Back to Browse

Tengence Geo Agent MCP Server

Developer ToolsModerate5.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

GEO/SEO content engine: planning, writing, gate checks, WordPress publishing, GEO monitoring.

About

GEO/SEO content engine: planning, writing, gate checks, WordPress publishing, GEO monitoring.

Security Report

5.8
Moderate5.8Moderate Risk

The Tengence GEO MCP server is a comprehensive content management system with generally sound architecture and reasonable authentication. However, several medium-severity concerns exist: (1) the MCP HTTP transport relies solely on a Bearer token without rate limiting or additional safeguards; (2) shell command execution via spawnSync in the registry uses user-controlled arguments that could be vulnerable to injection despite some safety measures; (3) sensitive database operations and WordPress API calls are delegated to child processes with minimal validation; (4) file I/O operations accept user-provided paths that could be traversal vectors; (5) the codebase relies on environment variables for multi-tenant isolation without explicit verification mechanisms. These issues prevent a higher score despite the server's legitimate purpose and generally clean code structure. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

4 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

database

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

SITES_ROOTRequired
DEEPSEEK_API_KEYRequired

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "com-tengence-geo-agent": {
      "env": {
        "SITES_ROOT": "your-sites-root-here",
        "DEEPSEEK_API_KEY": "your-deepseek-api-key-here"
      },
      "args": [
        "-y",
        "tengence-geo-agent"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Tengence GEO Agent

GEO/SEO content production & publishing engine — full-pipeline automation from content planning → writing & ingest → gate checks → WordPress publishing → search submission → GEO monitoring. Three usage modes: CLI / MCP (AI clients) / built-in agent runtime loop. Default storage is a single-file multi-tenant SQLite (auto-initialized) with optional MySQL; designed for open source and multi-site use.

  AI clients (any MCP-capable harness)
        │  MCP (stdio or Streamable HTTP + Bearer)
        ▼
  @tengence/geo-mcp     29 tools (workspace/site/article/check/publish/plan/image/monitor/db/search/diagnose/util/standards)
        ▼
  @tengence/geo-cli     21 tengence-geo-* commands
        ▼
  @tengence/geo-sdk     15-domain capability layer (site/db/wp/content/images/search/…)
        ▼
  SQLite (auto-init)  or  MySQL (tengence_geo_*, isolated from prod tengence_omni_*)

Packages (monorepo)

PackageFormDescription
@tengence/geo-sdkLibrary15-domain capability layer, lazy-loaded, single require entry
@tengence/geo-cliCLI21 bins (ingest / gate / publish / images / submission / monitor / plan)
@tengence/geo-mcpMCP Server29 tools, stdio + HTTP dual transport, Bearer auth
@tengence/geo-agentAgent launcherRuns once DEEPSEEK_API_KEY is set (HARNESS=dsh|opencode|pi)

Quick start

npm install
cp -R examples/site-template ~/tengence/sites/my-site
cd ~/tengence/sites/my-site && cp .env.example .env   # fill in WP credentials / tokens

# Full CLI pipeline
export SITES_ROOT=~/tengence/sites
tengence-geo-article-ingest hello-geo ./hello-geo.md --site my-site --research ./hello-geo.research.md
tengence-geo-check-article hello-geo --site my-site

# MCP (any MCP-capable client; see docs/mcp-platforms.md)
node packages/geo-mcp/bin/geo-mcp.js                          # stdio
GEO_MCP_TOKEN=sk-xxx node packages/geo-mcp/bin/geo-mcp-http.js  # HTTP

# Agent (runs once the API key is set)
export DEEPSEEK_API_KEY=sk-xxx
npx -y @tengence/geo-agent

Full onboarding: docs/getting-started.md.

Documentation

Development & verification

npm run build          # workspace consistency check
npm test               # 138 tests (all green on SQLite)
npm run geo:sdk-smoke  # SDK smoke test

Security boundaries

  • Secrets live only in SITES_ROOT/<site>/.env (gitignored); the repo ships only the .env.example template.
  • The production MySQL (tengence_omni_*) is never written by this repo; the new repo uniformly uses tengence_geo_*.
  • The MCP HTTP transport requires GEO_MCP_TOKEN (Bearer).

License

MIT

Reviews

No reviews yet

Be the first to review this server!