AskYourStack

com.askyourstackv0.18.0Updated Oct 7, 2026

Let Claude, ChatGPT or Cursor manage your servers, sites and SEO, with approvals for risky actions.

Overview

AI-generated overview

Lets an AI assistant manage Linux servers, websites and SEO through a hosted remote MCP endpoint, with approval for risky actions.

What it does
AskYourStack is a hosted remote MCP server that gives an assistant tools to inspect and operate Linux servers and the sites on them. It can read server facts, health reports, logs and files, run shell commands, manage databases, take snapshots and roll back, and work with Magento, WordPress and other site consoles. It also exposes SEO tools covering Google Search Console, Analytics 4, Core Web Vitals, Bing Webmaster data, Cloudflare DNS and firewall, keyword research, site audits and structured data. Destructive actions are meant to wait for the owner's approval.
When to use it
Useful when you want an assistant to run day-to-day server and site operations, such as installing or fixing a shop, taking backups, cleaning malware, hardening a server, migrating a site, or diagnosing SEO and performance problems from real crawl and log data.
Requirements
A remote MCP endpoint at askyourstack.com; nothing runs locally. You need an AskYourStack account and a small agent installed on each Linux server (systemd, x86_64 or ARM64). Clients connect either by signing in with OAuth or by pasting a private MCP address from the dashboard. Google Search Console, Analytics 4, Bing and Cloudflare connections are optional and set up in the dashboard.
Before you install
The server can run shell commands, write and replace files, change databases, alter DNS and firewall rules, and delete data, so approvals and server modes matter. The private MCP address in the URL path should be kept secret and rotated if leaked. Database credentials are read from site configs and are not sent to the AI. Paid plans are required for write actions and SEO tools, and the AI client is billed separately.

Installation

In SourceWeft

  1. Open AskYourStack in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "askyourstack": {
      "type": "http",
      "url": "https://askyourstack.com/mcp"
    }
  }
}

README

AskYourStack MCP server

Let Claude, ChatGPT, Cursor or Claude Code manage your own Linux servers, with approvals for anything risky.

AskYourStack is a hosted, remote MCP server. Install a small agent on your server with one line, add your private AskYourStack MCP address to your AI client, and ask in plain words: set up a raw VPS, install Magento or WordPress, fix a 500 error, take backups, clean up malware, harden the server or move a site to a new one. For SEO it reads Google Search Console, Google Analytics 4, Core Web Vitals, on-page audits and your structured data next to what Googlebot really fetches in your server logs, and fixes the causes on the server.

This repository holds the listing and documentation for the AskYourStack MCP server. The service itself is hosted at askyourstack.com; there is nothing to build or run locally.

How it works

  1. Connect your server. Sign up free at askyourstack.com, name your server and paste the one-line install as the Linux user who owns your sites (the agent then manages only that user's sites and files), or as root when it should run the whole server. The agent dials out to askyourstack.com over HTTPS: it opens no port, and no SSH key or password is stored anywhere.
  2. Add AskYourStack to your AI client with your private MCP address from the dashboard (see below).
  3. Ask. Your AI looks at the server first, explains its plan, and runs the work through AskYourStack's tools. Anything destructive waits for your approval.

Connect your AI client

Two ways in:

  • Sign in (OAuth): clients that support sign-in for remote MCP servers connect to https://askyourstack.com/mcp. You sign in to AskYourStack, see which app is asking and allow it. Each app gets its own access, which you can end under Security in the dashboard.
  • Private address: https://askyourstack.com/mcp/YOUR-ADDRESS, from the dashboard, for clients without sign-in. Keep it private, and make a new one in the dashboard if it leaks. The examples below use it.

The tool and playbook catalogue is public at https://askyourstack.com/mcp/catalog.

Claude (claude.ai and Claude Desktop): Settings, Connectors, Add custom connector. Name it AskYourStack, paste the address and leave the OAuth fields empty. Guide

Claude Code:

bash
claude mcp add --transport http sudowhizzy https://askyourstack.com/mcp/YOUR-ADDRESS

Guide

Cursor (mcp.json):

json
{  "mcpServers": {    "sudowhizzy": { "url": "https://askyourstack.com/mcp/YOUR-ADDRESS" }  }}

Guide

ChatGPT: Settings, Connectors, turn on developer mode, then add a custom connector with your address and no authentication. Guide

Any other client that supports remote MCP servers over streamable HTTP works the same way.

Tools

ToolWhat it doesPlan
overviewWhere everything stands in one call: plan, servers and their sites, open problems and warnings from the monitoring, approvals waiting, connected Google properties, saved notes and recent workFree
propose_planAsk approval once for a job with several risky steps: the user sees every risky step and approves them together; each then runs once, exactly as listedFree
save_note, forget_noteShort notes about a server or the account that the next chat sees in overview (never passwords: those are refused)Free
log_workA plain summary of a finished task, for the owner's dashboard and the next chatFree
list_serversThe servers on the account: online, safety mode, pausedFree
server_factsDistro, CPU, memory, disk, package manager, services, ports, Magento and WordPress installsFree
get_playbookStep-by-step guides for the AI (see Playbooks)Free
health_reportDisk and inodes, memory, load, failed services, certificates, security updates, reboot needed, backups (age and rhythm), out-of-memory kills, PHP out of workers, database connection limit; on Pro and Agency also software with a known vulnerabilityFree
list_sitesThe sites on the server: Magento 2, OpenMage (Magento 1), WordPress and WooCommerce, PrestaShop, Shopware 6, Drupal, Joomla, OpenCart and Laravel, found from the web server's own configuration (Plesk, CloudPanel, RunCloud, DirectAdmin and plain layouts) and in Docker containers: kind, root, domains, access logs, owner, version, database (passwords never shown), its consoleFree
logsA log by name (web-error, php, magento, wordpress, database, system, mail, auth, or any file) for a time window, with repeated errors counted once, a sample of each and the latest linesFree
read_fileRead a fileFree
runRun a shell command as the agent's user (root, or the site's own user); read-only commands on FreeFree / Starter
list_jobs, job_outputFollow background jobs, reading only new outputFree
list_snapshotsSnapshots on the serverFree
start_job, stop_jobLong commands (installs, composer, imports) in the background, surviving the chatStarter
write_fileCreate or replace a file, keeping the previous versionStarter
snapshot, rollbackSave folders and databases, write them back; a rollback can itself be undoneStarter
db_queryOne SQL statement with the site's own credentials; reads in a read-only transactionStarter
magentobin/magento as the site's ownerStarter
wpwp-cli as the site's ownerStarter
site_consoleRun a site's own command line tool as its owner, also inside a Docker container: bin/console (Shopware 6, PrestaShop), artisan (Laravel), drush (Drupal), Joomla's cli. Lists run straight away; uninstalling, database resets and arbitrary code need approvalStarter
connected_sitesSites connected without a server (a WordPress on any host, through its REST API with an application password, or a WhizzyCommerce shop through the shop's own connector): name, mode, content typesFree
content_list, content_getRead a connected site's posts, pages, media, categories, tags and other content typesFree
content_save, content_upload, content_trash, content_undoWrite drafts, edit, upload images, trash and undo on a connected site, inside the mode its owner chose (read-only, drafts only, publish too); what a change replaced is kept 90 daysStarter
whizzy_toolsWhat a connected WhizzyCommerce shop lets the AI do right now (the merchant decides per group in their WhizzyCommerce dashboard); search for one capability to read its whole input schemaFree
whizzy_callRun one capability of a connected WhizzyCommerce shop. Reads answer at once; a change comes back as a preview with a link the merchant confirms in their own dashboard, and its outcome can be read afterwards. Nothing the shop answers is storedFree (reads), Starter
keyword_volumeGoogle search volume, 12-month history, CPC and competition for up to 200 keywords in a country and language (metered: a monthly allowance per plan)Starter, SEO Starter
keyword_ideasUp to 100 keyword suggestions around a seed, with volume, keyword difficulty and intentStarter, SEO Starter
serp_checkThe live Google results for a keyword, desktop or mobile, with the user's site marked and the page features (AI overview, snippets, people also ask)Starter, SEO Starter
domain_keywordsWhat a domain ranks for, with position, volume, estimated visits and page, and its competitorsStarter, SEO Starter
bing_sitesThe sites in the user's Bing Webmaster Tools account (connected on the SEO page by signing in at Bing or with an API key) and which the AI may readStarter, SEO Starter
bing_performanceBing search performance: daily impressions and clicks, the last 28 days against the 28 before, top queries and pages, the pages of one query or the queries of one pageStarter, SEO Starter
bing_crawlBingbot's crawl: pages crawled and in the index, errors, crawl issues per address, one address inspectedStarter, SEO Starter
bing_keywordsKeyword research from Bing's own data: searches on Bing for a keyword, monthly history, related keywordsStarter, SEO Starter
bing_backlinksInbound links Bing knows: the site's pages with the most links, and who links to one page with which anchor textStarter, SEO Starter
bing_sitemapsThe sitemaps Bing knows for a site with status and countsStarter, SEO Starter
bing_submitSubmit up to 500 pages or a sitemap to Bing, with the quota leftStarter, SEO Starter
cf_zonesThe Cloudflare zones the user connected with an API token (Sites page), with status, plan, name servers and the connection's modeStarter
cf_dnsDNS records of a zone: list, add, change, remove. Records that were there before AskYourStack need the connection's "change anything" mode; every change can be undoneStarter
cf_purge_cacheClear a zone's Cloudflare cache, everything or given addressesStarter
cf_firewallCustom rules and rate limits: block, challenge, allow, log by address, network, ASN, country, path, user agent, or a raw expression; remove; every rule can be undoneStarter
cf_settingsUnder attack mode, security level, development mode, browser check; in the fullest mode SSL mode, always use HTTPS and minimum TLSStarter
cf_analyticsTraffic through Cloudflare: requests, cached share, visitors, threats, bandwidth and status codes per day, top countries, requests per hour, a sample of what the firewall stopped in the last 24 hoursStarter
cf_undoUndo a Cloudflare change made through cf_dns, cf_firewall or cf_settings, or list themStarter
redirectsGone pages: the 404s from the crawler logs and Search Console with a suggested target each, the site's own redirects (Magento url_rewrite, WordPress Redirection or Rank Math), new ones written with a preview and undone by batch, or the nginx and Apache lines to placeStarter
convert_imagesWebP or AVIF copies next to a site's JPEG and PNG uploads, made as the site's owner with the server's own encoder; originals untouched, a second run does only new filesStarter
list_dumpsThe database dumps kept on a server, by kind, size and ageFree
db_restoreLoad a dump back into a site's database with its own credentials; the database as it is now is dumped first, so the restore can be undoneStarter
seo_fieldsSEO titles, meta descriptions and image alt texts of a WordPress site (Yoast SEO, Rank Math, SEOPress, The SEO Framework) or a Magento 2 shop (products, categories, CMS pages, image labels): list what is there or missing, change in small batches with a preview of old against new, undo a batchStarter
db_dumpDump a site's database on its server, with its own credentialsStarter
transfer, transfer_closeCopy a folder directly between two of your servers for a migrationStarter
malware_scanBackdoors, PHP in uploads, disguised PHP, injected scripts in the database, suspicious cron, plus a maintained rule set: known skimmer and backdoor signatures, missing Magento security patches, vulnerable modules, WordPress plugins and themes, exposed .git and .env, config copies, crypto miners and rootkit signs on the serverPro
crawl_reportWhat Googlebot, Bingbot, AI crawlers and SEO tools really fetched, from the access logs: errors, crawl waste, fake GooglebotsFree
site_auditCrawl a whole site from the server it runs on (up to 5,000 pages, no CDN in the way), in the background: status, redirects, titles, canonicals, noindex, word counts, links, sitemap coverage for every pagePro
site_audit_reportRead a site audit by issue (broken links, redirect chains, repeated titles, duplicate and thin pages, sitemap problems), by page, or against the run beforePro
seo_historyDaily Search Console, Analytics and Core Web Vitals figures stored once the user switches history on, with alerts: clicks fell, a top page left the index, a vital turned poorStarter
indexnow_submitTell Bing, Yandex and the other IndexNow search engines which pages are new, changed or goneStarter
gsc_propertiesThe Google Search Console properties the user picked (connected read-only in the dashboard)Starter
gsc_performance_overviewHow the site is doing: the period against the one before, daily trend, biggest winning and losing queries and pagesStarter
gsc_search_analyticsClicks, impressions, CTR and position by query, page, country, device or date, with filters and two-period comparisonStarter
gsc_inspect_urlGoogle's URL Inspection for up to 20 URLs: indexed or not and why, last crawl, Google's canonicalStarter
gsc_sitemapsSubmitted sitemaps: errors, warnings, last download, URLs per typeStarter
core_web_vitalsReal-user LCP, INP, CLS, FCP and TTFB from the Chrome UX Report for a page or site, LCP broken into parts, 6 months of weekly history, optional Lighthouse testStarter
validate_schemaStructured data (JSON-LD and microdata) checked against schema.org and Google's rich-result requirements, live URL or pasted HTMLStarter
google_updatesGoogle core, spam and Discover updates since 2021 with their rollout dates, to line up with traffic changesStarter
gsc_cannibalizationSearches where two or more of the site's pages compete in Google, with clicks, impressions and position per pagePro
ga4_propertiesThe Google Analytics 4 properties the user picked, with a tracking health check (data flowing, key events, retention)Pro
ga4_overviewSessions, users, engagement, conversions and revenue against the period before, by channel, with organic search's sharePro
ga4_landing_pagesLanding pages with engagement, bounce rate, conversions and revenue, per channel and compared with an earlier periodPro
ga4_ai_trafficVisits from ChatGPT, Perplexity, Gemini, Claude, Copilot and other AI assistants, and the pages they land onPro
ga4_reportAny GA4 report: new vs returning, site search terms, devices, countries, sources, e-commercePro
ga4_realtimeActive users in the last 30 minutes by page, country and devicePro
page_auditOn-page audit of up to 10 URLs on any site: redirects, headers, title, description, robots, canonical, hreflang, headings, Open Graph, alt text, content length, issuesPro
page_linksEvery link on a page with anchor text and nofollow; finds broken and redirected linksPro
page_contentA page's main text without navigation and footers, as markdownPro
robots_checkrobots.txt tests the way Google reads them, for Googlebot, Bingbot and AI crawlersPro
sitemap_checkSitemap audit (indexes, limits, lastmod) with a sample of URLs checked for status, redirects, noindex and canonicalPro

Search Console history by plan: Starter the last 30 days, Pro 90 days, Agency all 16 months Google keeps. Google Analytics 4: Pro 10 properties and 90 days, Agency 25 and all history. Core Web Vitals: 100 checks a day on Starter, 300 on Pro, 1,000 on Agency. Agency can connect up to 3 Google accounts (clients' own).

Playbooks

Served as MCP prompts and through get_playbook: server-setup, magento, wordpress, hardening, backups, site-checkup, malware-cleanup, migrate, bot-attack, seo-technical, publish-content, performance, updates, site-down, add-site, staging, restore, magento-upgrade, email, woocommerce, prestashop, shopware, drupal, laravel, other-shops (Joomla, OpenCart, OpenMage), seo-dashboard, whizzycommerce, ghost. The AI fetches the right one on its own for tasks like a fresh Magento install or a hacked site.

Safety

  • Every call is sorted by risk. Reads run at once. Changes run after /etc is saved. Destructive actions (deleting your data, dropping databases, SSH, sudo and firewall changes, reboots) wait for your approval. Anything touching the agent's own key is blocked.
  • Approvals the AI cannot fake. You approve signed in on askyourstack.com; an approval runs once, only with the exact arguments you saw, within 30 minutes. Text planted in a log or web page cannot approve anything. The approval page says in plain words what the action does, what could go wrong and how to undo it, and before an approved delete of database tables or whole folders a copy is saved first when the command names them plainly.
  • Modes and kill switch. Each server is read-only, normal or full trust. Pause a server or the whole account in one click; disconnecting revokes the agent.
  • Undo. /etc snapshots before changes, previous versions of every overwritten file, snapshots and rollback.
  • Secrets stay on the server. Database credentials are read from the site's own config and never reach the AI. Your MCP address is stored only as a hash.
  • Signed agent updates and a full audit log of every call.

More at https://askyourstack.com/security

Supported servers

Linux with systemd (Debian, Ubuntu, Rocky Linux, AlmaLinux, RHEL and similar), x86_64 or ARM64, from any provider. A fresh VPS or a server already running a shop or site.

Pricing

Free: one server, read-only, 50 tool calls a day. Paid plans add changes, approvals and snapshots and the SEO tools with Google Search Console (Starter, 1 server, 3 properties), the malware scan, site checks every 15 minutes, Google Analytics 4, on-page and technical SEO tools and longer history (Pro, 5 servers, 10 properties; Agency, 25 servers, 25 properties, up to 3 Google accounts). Current prices: https://askyourstack.com/#pricing. Your AI client is billed separately by its own provider.

Support

[email protected] · Terms · Privacy

AskYourStack is operated by Whizzy Digital Solutions Lda, Portugal. The agent installed on your server is open source (Apache-2.0): https://github.com/shopwhizzy/askyourstack-agent, with a script that checks each release against its source. The hosted service is proprietary; this README may be quoted in MCP directories and listings.

Source: README.md at commit ec96582

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.18.0LatestOct 7, 2026