Search & analytics data as infrastructure — MCP server for Google Search Console, Bing Webmaster Tools, Google Adsense and GA4, designed for AI agents and automation.
# Add to your Claude Code skills
git clone https://github.com/saurabhsharma2u/search-console-mcpGuides for using ai agents skills like search-console-mcp.
Last scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@protobufjs/utf8: protobufjs has overlong UTF-8 decoding",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@tootallnate/once: @tootallnate/once vulnerable to Incorrect Control Flow Scoping",
"severity": "low"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "express-rate-limit: express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "protobufjs: Arbitrary code execution in protobufjs",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "qs: qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "rollup: Rollup 4 has Arbitrary File Write via Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tar: tar has Hardlink Path Traversal via Drive-Relative Linkpath",
"severity": "high"
},
{
"type": "npm-audit",
"message": "undici: Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "yaml: yaml is vulnerable to Stack Overflow via deeply nested YAML collections",
"severity": "medium"
}
],
"status": "FAILED",
"scannedAt": "2026-05-30T16:10:57.769Z",
"npmAuditRan": true,
"pipAuditRan": true
}search-console-mcp is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by saurabhsharma2u. Search & analytics data as infrastructure — MCP server for Google Search Console, Bing Webmaster Tools, Google Adsense and GA4, designed for AI agents and automation. It has 279 GitHub stars.
search-console-mcp failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/saurabhsharma2u/search-console-mcp" and add it to your Claude Code skills directory (see the Installation section above).
search-console-mcp is primarily written in TypeScript. It is open-source under saurabhsharma2u on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh search-console-mcp against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Google Search Console + Bing Webmaster Tools + GA4 + AdSense — in one context window.
Stop exporting CSVs. Start asking your AI agent questions about your site's traffic, rankings, and revenue.
📚 Docs · Quick Start · Tools · Backward Compatibility · Security
genai_query_insights): Surfaces likely generative-AI / AI-Mode / conversational "fanout" queries across Google and Bing. This is custom heuristic logic — no official API is provided by Google or Bing for GenAI citation data, so it flags prompt verbs, follow-ups, acknowledgements, and conversational phrasing on the regular query data both engines already return. See docs →analytics_query fix: rowLimit is now honored instead of being silently ignored (previously always returned up to 1000 rows); limit remains as a backward-compatible alias.setup --engine=adsense. Enabling AdSense requires you to approve a separate adsense.readonly OAuth scope; your existing GSC, Bing, and GA4 configuration remains unchanged until you opt in.adsense_report upgrades: Custom startDate/endDate now override preset dateRanges, plus a new orderBy parameter (-ESTIMATED_EARNINGS) for sorted revenue reports.setup --engine=adsense. Enabling AdSense requires you to approve a separate adsense.readonly OAuth scope; your existing GSC, Bing, and GA4 configuration remains unchanged until you opt in.adsense_report upgrades: Custom startDate/endDate now override preset dateRanges, plus a new orderBy parameter (-ESTIMATED_EARNINGS) for sorted revenue reports..mcpb): Drag and drop bundle installation for Claude Desktop.engine: "all"): Multi-engine queries fetch Google, Bing, and GA4 concurrently with 50%+ lower latency.Site data lives in four different silos. Answering one question — "did my ad revenue drop because of a traffic dip or a lower RPM?" — usually means logging into four dashboards, exporting four CSVs, and doing VLOOKUPs by hand.
Search Console MCP puts GSC, Bing, GA4, and AdSense behind one set of tools your AI agent can call directly, and does the analysis (cannibalization, anomaly detection, revenue attribution) before the data ever reaches your context window.
| Before | After | |
|---|---|---|
| Data | 4 dashboards, manual exports | 1 unified context |
| Analysis | Manual VLOOKUPs & pivot tables | Deterministic SEO + revenue math, server-side |
| Accounts | Constant re-login | 20+ accounts, auto-resolved per site |
| Insight | Raw rows, agent guesses | Curated signals (opportunity scores, anomalies) |
npx search-console-mcp setup
This opens your browser, authorizes your Google account, and stores your credentials securely (see Security). Then add it to your MCP client config (Claude Desktop, Cursor, Antigravity, etc.):
{
"mcpServers": {
"search-console": {
"command": "npx",
"args": ["search-console-mcp"]
}
}
}
Restart your client — and try one of the prompts below.
Paste these straight into your agent:
"My traffic dropped this week vs. last. Find exactly when it started and which pages are responsible."
"Find keywords for example.com ranking positions 8–15 with 1,000+ impressions — my best quick wins."
"Check for keyword cannibalization — are two of my pages competing for the same query?"
"Run
seo_auditon my top pages: which have high search visibility but poor CTR?"
site_health_check), segmented by Brand vs Non-Brand."pagespeed_analyze — any correlation with declining rankings?"compare_engines) — where is Bing winning?"indexing_submit with method: "index_now"."| Platform | Method | Setup |
|---|---|---|
| Google Search Console | OAuth (recommended) | npx search-console-mcp setup |
| Google Search Console | Service Account | Set GOOGLE_APPLICATION_CREDENTIALS — details |
| Bing Webmaster Tools | API Key | export BING_API_KEY="..." — get a key |
| Google Analytics 4 | Service Account | npx search-console-mcp setup --engine=ga4 |
| Google AdSense | OAuth (read-only) | npx search-console-mcp setup --engine=adsense — headless servers |
Manage everything from the CLI:
npx search-console-mcp accounts list
npx search-console-mcp accounts add-site --account=you@company.com --site=example.com
npx search-console-mcp accounts remove --account=you@company.com
When your agent queries a site, the server auto-resolves which account owns it — no manual switching. Multi-account docs →
AdSense cannot use service accounts, and config files are machine-encrypted — so authorize once on any machine with a browser and transfer the grant:
# 1. On your laptop (after setup --engine=adsense):
npx search-console-mcp adsense-export
# 2. On the server (prints a ready-to-run command on step 1):
npx search-console-mcp adsense-import --token='...' --publisher-id='accounts/pub-...'
The token is stored encrypted on the server and auto-refreshes — no browser needed again. Setup over SSH also works directly: when no browser is detected, setup prints the authorization URL plus ssh -L 3000:localhost:3000 port-forward instructions instead of failing.
Search Console MCP also exposes registered MCP tools as direct CLI commands. Use the run subcommand to list tools, inspect tool-specific arguments, and print results as JSON, CSV, or an ASCII table:
# List registered tools
npx search-console-mcp run --help
# Show options for one tool
npx search-console-mcp run analytics_query --help
# Run an SEO audit with JSON output
npx search-console-mcp run seo_audit --siteUrl=https://example.com --type=quick_wins
# Print array results as CSV or a table
npx search-console-mcp run analytics_query --siteUrl=https://example.com --startDate=2026-06-01 --endDate=2026-06-30 --dimensions=date,query --format=csv
npx search-console-mcp run sites_list --engine=all --format=table