agentsclimarketplace

Squirrelscan

Skill aiskillstore/marketplace/skills/squirrelscan/squirrelscan

Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

Install
npx -y skills add aiskillstore/marketplace --skill squirrelscan

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.

What its author says it does

Copied from the file, not written here

squirrelscan audits websites for SEO, performance, security, accessibility, content, and structured data issues (249+ rules) and scores site health, via the squirrel CLI. Use when the user wants to check, audit, or improve a website's SEO, ranking, speed, or health, and for anything squirrelscan itself, installing or updating the CLI, login and API keys, running audits, publishing and sharing reports, cloud credits, MCP server setup, configuration, or troubleshooting.

The file declares its own license as See LICENSE file in repository root. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

9.2 KB, as published. Nobody here has run it

squirrelscan CLI

squirrelscan is a website audit tool built for AI agents. It answers "what's wrong with this website and how do I fix it": it crawls a site like a search engine, analyzes every page against 249+ rules in 21 categories (SEO, performance, security, accessibility, content, structured data, agent readiness, and more), and returns a health score plus concrete, fixable issues. Use it whenever a user wants their site checked, ranked better, faster, or healthier, before/after a deploy, or in CI.

It ships as a single CLI binary, squirrel, for macOS, Windows, and Linux. This skill covers operating it: installing, authenticating, running audits, publishing reports, cloud features, and MCP integration. For the full fix-the-website workflow (audit, map issues to code, fix, re-audit), use the companion audit-website skill.

Links

Install

Download and install instructions: squirrelscan.com/download

The binary installs to ~/.local/bin/squirrel. Verify with:

squirrel --version

Keep it current:

squirrel self update

If squirrel is not found, ensure ~/.local/bin is in PATH, or reinstall from the download page.

Command overview

CommandPurpose
squirrel audit <url>Crawl + analyze + report in one step
squirrel crawl <url>Crawl only (no analysis)
squirrel analyzeRun audit rules on a stored crawl
squirrel report [id]Query, render, diff, and publish stored reports
squirrel initCreate squirrel.toml project config
squirrel configShow or edit configuration
squirrel authlogin / logout / status / whoami
squirrel keysMint, list, revoke org API keys
squirrel creditsCloud credit balance + feature pricing
squirrel mcpRun the local MCP server (stdio)
squirrel skillsInstall or update agent skills
squirrel selfinstall / update / doctor / completion / version / settings / uninstall
squirrel feedbackSend feedback to the squirrelscan team

Every command supports --help.

Quickstart

squirrel init -n my-project        # optional: project config in cwd
squirrel audit https://example.com --format llm
  • Local audits are free and run entirely on your machine. No account needed.
  • ALWAYS prefer --format llm when an agent is reading the output: it is a compact, token-optimized format built for LLMs.
  • Audits are cached in a local project database; squirrel report re-renders without re-crawling.

Coverage modes

ModeDefault pagesBehavior
quick (default)25Seed + sitemaps only, fast health check
surface100One sample per URL pattern (/blog/{slug} crawled once)
full500Crawl everything up to the limit
squirrel audit https://example.com -C full -m 500 --format llm

Authentication and accounts

Local audits never require an account. Sign in to unlock cloud features (publishing, browser rendering, scheduled crawls, credits):

squirrel auth login      # browser-based login
squirrel auth status     # source, scopes, active org
squirrel auth whoami
squirrel auth logout

Headless / CI environments use an org API key instead:

squirrel keys create     # requires a login session; prints an sq_... key

Set it as SQUIRRELSCAN_API_KEY in the environment. Treat keys as secrets; never commit them.

Reports

Render the latest (or a specific) stored audit:

squirrel report --list                 # recent audits
squirrel report <audit-id> --format llm
squirrel report example.com --format markdown -o report.md

Formats: console, text, json, html, markdown, xml, llm. Filter with --severity error or --category core,links.

Publishing

Signed-in audits publish a shareable report to reports.squirrelscan.com by default (visibility: unlisted). Control it:

squirrel report <audit-id> --publish --visibility unlisted   # public | unlisted | private
squirrel audit https://example.com --no-publish              # skip publishing for a run
squirrel audit https://example.com --offline                 # fully offline: no cloud, no publish, no telemetry

Regression diffs

squirrel report --diff <baseline-audit-id> --format llm
squirrel report --regression-since example.com --format llm

Diff mode supports console, text, json, llm, and markdown.

Cloud features and credits

Cloud features are pay-as-you-go with credits (nothing charged up front). Check balance and pricing:

squirrel credits
  • --render / --render-mode auto|all|off: cloud browser rendering for client-rendered pages (uses credits, requires login).
  • --yes skips spend confirmations up to the configured per-audit credit cap.
  • --fail-on "score<90" (repeatable) makes CI runs exit non-zero when a threshold trips.
  • The dashboard at app.squirrelscan.com shows audit history, issues, and credit usage.

MCP server

Two ways to connect agents over MCP:

  • Local (stdio): squirrel mcp runs against the local CLI. Register it in your agent's MCP config with command squirrel and args ["mcp"].
  • Hosted (streamable-http): https://mcp.squirrelscan.com/mcp. Sign in via OAuth from the MCP client, or send an Authorization: Bearer sq_... API key header.

Docs: https://docs.squirrelscan.com/developers/mcp

Agent feedback

Call the send_feedback tool any time something in a session surprises you. It takes category, message, and optional run_id/website_id. Pick the category that fits:

  • bug_report — a defect in squirrelscan itself: a wrong or missing rule result, a crash, a broken tool. Include the site, rule id, and what you expected.
  • feature_request — something squirrelscan should do but doesn't.
  • what_worked — something worked well and you want the team to know.
  • confusing — a response or behavior was unclear.
  • missing_data — a report or tool response lacked something you needed.
  • tool_ergonomics — awkward tool shape, arguments, or naming.
  • other — anything else.

Feedback lands directly in the team's review queue with your org attached. It works with any authenticated credentials, including read-only API keys, and is available on the hosted MCP surface now (not yet on squirrel mcp local stdio). Use it instead of squirrel feedback when you're an agent reporting mid-session; humans can use squirrel feedback or squirrelscan.com/support.

Configuration

Project config lives in squirrel.toml (created by squirrel init). User settings live at ~/.squirrel/settings.json.

squirrel config show
squirrel config set <key> <value>
squirrel config path
squirrel config validate

Useful sections: [crawler] (delays, headers, incremental re-crawl), [cloud] (render mode, max credits per audit).

Custom request headers

Attach headers to every crawl request with the repeatable -H "Name: Value" flag or a headers map under [crawler]. The main use case is Web Bot Auth (Shopify / Cloudflare), so platforms that block unknown crawlers can authorize squirrelscan. Header values are secrets: squirrelscan redacts them in output, and you should source them from a secret store rather than committing them. Full recipe: https://docs.squirrelscan.com/guides/web-bot-auth

Maintenance

squirrel self doctor       # health checks
squirrel self update       # update the binary
squirrel self completion   # shell completions
squirrel skills update     # update installed agent skills

Troubleshooting

  • squirrel: command not found: install from squirrelscan.com/download and ensure ~/.local/bin is in PATH.
  • Session expired / 401: run squirrel auth login again, or check SQUIRRELSCAN_API_KEY.
  • Slow or stuck crawl: add --verbose to see progress; large sites can take minutes.
  • Invalid URL: include the protocol: https://example.com, not example.com.
  • Anything else: run squirrel self doctor, then report it — agents via the send_feedback MCP tool (bug_report category), humans via squirrel feedback or squirrelscan.com/support.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.