mcp server
SiteGuardian
EU-hosted website monitoring + 17-framework compliance MCP. One anonymous tool, four authenticated.
Description as published by the maintainer. Source
- version 1.0.0
- slowing
- security
slowing — Most recent push to the repository was 2026-04-25. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
5 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
get_domain_status(domain)- Returns the current security grade (A–F), last-scan timestamp, and list of active issues for a domain that is ALREADY under SiteGuardian monitoring by the authenticated account. Each issue carries a stable id, a severity, a short title, and an impact description. The response also includes a relative dashboard URL. Use this when the user asks about the current state of a specific monitored domain, wants to confirm a recent change landed, or needs issue ids to call get_fix_recommendations with a specific issue_id. Do NOT use this for domains not yet under monitoring — it will return a domain_not_monitored error; call scan_domain for one-off checks instead. Compliance framework tags (NIS2 / GDPR / DORA) are NOT included in v1; framework tagging on the monitored-domain path is tracked as a follow-up. Requires a valid API key. Required: domain.
get_drift_events(limit, since, domain)- Returns recent configuration drift events for a domain under monitoring by the authenticated account — TLS changes, DNSSEC state changes, new or removed security headers, shifts in third-party JS hosts, new cookies. Each event carries its observed-at timestamp, a kind (tls/dnssec/cookies/js_hosts/headers), a severity classified centrally (high for tls/dnssec/headers, medium for cookies/js_hosts, otherwise low), a short summary, and a sanitised detail payload. Use this when the user asks 'what changed' on a domain, wants to audit recent posture shifts, or is diagnosing an unexpected issue. Pair it with get_domain_status to see the current state and get_drift_events to see how it got there. Do NOT use this for a domain that is not under monitoring — you'll get a domain_not_monitored error; monitoring has to be active for the drift history to accumulate. Optional since (ISO-8601) and limit (1..100) params narrow the window. Requires a valid API key. Required: domain.
get_fix_recommendations(domain, issue_id)- Returns copy-paste-ready fix recommendations (nginx, Apache, DNS, shell) for the issues found on a domain the caller has already paid for — either an active Monitor/Compliance subscription covering the domain, OR a purchased one-off Report for the domain. Each recommendation carries a stable issue_id, a priority (high/medium/low), a title, prose instructions, one or more config snippets with the target domain already interpolated, a verify command, and a category tag. Use this when the user asks how to fix an issue, wants the exact config to apply, or needs to verify a fix worked. Pass the optional issue_id to scope the response to one specific finding. The response is read-only — this tool NEVER triggers a fresh scan; fixes are computed from the most recent stored scan (including the Report-included re-scan if that was used). Do NOT use this for domains the caller hasn't purchased coverage for — you'll get an upgrade_required error that links to the pricing page. Do NOT use this to run or trigger a scan; call scan_domain for anonymous checks. Requires a valid API key. Required: domain.
list_monitored_domains- Returns the full list of domains under continuous SiteGuardian monitoring for the authenticated account. Each entry includes the domain, current security grade (A–F), timestamp of the last completed scan, and a relative dashboard URL. Use this when the user asks what they are monitoring, wants an inventory summary, or needs to look up a specific domain's exact spelling before calling get_domain_status / get_drift_events / get_fix_recommendations. The list is scoped entirely by the API key — there is no filter parameter to widen or narrow the result. Do NOT use this to enumerate domains the user does not own or monitor — it only returns their own inventory. Do NOT call it to trigger a scan (it does not); use scan_domain for one-off checks. Requires a valid API key.
scan_domain(domain)- Runs a free one-off security scan of the given domain and returns its grade (A–F), scan timestamp, and up to three top-priority issues with a permalink to the full report on siteguardian.io. Use this when the user asks for a quick security check of a domain that is NOT yet under SiteGuardian monitoring, or when they want a fresh assessment before subscribing. Results are cached for two hours, so repeated calls about the same domain return the same snapshot and mark it with cached=True. Do NOT use this for domains already under monitoring by the user — call get_domain_status instead for the account-scoped view with framework tags. Do NOT use this to batch-scan many domains as a competitive-intelligence tool; per-source-IP and per-target rate limits bound usage. This tool does not require authentication. Required: domain.
Last successful function declaration observed on . Source: https://mcp.siteguardian.io. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://mcp.siteguardian.io.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| GitHub stars | 0 | Number of GitHub accounts that bookmarked this repository since it was created. It is a bookmark count, not installs, not active users and not quality. | cumulative, all time | GitHub | |
| Last commit | 2026-04-25 | Date of the most recent push to any branch. This is the strongest cheap indicator of whether the project is still maintained. | point in time | GitHub | |
| Open issues | 0 | Open issues plus open pull requests, as GitHub counts them together. A high number can mean an active project or an abandoned one. | as of fetch | GitHub | |
| Latest published version | 1.0.0 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-04-25 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| License | MIT | Licence GitHub detected in the repository. Detection can be wrong; the LICENSE file is authoritative. | as of fetch | GitHub | |
| First listed in the MCP Registry | 2026-04-25 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| repository status | active | The repository exists on GitHub and is not archived. This says nothing about how recently it was worked on. | as of fetch | GitHub | |
| mcp tools declared | 5 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | mcp.siteguardian.io | |
| mcp endpoint status | ok | The server listed 5 functions when asked. | as of probe | mcp.siteguardian.io |
Where to get it
Related, by what their authors tagged them
-
io.github.CSOAI-ORG/dora-nis2-crosswalk-mcp
— last commit 2026-06-26, shares dora, nis2
DORA × NIS2 Crosswalk MCP — map Regulation (EU) 2022/2554 obligations to Directive (EU) 2022/255...
-
io.github.CSOAI-ORG/nis2-compliance-mcp
— last commit 2026-06-26, shares nis2
NIS2 Directive (EU 2022/2555) compliance for AI agents. 10 Article 21 risk-management measures a...
-
io.github.CSOAI-ORG/cobol-bridge-mcp
— last commit 2026-06-26, shares dora
AI-assisted COBOL → modern stack bridge. Parse COBOL programs, map to Python/Java/Go, generate t...
-
io.github.CSOAI-ORG/dora-compliance-mcp
— last commit 2026-06-26, shares dora
DORA (EU Digital Operational Resilience Act) compliance for AI agents. 5-pillar audit, incident ...
-
io.github.feedoracle/feedoracle-macro-mcp
— last commit 2026-03-19, shares dora
Real-time macroeconomic signals for AI agents. 86 FRED series, regime classification, DeFi rates.
-
Email Deliverability Audit API
— last commit 2026-07-19, shares monitoring, security
Audit email domain deliverability: SPF, DKIM, DMARC, MX. Score 0-100. x402.
-
HTTP Headers Analyzer API
— last commit 2026-07-18, shares monitoring, security
HTTP header analysis — security headers, cache, server detection. x402 micropayment.
-
SEO Page Analyzer
— last commit 2026-07-19, shares monitoring, security
SEO audit any URL: meta tags, headings, links, images, Schema.org, score 0-100. x402.
-
Webhook Tester API
— last commit 2026-07-19, shares monitoring, security
Test webhook endpoints — send requests, measure latency, validate responses. x402 micropayment.
-
Tokonomix Council
— last commit 2026-07-30, shares gdpr
Multi-model consensus: 2-6 frontier LLMs answer, an independent judge synthesises one answer.
These share tags the maintainers applied themselves, such as dora, nis2, monitoring, security. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.
This is not a recommendation and not a test result. It is a map of what the authors said their work is about.
How the author describes it
Topics the maintainer set on GitHub: anthropic, claude, compliance, dora, eu-hosted, gdpr, mcp, model-context-protocol, monitoring, nis2, security.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json