# com.serpzilla/mcp

Enables AI assistants to natively interact with the Serpzilla link-building marketplace.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** com.serpzilla
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.serpzilla.com/mcp
- **Source:** https://mcp.serpzilla.com/mcp
- **Endpoint health:** reachable (last checked 2026-10-02T08:27:17.931Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 15 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-20T16:29:51.208Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `get_user_info` tool: Links to undeclared domain: passport.serpzilla.com

## Tools

28 declared. Observed from a live `tools/list` probe.
- `list_projects` — Get list of existing Serpzilla projects with optional pagination, sorting, and filtering. All parameters are optional; calling without arguments returns the fir
- `create_project` — Create a new Serpzilla project for domain promotion.
- `add_article` — Create a new Serpzilla Guest Post article (Advertiser's Article) for a project. Returns articleId and urlId needed for purchase.
- `add_texts` — Add promoted URLs with anchor texts to a Serpzilla project. Each URL can have multiple anchor texts. Use #a#...#/a# markup within each text to specify the link 
- `get_project_content_list` — Get a list of content (articles and texts) in a Serpzilla project with filtering, sorting, and pagination. Supports status, type, URL IDs, and search by substri
- `set_limits` — Set usage limits for Serpzilla content (anchors/texts). Targets either specific content IDs or all content of a URL. Limit 0 means no restrictions.
- `update_url` — Update a Serpzilla promoted URL: URL, title and link decoration (hiding links from search engines). The url field is required; pass the current URL unchanged if
- `search_sites` — Search Serpzilla donor sites by given filters.
- `search_rent_sites` — Search Serpzilla donor sites for rental (monthly-billed) links by URL ID and filters. The search runs asynchronously: this tool polls internally until results a
- `search_context_sites` — Search Serpzilla donor sites for contextual (Niche Edit) links by URL ID and filters. The search runs asynchronously: this tool polls internally until results a
- `get_site_info` — Get detailed information about a Serpzilla donor site (site card), including metrics, price, status, languages, statistics, etc.
- `favorites_add_list` — Create a new Serpzilla favorites list (a named group of donor domains). Returns the created list ID.
- `favorites_get_lists` — Get all Serpzilla favorites lists with domain counts.
- `favorites_rename_list` — Rename a Serpzilla favorites list.
- `favorites_delete_list` — Delete a Serpzilla favorites list. With is_delete_sites=false (default) the domains are moved to the general favorites list; with true they are deleted along wi
- `favorites_get_domains` — Get domains from a Serpzilla favorites list (grouped into sections), with pagination and optional filters (sort order, domain zones, availability to buy).
- `favorites_add_domains` — Add domains to Serpzilla favorites lists. Domains can be identified by domain IDs, site IDs (from search results), or domain names. At least one identifier kind
- `favorites_delete_domains` — Remove domains from Serpzilla favorites lists. If list_ids is omitted, the domains are removed from ALL favorites lists.
- `favorites_move_domains` — Move domains from one Serpzilla favorites list to another.
- `blacklist_get` — Get domains from the Serpzilla Blacklist, grouped into sections. Returns the global Blacklist by default, or a project's own Blacklist when project_id is given.
- `blacklist_add_domains` — Add domains to the Serpzilla Blacklist by domain IDs and/or domain names. Optionally scope the addition to project blacklists via project_ids. Returns a per-dom
- `blacklist_delete_domains` — Remove domains from the Serpzilla Blacklist. Domains are identified by domain IDs only (from blacklist_get sections[].domainsList[].domainId). Optionally limit 
- `purchase_placement` — Purchase a placement on a selected Serpzilla donor site.
- `purchase_rent_placement` — Purchase rental (monthly-billed) link placements on selected Serpzilla donor pages. The search_id, force_seo_wait, mos_sites, and pages_extra values must come f
- `purchase_context_placement` — Purchase contextual (Niche Edit) link placements on selected Serpzilla donor pages. The search_id, force_seo_wait, mos_sites, and pages_extra values must come f
- `get_project_placements` — Get a list of all placements in a Serpzilla project.
- `perform_placement_action` — Perform an action on one or more Serpzilla placements (e.g., approve, cancel). Allowed actions: force_billing_seo, approve_seo, approve_content_seo, approve_fro
- `get_user_info` — Get current Serpzilla user information including account balance (balance field). To top up your balance, visit https://passport.serpzilla.com/deposit/

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.serpzilla.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on someone else's infrastructure.
- Floor 36, ceiling 60 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.serpzilla%2Fmcp
- Install plan: https://forgeregistry.com/api/v1/packages/com.serpzilla%2Fmcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.serpzilla%2Fmcp
- HTML page: https://forgeregistry.com/registry/com.serpzilla%2Fmcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
