Skip to content

mcp: add read-only "stats" tools module - #110

Merged
ralyodio merged 1 commit into
masterfrom
mcp/stats-tools
Jul 17, 2026
Merged

ralyodio merged 1 commit into
masterfrom
mcp/stats-tools

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

What

A second capability module for the MCP server — read-only stats, no side effects. An agent can now ask "what sites do I have / how did my last audits score / what am I earning / did my promo posts land."

Tool What it does
list_projects The caller's sites/projects (name, url, id).
recent_audits Recent AEO audits + scores/status. { url?, limit? }
ad_earnings Earned (publisher) / spent (advertiser) / net.
promote_status Recent Promote posts + posted/queued/failed. { limit? }

Scoping (important)

The MCP route uses the service-role client (no RLS), so every query here filters explicitly by owner_id/user_id (projects.owner_id, audits.owner_id, ad_ledger.owner_id, ad_campaigns.owner_id, promo_list.user_id). No cross-user leakage.

Changes

  • lib/mcp/stats.ts — registerStatsTools(server)
  • app/api/mcp/route.ts — register alongside promote (2 lines)
  • docs/mcp.md + API-tokens UI — tool list updated
  • tests/contract/mcp-stats.test.ts — 4 tools register + discoverable over the real SDK

Verified

Both MCP contract tests pass (promote + stats) against the real SDK in-memory transport. Same instance, no migration, no new deps.

🤖 Generated with Claude Code

A second capability module for the MCP server — read-only, no side effects, all
explicitly scoped to the authenticated user (the route uses the service-role
client, so each query filters by owner_id/user_id itself):

- list_projects   — the caller's sites/projects
- recent_audits   — recent AEO audits + scores (optional url filter)
- ad_earnings     — earned (publisher) / spent (advertiser) / net
- promote_status  — recent Promote posts + posted/queued/failed status

Registered alongside promote in app/api/mcp/route.ts. Docs + the API-tokens UI
tool list updated. Contract test asserts the 4 tools register + are discoverable
over the real SDK (in-memory transport).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 24a0282 into master Jul 17, 2026
8 checks passed
@ralyodio
ralyodio deleted the mcp/stats-tools branch July 17, 2026 13:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant