# com.varynforge/server

SEO research SaaS exposed as 30+ MCP tools. Forge niche analysis, plans, and writer-ready briefs.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.21.0
- **Author:** com.varynforge
- **License:** Unknown
- **Endpoints:** streamable-http https://app.varynforge.com/api/mcp
- **Source:** https://app.varynforge.com/api/mcp
- **Endpoint health:** reachable (last checked 2026-10-03T00:27:28.238Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 37 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-08-29T16:52:20.824Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (note) in the `get_writer_system_prompt` tool: References the system prompt

## Tools

57 declared. Observed from a live `tools/list` probe.
- `get_instructions` — Get the VarynForge agent guide — workflow paths (free vs paid), token-economy rules, walls and upgrade conversation conventions. Read this at session start.
- `get_changelog` — Get the URL of the VarynForge product changelog — what shipped, newest first, in plain markdown. Fetch it when the operator asks what is new, and in the days af
- `get_writer_system_prompt` — Get the writer system prompt for drafting one content type from its brief. The writer works with your Varyn account context: every channel prompt binds to the b
- `get_account_status` — Get the operator account status — the organization whose plan/credits/limits this payload describes (plans and usage limits are per-organization; see list_organ
- `list_organizations` — List the organizations this account belongs to — id, name, your role (owner | admin | member), is_personal, plan, and member_count — plus pending invitations aw
- `get_onboarding_guide` — Diagnose where the operator is in their VarynForge journey and get a guided setup path. Call when the operator asks to set up VarynForge, get started, or seems 
- `send_feedback` — File a note to the VarynForge team: a bug, a missing capability, a friction point, or an operator idea. Call when you hit something VarynForge cannot do, a conf
- `create_project` — Create a new project — pass either a website URL or a niche description (or both). Returns projectId immediately; niche analysis and asset mapping run async. Po
- `get_project` — Get one project — its canonical name (operator-set, falling back to site brand then niche name), niche profile, target audience, current research status, and po
- `get_project_asset` — Get the asset (website/product) associated with a project — URL, name, description, solution profile.
- `update_niche` — Update a niche profile — name, industry, language, country, target customer, core problem, related terms. Use after the operator refines their market definition
- `list_destinations` — List the project's destinations — where the operator publishes (website, youtube_channel, tiktok, instagram, x, linkedin, local_business). Destination type ids 
- `add_destination` — Add a destination to a project — where the operator publishes. Pass `type` (website | youtube_channel | instagram | tiktok | x | linkedin | local_business) and 
- `list_competitors` — List companies for a project — marked competitors (important / default / ignored) and SERP-discovered companies (unmarked). Sorted important → default → unmarke
- `set_competitor_importance` — Mark a competitor important, default, or ignored. Important applies a 1.25× boost on opportunity scores for clusters where the competitor ranks top-10. Scores a
- `add_competitor_by_domain` — Add a competitor to a project by domain (e.g. example.com). Marks the competitor as important or ignored on creation.
- `update_asset_profile` — Correct the inferred profile of the project asset — description, primary offer, benefits, key differentiators, use cases. Use when get_project_asset shows claim
- `set_posting_cadence` — Set how many articles per week the operator actually publishes (1-14). Sizes the pitch report’s 90-day content sequence; read back via get_project.postsPerWeek.
- `resync_asset_profile` — Re-read the project website and re-infer the asset profile (name, description, primary offer, benefits, differentiators, use cases) from its current content. Us
- `remap_asset` — Re-crawl the project website and refresh its owned pages. Use when get_project_asset shows mappingStatus "error" or owned pages look stale. Rate-limited per sit
- `start_research_run` — Start a research run for a project — discovers keywords, evaluates competitors, and writes opportunity clusters. Consumes one credit. Returns `{ runId }`; poll 
- `list_projects` — List all projects for the authenticated operator — paginated, sortable by createdAt, niche, or industry. `name` is the canonical project name (operator-set, fal
- `get_competitor_detail` — Get a competitor company detail in a project context — domain, name, importance, top pages in the project SERPs, and top keywords they rank for.
- `get_project_overview` — Get the at-a-glance read on a project — niche summary, keyword stats, nextActions (the ranked queue of what to do next in this project — offer its first entry w
- `get_research_status` — Poll the latest research run for a project — runId, status, current pipeline phase, progress percent, elapsed seconds, and structured failure diagnostics when f
- `get_pitch_report_payload` — Assemble the client-ready pitch report payload for a completed research run — niche + solution profile, competitor landscape, ranked opportunity map holding GAP
- `get_starting_point_report` — Get the free starting-point report for a project — a client-facing document assembled from setup-time data: positioning (niche + market profile), the site and i
- `list_opportunities` — List content opportunity clusters sorted by opportunity score. Goal filters: fast_wins, high_intent, authority_building, competitor_gap. coverage filters by sit
- `get_opportunity_detail` — Get a cluster detail — top-20 keywords by score, top-10 ranked pages by position, top-5 competitor podium, linked article suggestions, and rawOpportunityScore (
- `set_opportunity_status` — Dismiss or restore an opportunity cluster. status=dismissed hides it from list_opportunities and the create_content_plan_from_opportunities harvest; status=defa
- `set_excluded_terms` — Set the project-level exclusion terms — products or topics the operator explicitly does NOT sell (e.g. "wedding suite", "free template", "printing"). Keywords m
- `list_keywords` — List keywords tracked for a project — text, difficulty, intent, volume bucket (no_traffic | long_tail | average | high). Paginated; supports sorting and intent 
- `get_keyword_detail` — Get a keyword detail — pages ranking for it with positions and ownership, plus related keywords already tracked in the project.
- `list_pages` — List ranked pages tracked for a project — URL, title, company, query count, ownership. Filter by ownership or company domain.
- `get_page_dossier` — Get a page dossier — URL, title, project rankings, ownership. `headingOutline`, `targetKeywords`, and `contentAnalysis` populate for owned (asset-mapped) pages 
- `list_article_suggestions` — List article suggestions for a project — title, status, priority, cluster, intent, source, publishedAt, scheduledFor, and a per-channel distributions rollup ({ 
- `create_content_plan_from_opportunities` — Create a content plan by harvesting the top-30 opportunity clusters from a completed research run. Auto-creates article suggestions linked to each cluster. Left
- `add_article_suggestion` — Add a bare article suggestion to a content plan (title + optional intent and reasoning). For richer input that produces a brief-ready suggestion, use create_art
- `create_article_suggestion_with_input` — Create a brief-ready article suggestion from the operator's own input. Auto-resolves a default content plan; creates/links search-query rows for the keywords; r
- `update_article_status` — Move an article through the production pipeline. Statuses: planned, generating_brief, brief_ready, drafting, draft_ready, reviewing, ready_to_publish, published
- …and 17 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"server\": {\n      \"type\": \"http\",\n      \"url\": \"https://app.varynforge.com/api/mcp\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on someone else's infrastructure.
- Floor 33, ceiling 57 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.varynforge%2Fserver
- Install plan: https://forgeregistry.com/api/v1/packages/com.varynforge%2Fserver/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.varynforge%2Fserver
- HTML page: https://forgeregistry.com/registry/com.varynforge%2Fserver
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
