 273 rules in 21 categories (SEO, performance, security, accessibility, agent experience, etc.)
  • crawl — Fast, memory-efficient website crawler with smart incremental crawling using ETags, Last-Modified headers, and content hashing
  • report-generation — Generate reports in multiple formats: console, JSON, HTML, Markdown, text, LLM-optimized, and XML
  • publish-reports — Publish audit reports to the web for sharing with team members or coding agents with embedded fix instructions
  • rule-filtering — Run specific rule categories or individual rules using --rule-include and --rule-exclude flags
  • crawl-history — Track site evolution, compare crawls, and detect regressions over time

Use cases

  • Audit a website for SEO, performance, security and accessibility issues before deployment
  • Generate shareable HTML reports with category scores and actionable fix instructions
  • Integrate website QA into your coding agent workflow to automatically detect and fix site quality issues
  • Run incremental crawls to track site changes and catch regressions between audits
  • Audit agent experience to ensure your site is optimized for AI agents like Claude and GPTBot

squirrelscan MCP server FAQ

What is squirrelscan?

squirrelscan is a website QA tool that audits sites across 273 rules in 21 categories: SEO, performance, security, accessibility, agent experience, and more. It provides exact fixes and integrates with coding agents via MCP.

Is squirrelscan free?

The CLI is open source and free to use. Cloud features (rendering, cloud audits) require authentication and may have usage limits; check the documentation for details.

How do I install squirrelscan in Cursor?

Click the 'Add to Cursor' badge on the GitHub repository, or manually add to ~/.cursor/mcp.json: {"mcpServers": {"squirrelscan": {"url": "https://mcp.squirrelscan.com/mcp"}}}

How do I add squirrelscan to Claude Code?

Run `/plugin marketplace add squirrelscan/squirrelscan` then `/plugin install squirrelscan@squirrelscan`, or add just the MCP server with `claude mcp add --transport http squirrelscan https://mcp.squirrelscan.com/mcp`

Does squirrelscan require authentication?

Basic CLI audits work without authentication. Cloud features (cloud rendering, cloud audits, publishing reports) use per-user OAuth or API key authentication.

What output formats does squirrelscan support?

Console (default), JSON, HTML, Markdown, text, LLM-optimized, and XML. Use the -f flag to specify format, e.g., `squirrel audit example.com -f html -o report.html`

README (reference)

Source of truth, from the repository.

squirrelscan

squirrelscan

The website QA tool for your coding agent

squirrelscan is an Open Source cli tool that audits websites for SEO, performance, security, accessibility, agent experience and other issues, and gives your coding agent exact fixes. Run it from the CLI, inside your coding agent, in the cloud, or over MCP.

Combine your coding agent with a deterministic and extensible audit tool.

Add to Cursor Add to Claude Code Add to Codex Add to opencode MCP Registry

CI CodeQL npm License: MIT

Features

  • 273 Rules, 21 Categories - Comprehensive coverage across SEO, accessibility, performance, and security
  • Fast crawler - Highly optimized memory efficient crawler
  • Agent Experience - Audit agent experience to assist agents in using your site
  • Security Audit - Detect phishing kits, leaked credentials, and more
  • Smart Incremental Crawling - ETag, Last-Modified, content hashing. Resume from checkpoints.
  • Developer-First CLI - Single binary, zero dependencies, shell completions, self-update
  • Crawl History & Changes - Track site evolution, compare crawls, spot regressions
  • Multiple Output Formats - Console, JSON, HTML, Markdown, Text, LLM, XML
  • MCP Connection - Connect your agent to local or cloud MCP to run audits, fixes, etc.

Rule Categories

Ordered by how much a failure usually costs you, not by how many rules each one has.

CategoryRulesWhat it covers
Crawlability18Whether search engines and agents can reach and index you at all: robots.txt, sitemap validity and coverage, indexability conflicts, redirect and canonical chains, soft 404s
Core SEO14The per-page fundamentals: title, meta description, H1, canonical, charset, doctype, robots meta, Open Graph and Twitter cards, plus canonical form drift across the site
Agent Experience17How ready you are for AI agents to read, discover and act on the site: whether GPTBot and Claude-User get the same content a browser does, AGENTS.md, llms.txt, Markdown responses, API and MCP discovery, licensing and noai signals, pay-per-crawl, response token weight
Site Integrity9Signs the site has been compromised: injected doorway pages, phishing kit signatures, obfuscated scripts, brand impersonation, cloaking, known-malicious URLs
Security16Transport and header hygiene: HTTPS and HSTS, CSP, cookie flags, mixed content, subresource integrity, leaked secrets, unprotected and downgraded forms
Links14Internal and external link health: broken and dead links, redirect chains, anchor-text quality, orphan and dead-end pages, HTTPS downgrades
Content17Text quality and honesty: duplicate titles and descriptions, title-template consistency, readability, word count, freshness, heading hierarchy, keyword stuffing, hidden text, encoding damage
Performance29Core Web Vitals and delivery: LCP, CLS and INP hints, TTFB, compression, caching, render-blocking resources, DOM size, font delivery, legacy and unminified JS/CSS
Images15Alt text, modern formats, responsive srcset, intrinsic dimensions and aspect-ratio mismatches, lazy loading above versus below the fold, file weight
Structured Data12JSON-LD validity and rich-result eligibility for Article, Product, FAQ, Review, Breadcrumb, Organization, LocalBusiness, Video and site search, plus rating markup that is not about the page it sits on
Accessibility61WCAG coverage: ARIA roles and names, form labels and autocomplete tokens, colour contrast, heading order, landmarks, tables and lists, focus visibility, touch targets, captions
Mobile6Viewport configuration, tap-target size, legible font sizes, horizontal scroll, blocked zoom, intrusive interstitials
Social Media4Open Graph and Twitter Card completeness, image dimensions, canonical URL match, social profile links
URL Structure9Length, casing, hyphenation, stop words, query parameters, special characters, trailing-slash consistency, site-wide convention consistency
E-E-A-T15Experience, expertise, authority and trust signals: author bylines and credentials, about and contact pages, citations, editorial policy, disclaimers, YMYL detection
Legal Compliance4Privacy policy, terms of service, real cookie-consent machinery, subprocessor disclosure
Internationalization2hreflang correctness and the document language declaration
Local SEO3NAP (name, address, phone) consistency across every crawled page, geo metadata, service-area businesses
Video3VideoObject markup, captions and accessibility, thumbnails
Analytics2Google Tag Manager presence and consent-mode wiring
Blocking3Content, links and trackers that ad blockers and privacy filters strip for a large share of your visitors

Total: 273 rules across 21 categories

See the rules reference for full details.

CLI

Installation

macOS / Linux:

curl -fsSL https://install.squirrelscan.com | bash

Windows:

iwr -useb https://install.squirrelscan.com/install.ps1 | iex

npm (all platforms):

npm install -g squirrelscan

npx (run without installing):

npx squirrelscan audit example.com

Quick Start

# Audit a website
squirrel audit example.com

# Generate HTML report
squirrel audit example.com -f html -o report.html

# Pipe to Claude for AI analysis
squirrel audit example.com --format llm | claude

# Quick audit for fast initial probe (other options surface, full)
squirrel audit example.com -C quick

# run only agent experience and performance rules
squirrel audit example.com --rule-include ax,performance

# login for cloud audits and cloud rendering 
squirrel auth login

Reports

Category scores for SEO, performance, security and Agent Experience (AX). Publish reports to the web to share with team members or coding agents (fix instructions are embedded)

squirrelscan report

see an example report

Add to your coding agent

squirrelscan ships as an MCP server (hosted at mcp.squirrelscan.com), skills (autonomous audit + fix workflows), and a plugin for Claude Code and Cursor. Cursor installs in one click from the badge above; the rest are a single copy-paste.

Cursor

Click the Add to Cursor badge above, or add it manually to ~/.cursor/mcp.json:

{
  "mcpServers": {
    "squirrelscan": { "url": "https://mcp.squirrelscan.com/mcp" }
  }
}

Skills: npx skills add squirrelscan/squirrelscan

Claude Code

Install the plugin (bundles skills + the MCP server):

/plugin marketplace add squirrelscan/squirrelscan
/plugin install squirrelscan@squirrelscan

Or add just the MCP server:

claude mcp add --transport http squirrelscan https://mcp.squirrelscan.com/mcp

OpenAI Codex

Add the server to ~/.codex/config.toml:

[mcp_servers.squirrelscan]
url = "https://mcp.squirrelscan.com/mcp"

Codex reads Agent Skills from ~/.agents/skills, so skills work too: npx skills add squirrelscan/squirrelscan

opencode

Add the server to opencode.json:

{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "squirrelscan": {
      "type": "remote",
      "url": "https://mcp.squirrelscan.com/mcp",
      "enabled": true
    }
  }
}

Any MCP client

squirrelscan is in the MCP Registry as com.squirrelscan/squirrelscan. Point any client at the remote server:

https://mcp.squirrelscan.com/mcp

Authentication is per-user OAuth (or pass a squirrelscan API key as a Bearer token). Skills follow the Agent Skills standard: npx skills add squirrelscan/squirrelscan lands them in .agents/skills/.

Skills

Two skills drive agent workflows:

  • squirrelscan - operating the CLI: install, login, keys, credits, running audits, publishing reports, MCP setup, config, troubleshooting.
  • audit-website - the full fix loop: audit, map issues to source files, fix in batches, re-audit until the site scores well.
npx skills add squirrelscan/squirrelscan

Then, in your agent:

Use the audit-website skill to audit this site and fix all issues but only crawl 10 pages

Output Formats

FormatFlagUse Case
Console(default)Human-readable terminal output
JSON-f jsonCI/CD, programmatic processing
HTML-f htmlVisual reports for sharing
Markdown-f markdownDocumentation, GitHub
Text-f textClean output for piping to LLMs
LLM-f llmLLM optimized output
XML-f xmlXML output

Source and development

The complete local CLI, crawler, audit engine, rules, report generators, CLI-facing cloud clients, and documentation site are open source in this repository. The hosted API, website, dashboard, and cloud worker implementations are separate private services.

Prerequisites: Bun 1.3.14 and Git.

git clone https://github.com/squirrelscan/squirrelscan.git
cd squirrelscan
bun install --frozen-lockfile
bun run dev -- audit https://example.com --max-pages 10

Run the same checks used in pull requests:

bun run format:check
bun run lint
bun run typecheck
bun test
bun run build
bun run docs:check
bun run docs:build

See CONTRIBUTING.md before opening a pull request. Contributions require a Developer Certificate of Origin sign-off (git commit -s).

Telemetry

Telemetry is enabled by default and is deliberately minimal: event name, CLI version, a random install ID, and bounded error categories. It does not send credentials, URLs, report contents, or raw error messages, and telemetry requests are never authenticated.

Disable it permanently with:

squirrel self settings set telemetry false

Or disable all telemetry and install registration for any invocation by defining NO_TELEMETRY. Any defined value works, including an empty value, 0, or false:

NO_TELEMETRY=1 squirrel audit https://example.com

Links

License

The CLI and the repository contents are licensed under the MIT License. squirrelscan names and logos are covered by TRADEMARKS.md.

Related MCP servers

SR&ED Claim Calculator: the site's own MCP server — calculator, enquiry (enquiry = a human...

View repository →

SR&ED Finder: the site's own MCP server — compare, enquiry (enquiry = a human handoff, not a...

View repository →

Industry-standard bond math for AI agents: price, yield, accrued interest, duration, yield-to-worst

Create AI-powered short-form video clips from YouTube videos. Supports webhook callbacks.

4
JavaScript
MIT
View repository →

Agent-only BBS: live channels, persistent threads, artifact drops, signed history, ROOT takeovers.

Five read-only tools: spot prices, observed premiums, price history, Goldback rate, and currencies.