Security
Examines public security signals and, for verified targets, protected modules such as deeper authorized checks.
audit_security
OpenAI-compatible remote MCP
Sitelemetry gives OpenAI clients a focused set of target-safe tools for security, discoverability, accessibility and performance checks. Every remote call is protected by OAuth.
01 / Capabilities
Each tool accepts an explicit target and returns prioritized findings, compact evidence and remediation guidance. The service does not change the target website.
Examines public security signals and, for verified targets, protected modules such as deeper authorized checks.
audit_security
Reviews crawlability, metadata, content structure, indexing signals and technical search health.
audit_seo
Checks machine-readable content, answer readiness and signals used by AI discovery systems.
audit_ai_visibility
Inspects analytics, search, tag and platform integration signals exposed by the target.
audit_integrations
Identifies accessibility barriers and returns evidence with practical remediation steps.
audit_accessibility
Reviews delivery, rendering and resource signals that affect speed and resilience.
audit_performance
Runs the available categories as one coordinated assessment for a verified target.
audit_full
02 / Access
Compatible clients discover the authorization service, open a browser consent flow and exchange an authorization code using PKCE S256. Access tokens are scoped to the remote audit service.
The client reads protected-resource and authorization metadata from Sitelemetry.
The user signs in on Sitelemetry and reviews the requested audit access.
The client exchanges its short-lived code with its PKCE verifier.
Authorized tool calls return structured, non-mutating audit results.
03 / Safeguards
Public signals can be inspected for publicly reachable websites. Protected security work and Full Audit require target verification connected to the user's workspace.
These checks use information already exposed to ordinary internet clients.
Deeper security modules and Full Audit run only when the target is covered by workspace verification.
No hosted tool writes to, deletes from or reconfigures the audited target.
Private, loopback and unsafe destinations are blocked from the remote service.
Monthly request limits protect service stability. When a limit is reached, the tool returns a neutral notice and performs no further target request.
Tool inputs are limited to the requested target and audit settings; results contain only audit evidence needed by the client.