GEO intelligence platform for B2B with AI bot monitoring, competitor analysis, revenue risk quantification, and defense code generation.
Review before connecting
The findings on this server are worth reviewing before you connect an agent to it.
Scanned 6 days ago
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The Lotus GEO Engine MCP server exposes 16 tools, focused primarily on developer capabilities. Its published description reads: "GEO intelligence platform for B2B with AI bot monitoring, competitor analysis, revenue risk quantification, and defense code generation". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates Lotus GEO Engine C — the findings are worth reviewing before you connect an agent to it. Its most notable findings include "Cross-tool shadowing" and "No authorization on a public remote server". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check Lotus GEO Engine's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add Lotus GEO Engine to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://lotus.clicon.app/mcp/Streamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Analyze a domain's visibility across AI-generated answers. Without an API key: returns a limited preview (1/day per IP, 3/week). With a valid API key: returns the full analysis including measured metr
Return pending and applied quick wins for a domain. Requires a valid API key (pro, growth or agency).
Generate ready-to-install code for a quick win, identified by its hash. Only available for structured_data quick wins. Requires a valid API key.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: get_report_data
A tool description tries to alter the model’s use of another tool.
erated with generate_share_link, without opening the public URL in a browser.RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: regenerate_artifacts
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
Analyze web pages and entire sites for SEO, accessibility, performance, and security compliance. Generate detailed reports and actionable issue lists to improve site quality and user experien
Validates ZUGFeRD, Factur-X, and XRechnung e-invoices against EN 16931 with correction suggestions.
Tracks US tariff and trade-action changes from Federal Register documents and exposes them through an API for AI agents.
Instant rug-check for any EVM or Solana token, distilled to one clear 0-10 risk verdict.
Provides access to Bible translations, books, chapters, verses, and search functionality.
Remote-first MCP adapter for emitting Settlement Attestation Receipts; not a verifier.
Verify-before-mark: checks that the expected schema is actually present in the live DOM of the site before marking the quick win as applied. Only marks it if the expected @type is found among the sche
Return pending and completed competitor actions for a domain. Requires a valid API key (pro, growth or agency).
Return the most recent artifact (llms_txt or json_ld) for the authenticated client: content, version, generated_at and status. Use when an agent needs to read the generated llms.txt or JSON-LD. artifa
Return AI crawler activity for the authenticated client's domain: total hits, breakdown per bot, most recent hits and last-seen per bot. Use when an agent needs to assess how frequently AI crawlers vi
Return the traffic erosion model for the authenticated client: cascading metrics with their *_source provenance labels, plus the resulting revenue-at-risk calculation. Use when an agent needs to asses
Check live whether llms.txt and JSON-LD are correctly installed on the authenticated client's domain. Returns an overall status (fully_deployed / partially_deployed / not_deployed) plus the detailed r
Return the most recent citation score for the authenticated client, along with the measurements from that same week (safe fields only). Raw data — no healthy/critical classification applied. Use when
Generate a public report link for the authenticated client and persist it. Returns {report_url, slug}. Use when an agent needs to create a shareable report covering the client's full visibility status
Regenerate the GEO artifacts (llms_txt, json_ld and supporting schema nodes) for the authenticated client. Respects a 6h cooldown and the daily generation budget. Use when an agent needs to force rege
Return the full report payload for a share link slug owned by the authenticated client. Returns the report even if the share link has expired. Use when an agent needs to read a report it previously ge
Return artifacts (llms_txt, json_ld, defense_nodes) for the authenticated client, without their content payload. Optionally filter by exact status (e.g. "pending_review", "approved"). Use status="" to
Approve an artifact by its ID. The artifact must belong to the authenticated client's domain. Approved artifacts are ready for activation but are not yet live on the site. Use when an agent has review
Activate an artifact by its ID. The artifact must belong to the authenticated client's domain. Activation makes the artifact live — only one version of a given type can be active at a time. Use when a