Skip to content

mcp: add async "audits" tools module (start_audit + get_audit) - #111

Merged
ralyodio merged 1 commit into
masterfrom
mcp/audits-tools
Jul 17, 2026
Merged

ralyodio merged 1 commit into
masterfrom
mcp/audits-tools

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

What

Third MCP capability — AEO audits. Audits are asynchronous (the worker runs each engine and fills in the score later), so this is a start + poll pair, mirroring the in-app runAudit flow.

Tool What it does
start_audit Validate URL → charge credits → insert queued audit rows (shared scan_run_id) → notify the worker /enqueue. Returns the run id. Engines default to rule+dns (free); AI engines (claude/openai/gemini/perplexity/…) cost credits. { url, engines? }
get_audit Per-engine status + scores for a run, with public report links when complete. { run_id }

So an agent can: start_audit({ url }) → get a run id → get_audit({ run_id }) until the scores land.

Safety / scoping

  • Owner-scoped throughout (service-role client, explicit owner_id).
  • Credit-safe default: with no engines, it runs the free rule+dns engines — no surprise credit burn. AI engines are opt-in.
  • Reuses the app's guards: isAllowedTargetUrl, checkPerTargetLimit (refunds credits if the per-target cooldown blocks it), consumeCredit/refundCredit. triggered_by='manual' (the only allowed non-scheduled value).

Changes

  • lib/mcp/audits.ts — registerAuditTools(server)
  • app/api/mcp/route.ts — register alongside promote + stats
  • docs/mcp.md + API-tokens UI — tool list
  • tests/contract/mcp-audits.test.ts — both tools register + discoverable over the real SDK

Verified

Built in an isolated worktree off master (clear of the concurrent @profullstack/stack refactor). tsc clean, next build compiles /api/mcp, all 3 MCP contract tests pass (promote + stats + audits). Same instance, no migration, no new deps.

🤖 Generated with Claude Code

Third MCP capability — AEO audits. Audits run asynchronously (the worker runs
each engine and fills in the score later), so this is a start + poll pair,
mirroring the in-app runAudit flow:

- start_audit({ url, engines? }) — validate URL, charge credits (engines default
  to the free rule+dns; AI engines cost credits), insert queued audit rows with
  a shared scan_run_id, notify the worker /enqueue. Returns the run id.
- get_audit({ run_id }) — per-engine status + scores (+ public report links when
  complete) for that run.

Owner-scoped throughout (service-role client). Registered alongside promote +
stats in app/api/mcp/route.ts. Docs + API-tokens UI updated. Contract test
asserts both tools register + are discoverable over the real SDK.

Built in an isolated worktree off master to stay clear of the concurrent
@profullstack/stack refactor. tsc + next build clean; 3 MCP contract tests pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 97366ae into master Jul 17, 2026
8 checks passed
@ralyodio
ralyodio deleted the mcp/audits-tools branch July 17, 2026 14:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant