Pilot AEO and GEO from Claude: bulk audits, server-side WordPress fixes, and AI citation tracking.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The aeotool MCP server exposes 36 tools, focused primarily on AI capabilities. Its published description reads: "Pilot AEO and GEO from Claude: bulk audits, server-side WordPress fixes, and AI citation tracking". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates aeotool F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Data-exfiltration parameters" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check aeotool's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add aeotool to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://aeotool.io/api/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Liste les sites WordPress connectés au compte (plugin Everlange Connect) : domaine, statut, modules actifs, version du bundle.
Lance un audit AEO/GEO d’une URL (asynchrone, ~2 min) et renvoie immédiatement l’audit_id. Suivre avec aeo_audit_status jusqu’à completed, puis aeo_report / aeo_improvements. Coûte 50 GTO, débités à l
Statut d’un audit lancé par aeo_audit : pending/processing → completed (avec le score) ou failed. Gratuit : poll toutes les 20-30 s.
Lance l’audit de plusieurs sites en une commande (le « killer agence »), en asynchrone : renvoie immédiatement un audit_id par URL. Suivre chaque id avec aeo_audit_status. Coûte 50 GTO par site, débit
Renvoie le détail complet d’un audit existant (par audit_id) : score global, scores par catégorie et tous les critères (score + recommandation). Gratuit.
La CHECKLIST d’améliorations d’un audit : groupées par niveau (1=auto-applicable plugin, 2=générable, 3=rebuild/lead), triées par gain projeté. Fournit les ids à passer à aeo_apply. Passer audit_id OU
Génère (sans appliquer) un artefact AEO, déterministe et gratuit. Types : jsonld, robots, llms, meta, faq (params faqs[]), ai-txt, humans-txt, security-txt, sitemap. jsonld/robots/llms/meta/faq sont a
APPLIQUE la sélection d’améliorations niveau 1 (jsonld/robots/llms/meta) sur un site connecté : génère + archive les correctifs et bump le bundle → le plugin les injecte au prochain sync. Optionnel :
Historique de citation d’un domaine dans les moteurs IA : taux de citation par date, détail par moteur, part de voix. Renvoie `series[].basis` = "measured" ou "derived" (dénominateur reconstitué sur l
La PREUVE : compare les 2 derniers audits complétés d’un domaine : delta de score, critères améliorés, critères régressés. L’argument client en un appel. Gratuit.
Programme un scan de citations récurrent côté serveur (10 moteurs IA, part de voix vs watchlist, alertes email). action=create {domain, brand_name?, frequency: daily|weekly|biweekly} · list · delete {
Liste les comptes Google Ads connectés au compte aeotool (OAuth) : customer_id, nom, statut, is_manager (MCC, non requêtable directement, ses comptes clients apparaissent aussi dans la liste), write_e
Performance des campagnes Google Ads sur N jours (défaut 30) : impressions, clics, coût, conversions, CTR, CPC moyen, budget/jour : triées par coût. Gratuit.
Termes de recherche réels ayant déclenché les annonces (N jours, triés par coût) avec le flag wasted=true (coût sans conversion) : candidats directs pour ads_add_negative_keywords. Gratuit.
Qui a change quoi et quand sur le compte (30 jours max, retention Google). Signale les changements de budget ou d'encheres qui ont pu RELANCER la phase d'apprentissage : les metriques anterieures ne s
Decompose le Quality Score de chaque mot-cle en ses trois composantes Google (pertinence de l'annonce, experience sur la page de destination, CTR attendu) et designe la cause DOMINANTE. Un QS bas se c
Performance de chaque page de destination (cout, clics, conversions, taux de conversion) et liste des pages qui ont recu au moins 10 clics payants SANS une seule conversion. Ces URLs sont directement
Performance par zone REELLE de l'internaute (ville / region), libelles resolus, avec les zones qui depensent sans convertir. Determinant pour une activite a zone de chalandise. Gratuit, lecture seule.
Note Google de chaque titre et description d'annonce responsive (LOW / GOOD / BEST / en cours d'evaluation). Remplacer les LOW par des variantes des BEST est l'optimisation creative la moins risquee :
Zones, appareils et plages horaires cibles par les campagnes, avec leur ajustement d'enchere actuel et leur criterion_id. Lecture prealable indispensable a ads_set_bid_modifier et ads_remove_criterion
Trouve l'identifiant Google d'une zone a partir de son nom (ville, departement, region) : seule forme acceptee par ads_add_location. Gratuit.
Listes de remarketing disponibles et leur taille, avec celles qui atteignent le seuil de diffusion sur le reseau de recherche (~1 000 utilisateurs). Gratuit.
Cout, conversions et cout par conversion par appareil (mobile, ordinateur, tablette). Prealable a tout ajustement d'enchere par appareil. Gratuit.
ECRITURE GARDEE. Ajuste l'enchere d'un critere existant : 1.0 = aucun ajustement, 1.2 = +20 %, 0.8 = -20 %, 0 = exclusion. Reversible en repassant a 1. Dry-run valide par Google d'abord ; confirm:true
ECRITURE GARDEE. Ajoute une zone au ciblage d'une campagne, ou l'exclut avec negative:true. L'identifiant s'obtient avec ads_geo_target_search. Dry-run valide par Google d'abord ; confirm:true pour ap
ECRITURE GARDEE. Retire un critere de ciblage d'une campagne (zone, audience, ajustement). Un retrait se repare en RECREANT le critere, pas en annulant. Dry-run valide par Google d'abord ; confirm:tru
ECRITURE GARDEE. Rattache une liste de remarketing a une campagne. Mode observation par defaut : la diffusion NE CHANGE PAS, l'audience est seulement mesuree. Le mode targeting restreint la diffusion
Mots-clés actifs avec leurs métriques (N jours) et les ids nécessaires aux actions (ad_group_id + criterion_id pour ads_pause_keyword). Gratuit.
Audit complet du compte Google Ads : score /100, grade, € gaspillés/mois, manque à gagner, quick wins par catégorie (tracking, gaspillage, enchères, structure, RSA…). Lecture seule, gratuit.
ÉCRITURE GARDÉE : ajoute des mots-clés négatifs (1-50) à une campagne. Sans confirm:true : dry-run validé par Google (rien n’est appliqué). Nécessite le pilotage activé pour ce compte (ads_list_accoun
ÉCRITURE GARDÉE : met un mot-clé en pause (réversible dans Google Ads). ids via ads_keywords. Sans confirm:true : dry-run validé par Google. Pilotage requis (write_enabled) ; journalisé.
ÉCRITURE GARDÉE : modifie le budget quotidien d’une campagne. Caps : ±20 % max par appel, plafond absolu (env ADS_MAX_DAILY_BUDGET_EUR, défaut 200 €/j), budgets partagés refusés. Sans confirm:true : d
ÉCRITURE GARDÉE : met une campagne en pause ou la réactive (réversible). Sans confirm:true : dry-run validé par Google. Pilotage requis (write_enabled) ; journalisé.
Annonces (RSA…) avec métriques N jours et ids (ad_group_id + ad_id) nécessaires à ads_ad_status. Gratuit.
ÉCRITURE GARDÉE : met une annonce individuelle en pause ou la réactive (réversible). ids via ads_list_ads. Dry-run Google puis confirm:true. Pilotage requis (write_enabled) ; journalisé.
ÉCRITURE GARDÉE : ajoute des mots-clés POSITIFS (1-20) à un groupe d’annonces. ad_group_id via ads_keywords. Dry-run Google puis confirm:true. Pilotage requis (write_enabled) ; journalisé.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: aeo_audit
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: aeo_audit
A tool description tries to alter the model’s use of another tool.
id. Suivre avec aeo_audit_status jusqu’à completed, puis aeo_report / aeo_improvRecommendationDescriptions must describe only their own tool.
tool: aeo_audit_status
A tool description tries to alter the model’s use of another tool.
audit lancé par aeo_audit : pending/processing → completed (avec le scoreRecommendationDescriptions must describe only their own tool.
tool: aeo_batch_audit
A tool description tries to alter the model’s use of another tool.
chaque id avec aeo_audit_status. Coûte 50 GTO par site, débités à la complétionRecommendationDescriptions must describe only their own tool.
tool: aeo_improvements
A tool description tries to alter the model’s use of another tool.
ids à passer à aeo_apply. Passer audit_id OU domain (= dernier audit terRecommendationDescriptions must describe only their own tool.
tool: aeo_generate
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: aeo_generate
A tool description tries to alter the model’s use of another tool.
pplicables (cf. aeo_apply) ; ai-txt/humans-txt/security-txt/sitemap sontRecommendationDescriptions must describe only their own tool.
tool: aeo_apply
A tool description tries to alter the model’s use of another tool.
être connecté (aeo_list_sites).RecommendationDescriptions must describe only their own tool.
tool: ads_search_terms
A tool description tries to alter the model’s use of another tool.
ts directs pour ads_add_negative_keywords. Gratuit.RecommendationDescriptions must describe only their own tool.
tool: ads_landing_pages
A tool description tries to alter the model’s use of another tool.
auditables avec aeo_audit : le diagnostic de citabilite et celui de conveRecommendationDescriptions must describe only their own tool.
tool: ads_campaign_criteria
A tool description tries to alter the model’s use of another tool.
indispensable a ads_set_bid_modifier et ads_remove_criterion. Gratuit.RecommendationDescriptions must describe only their own tool.
tool: ads_geo_target_search
A tool description tries to alter the model’s use of another tool.
me acceptee par ads_add_location. Gratuit.RecommendationDescriptions must describe only their own tool.
tool: ads_add_location
A tool description tries to alter the model’s use of another tool.
s'obtient avec ads_geo_target_search. Dry-run valide par Google d'abord ; confirm:trRecommendationDescriptions must describe only their own tool.
tool: ads_keywords
A tool description tries to alter the model’s use of another tool.
iterion_id pour ads_pause_keyword). Gratuit.RecommendationDescriptions must describe only their own tool.
tool: ads_add_negative_keywords
A tool description tries to alter the model’s use of another tool.
pour ce compte (ads_list_accounts → write_enabled). Chaque application est journaRecommendationDescriptions must describe only their own tool.
tool: ads_pause_keyword
A tool description tries to alter the model’s use of another tool.
e Ads). ids via ads_keywords. Sans confirm:true : dry-run validé par Google.RecommendationDescriptions must describe only their own tool.
tool: ads_list_ads
A tool description tries to alter the model’s use of another tool.
) nécessaires à ads_ad_status. Gratuit.RecommendationDescriptions must describe only their own tool.
tool: ads_ad_status
A tool description tries to alter the model’s use of another tool.
sible). ids via ads_list_ads. Dry-run Google puis confirm:true. Pilotage reqRecommendationDescriptions must describe only their own tool.
tool: ads_add_keywords
A tool description tries to alter the model’s use of another tool.
ad_group_id via ads_keywords. Dry-run Google puis confirm:true. Pilotage reqRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
sites clients : aeo_list_sites → aeo_batch_audit → aeo_improvements (par auditRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: aeo_audit
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: aeo_batch_audit
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_performance
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_search_terms
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_change_history
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_quality_breakdown
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_landing_pages
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_geo_performance
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_asset_performance
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_campaign_criteria
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_geo_target_search
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_audiences
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_device_performance
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_set_bid_modifier
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_add_location
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_remove_criterion
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: ads_attach_audience
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_keywords
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_audit
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_add_negative_keywords
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_pause_keyword
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_update_budget
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: ads_campaign_status
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_list_ads
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_ad_status
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: ads_add_keywords
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.