# com.epovest/ai-visibility

With Epovest, businesses make AIs recommend them.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** com.epovest
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.epovest.com/mcp
- **Source:** https://epovest.com
- **Endpoint health:** reachable (last checked 2026-09-17T05:26:00.706Z, 4 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-17T05:26:00.706Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `create_project` tool: Links to undeclared domain: example.com
- injection-shaped content (note) in the `update_project_canon` tool: Links to undeclared domain: example.com

## Tools

67 declared. Observed from a live `tools/list` probe.
- `list_trackers` — List the trackers of the account, current versions: configuration, status, keywords, analysts, project and the recalculated cost per survey. Start here to find 
- `create_tracker` — Create a tracker in draft. It measures nothing yet: call start_tracker to launch it against the prepaid credit balance. Validation rules and messages are the sa
- `update_tracker` — Update the configuration of a tracker: only the fields you send change. Keywords, analysts and the title apply in place. Changing the prompts, engines, frequenc
- `start_tracker` — Start or restart the measurement of a tracker against the prepaid credit balance. The first survey runs there and then, whatever the frequency, unless the track
- `survey_now` — Run one survey of a measuring tracker right now, on top of its schedule. Its settings stay as they are: same anchor, same frequency, and the next scheduled surv
- `pause_tracker` — Pause the measurement of an active tracker. The score series is kept; start_tracker resumes it.
- `archive_tracker` — File a finished tracker away: a campaign that ended, a brand that was sold, a trial that is over. It moves to the end of list_trackers with archived true, stops
- `list_projects` — The projects of the account: the folders trackers are filed under (one project per tracker at most; pure organization, no effect on measurement or billing). Eac
- `create_project` — Create a project to file trackers under: one project per BRAND, never per language. It can carry the brand canon: the reference wording every publication reuses
- `rename_project` — Correct the name of a project: the folder keeps its id, its canon, its trackers, its surfaces and its logbook, and the name shown is the only thing that changes
- `get_canon` — The brand canon of a project and every revision it went through. canon is the CURRENT wording, under the same keys update_project_canon writes (one_liner, short
- `update_project_canon` — Revise the brand canon of a project. Field by field: a provided field replaces the current wording (an empty string clears it), an omitted field is kept as is. 
- `get_link_targets` — The addresses of the brand that a watched page can link to. Two lists come back. derived: what is already covered without anyone typing it, each row with its so
- `set_link_targets` — Set the addresses of the brand that are neither its canonical website nor a page of the surface registry: a satellite domain the customer does not want to keep 
- `archive_project` — File a project away once the folder has served its purpose: a client that left, a brand that was sold. It moves to the end of list_projects with archived true, 
- `list_surfaces` — The surface registry of a project: the pages about the brand where the customer has the FINAL SAY (website, GitHub, LinkedIn, X, YouTube, Wikidata, directories,
- `create_surface` — Register a surface of a project: one page about the brand where the customer has the final say (their site, their profiles, their listings, wherever they can ch
- `update_surface` — Update the registry sheet of a surface: only the fields you send change (a sent languages list replaces the previous one; an empty label or notes clears it). No
- `tick_surface_checklist` — Record what a surface actually carries, cell by cell, as many moves as you want in one call. The items are listed by list_surfaces as checklist.items: the templ
- `add_surface_check` — Add a check of your own to the checklist of one surface: a requirement the person holds on THAT page, in their words. It becomes REQUIRED for the page to count 
- `update_surface_check` — Correct a check of your own on a surface: its label, and whether it restates the canon. Only what you send changes. The key never moves, being the coordinate of
- `delete_surface_check` — Take a check of your own out of the checklist of a surface: it leaves the list, stops holding the page short of aligned and stops accepting ticks. Use it when t
- `restore_surface_check` — Bring a check of your own back to the checklist of a surface, with the cells it had: it becomes work again, so the page needs it verified to count as aligned. T
- `delete_surface` — Take a surface out of the registry: the page stops being followed, and the registry stops asking to bring it in phase with the canon. Use it for a page that is 
- `restore_surface` — Bring a surface back to the registry, with its sheet and its alignment journal as they were. Call list_surfaces with deleted set to "only" to find the surfaces 
- `convert_surface_to_corroboration` — Move the page to the corroboration registry: someone else has the final say on it (the customer lost, or never had, the hand on the content). Nothing is retyped
- `list_corroborations` — The corroborations recorded for a project: the pages about the brand where someone else has the FINAL SAY, each with its exact address, the source it sits on (d
- `create_corroboration` — Record a page about the brand where someone else has the final say. URL-FIRST: the exact address of the page is the only thing needed, the source on the map and
- `update_corroboration` — Update the sheet of a corroboration: only the fields you send change (an empty label goes back to the derived one, an empty notes or published_on clears it). Co
- `archive_corroboration` — Record that the page is no longer there (article unpublished, link dead), or put it back live with archived false. Nothing is deleted: the line stays, and so do
- `verify_corroboration` — Read the page again and report what it says today. One pass returns two findings, dated, and included at no cost. On the MENTION: the passage around the brand i
- `convert_corroboration_to_surface` — Move the page to the surface registry: the customer has, or takes, the final say on it (their own profile or listing recorded on the wrong side, or a source tha
- `list_corroboration_candidates` — The MENTIONS a search engine has shown the brand in, found in the text the engine itself returned next to each address. The list is recomputed on every read fro
- `dismiss_corroboration_candidate` — Refuse a suggested page: it is never proposed again for this project. Use it when the excerpt matched something else than the brand, or when the page is not wor
- `get_logbook` — The logbook of a project, newest first: every dated move, composed from two sources. source=tool events are derived from the suite itself (canon moved to a vers
- `create_logbook_entry` — Record an action in the logbook of a project: what was done, and WHEN it was done. occurred_at is the date of the ACTION itself, not of the recording: recording
- `update_logbook_entry` — Edit a manual logbook entry: only the fields you send change (empty notes clear them). It is the customer's own logbook: a typo or a wrong date is simply correc
- `delete_logbook_entry` — Take a manual logbook entry out of the logbook, and the annotation it placed on the curves with it. Only do it when the user asked for it: it is their logbook. 
- `restore_logbook_entry` — Bring an entry back to the logbook, with the annotation it placed on the curves. Call get_logbook with deleted set to "only" to find the entries to bring back. 
- `list_quests` — What there is to do for the GEO work, and where to resume it. Lists the quests of the account: moves the customer (or you, on their behalf) decided and recorded
- …and 27 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"ai-visibility\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.epovest.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive blast radius — deletes data; runs on someone else's infrastructure.
- Floor 35, ceiling 59 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.epovest%2Fai-visibility
- Install plan: https://forgeregistry.com/api/v1/packages/com.epovest%2Fai-visibility/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.epovest%2Fai-visibility
- HTML page: https://forgeregistry.com/registry/com.epovest%2Fai-visibility
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
