Serveur MCP

Agentwatch

lighting.comiza/agentwatch
Marketing et publicité Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Tests website accessibility to AI crawlers, identifies crawler traffic, and verifies HTTP bot signatures.

check_site
Check whether AI assistants can read a site
Fetch a website the way ChatGPT, Claude, Perplexity, Google and Copilot fetch it, and report what stops them. Checks robots.txt per crawler with the deciding line number, makes real requests as each crawler to catch firewall and CDN rules that robots.txt cannot express, and measures whether the page carries readable text without JavaScript. Use this before advising anyone on why their site does not appear in AI answers: the usual cause is one of these three and none of them are visible from the outside.
Schéma d’entrée
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'Domain or URL, for example example.com'}}}
list_ai_crawlers
List the AI crawlers and what each one is for
The robots.txt tokens used by the major assistants, separated by purpose: the ones that build the index answers come from, the ones that fetch a page live when a person asks, and the ones that only collect training data. Blocking the last group costs no visibility; blocking the first two removes a site from the answers. Use this before writing or editing a robots.txt.
Schéma d’entrée
{'type': 'object', 'properties': {}}
verify_crawler_visit
Check whether a crawler visit was genuine
Given the IP address and User-Agent from a log line, say whether that visit really came from the crawler it claims to be. Checks the address against the vendor's own published ranges where they exist, and falls back to forward-confirmed reverse DNS. On one ordinary server's logs, 14% of requests claiming to be Googlebot were not Google. Use this before anyone writes a firewall rule based on a user agent string, because that string is a claim and not proof.
Schéma d’entrée
{'type': 'object', 'required': ['ip', 'user_agent'], 'properties': {'ip': {'type': 'string', 'description': 'Source address from the log line.'}, 'user_agent': {'type': 'string', 'description': 'User-Agent from the same line.'}}}
verify_signed_request
Verify an HTTP Message Signature on a request
Verify a Web Bot Auth signature (RFC 9421, Ed25519) on a captured request. Unlike an address check, this proves who sent that exact request: it fetches the signer's published key directory, rebuilds the signature base from the covered components, and checks the signature. Use it when a request carries Signature-Input and Signature headers. Returns 'unsigned' when they are absent, and 'cannot_verify' rather than 'invalid' whenever the limitation is on our side.
Schéma d’entrée
{'type': 'object', 'required': ['url', 'headers'], 'properties': {'url': {'type': 'string', 'description': 'Full URL as requested; the signature covers it.'}, 'method': {'type': 'string', 'default': 'GET', 'description': 'HTTP method of the captured request, uppercase. It is part of the signature base whenever the signature covers @method, so a wrong value fails verification. Defaults to GET.'}, 'headers': {'type': 'object', 'description': 'Request headers, including Signature-Input, Signature and Signature-Agent.'}}}
Ajouté
list_ai_crawlers
17 September 2026 12:54
Ajouté
verify_signed_request
17 September 2026 12:54
Ajouté
verify_crawler_visit
17 September 2026 12:54
Ajouté
check_site
17 September 2026 12:54