
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
MCP server: check whether ChatGPT, Perplexity and Gemini recommend a business. By Cited (cited.voreli.ai)

Ask ChatGPT, Perplexity and Gemini the questions your customers ask, with live web search on, and see whether they recommend your business.
By Cited, the AI visibility tracker from Voreli AI.
cited-mcp is an open-source Model Context Protocol server. Add it to Claude Desktop, Claude Code, Cursor or any MCP client, then ask something like:
Check whether AI engines recommend Sunshine Dental (sunshinedental.com) for family dentist questions in Tampa, FL.
For every question and engine it reports:
check_ai_visibility| Argument | Required | Notes |
|---|---|---|
business_name | yes | e.g. Sunshine Dental & Implants, LLC |
website | no | e.g. sunshinedental.com. Used to detect citations of your pages. |
questions | no | 1 to 10 buyer questions. |
category | if no questions | e.g. family dentist. Generates 5 generic buyer questions. |
location | no | e.g. Tampa, FL. Used in generated questions. |
engines | no | Any of openai, perplexity, gemini. Default: every engine with a key. |
Name matching ignores case and punctuation, treats & and and as the same, drops legal suffixes such as LLC, Inc and Co, and also counts a mention of your website domain. Website citation matches the domain and its subdomains against every URL the engine cited.
You bring your own API keys and pay each provider directly. Set any one, two or all three; engines without a key are skipped with a note.
Edit claude_desktop_config.json (Settings, Developer, Edit Config):
{
"mcpServers": {
"cited": {
"command": "npx",
"args": ["-y", "cited-mcp"],
"env": {
"OPENAI_API_KEY": "sk-...",
"PERPLEXITY_API_KEY": "pplx-...",
"GEMINI_API_KEY": "..."
}
}
}
}
claude mcp add cited -e OPENAI_API_KEY=sk-... -e PERPLEXITY_API_KEY=pplx-... -e GEMINI_API_KEY=... -- npx -y cited-mcp
Add to ~/.cursor/mcp.json (or .cursor/mcp.json in a project):
{
"mcpServers": {
"cited": {
"command": "npx",
"args": ["-y", "cited-mcp"],
"env": {
"OPENAI_API_KEY": "sk-...",
"PERPLEXITY_API_KEY": "pplx-...",
"GEMINI_API_KEY": "..."
}
}
}
}
Any other MCP client works the same way: run npx -y cited-mcp over stdio with the keys in its environment. Node 20 or newer.
| Variable | Engine | Default model |
|---|---|---|
OPENAI_API_KEY | ChatGPT via the OpenAI Responses API with the web_search tool | gpt-5.4-mini (override with OPENAI_MODEL) |
PERPLEXITY_API_KEY | Perplexity Sonar (search is built in) | sonar (override with PERPLEXITY_MODEL) |
GEMINI_API_KEY | Gemini with Grounding with Google Search | gemini-3.5-flash-lite (override with GEMINI_MODEL) |
The API versions of these engines are close to, but not the same as, the consumer apps. ChatGPT, Perplexity and Gemini in the browser can use different models, personalization and location signals.
This is the tool's real output format, run against the sample responses in test/fixtures, which follow each provider's documented response format (the businesses are made up):
# AI visibility check: Sunshine Dental & Implants (sunshinedental.com)
- ChatGPT (OpenAI API): named in 1 of 1 answers, website cited in 1
- Perplexity: named in 0 of 1 answers, website cited in 0
- Gemini: named in 1 of 1 answers, website cited in 1
## "What is the best dentist in Tampa, FL?"
- ChatGPT (OpenAI API): NAMED, #2 of 3 listed, website cited
- Named instead: Bayshore Smiles, Harbor Family Dentistry
- Sources: bayshoresmiles.com, yelp.com, sunshinedental.com
- Perplexity: not named, website not cited
- Named instead: Harbor Family Dentistry, Bayshore Smiles, Westshore Dental Group
- Sources: yelp.com, bayshoresmiles.com, healthgrades.com
- Gemini: NAMED, #2 of 3 listed, website cited
- Named instead: Westshore Dental Group, Bayshore Smiles
- Sources: sunshinedental.com, yelp.com
Estimated provider cost: $0.0229. AI answers change from run to run, so treat one check as a snapshot, not a score. Costs are estimates from token usage at list prices; you pay your provider directly.
Track this weekly with Cited: https://cited.voreli.ai
The tool also returns the same data as structured JSON (structuredContent) for clients that use it.
There is no Cited fee and no account. Each question is one API call per engine, billed to your own provider account at their list prices (checked October 2026):
| Engine | What you pay per question |
|---|---|
OpenAI gpt-5.4-mini | $10 per 1,000 web search calls, plus tokens at $0.75 per 1M input and $4.50 per 1M output. Search results count as input tokens. |
Perplexity sonar | $5 per 1,000 requests (low search context), plus tokens at $1 per 1M. Perplexity reports the exact cost and the tool uses it. |
Gemini gemini-3.5-flash-lite | See Google's current Gemini API pricing (https://ai.google.dev/gemini-api/docs/pricing). The cost estimate shows $0 for models without a built-in price; check your Google billing for the real figure. |
In practice that is a few cents or less per question per engine, so a default check (5 questions on 3 engines, 15 calls) should land well under a dollar. Every result includes an estimate computed from the token counts the provider returned. It does not include Gemini grounding fees past the free daily allowance. Check your provider dashboard for the exact charge. Prices change; see OpenAI, Perplexity and Gemini.
PERPLEXITY_API_KEY=your-key npm run live
Uses whichever of OPENAI_API_KEY, PERPLEXITY_API_KEY and GEMINI_API_KEY are set. Override the target with BUSINESS, WEBSITE, LOCATION and QUESTION. A single check costs a few cents.
This server answers "are we named today?". Cited runs the same questions every week across engines, stores the history, and shows which competitors and sources are winning so you can see whether your work is moving the number.
npm install
npm test # unit tests against sample responses, no network
npm run typecheck
npm run build
npm run smoke # spawns the server over stdio, lists tools, runs a no-key call
To try it with the MCP Inspector: npx @modelcontextprotocol/inspector node dist/index.js.
MIT. Built by Voreli AI. Questions or ideas: open an issue, or visit cited.voreli.ai.
FAQs
MCP server: check whether ChatGPT, Perplexity and Gemini recommend a business. By Cited (cited.voreli.ai)
The npm package cited-mcp receives a total of 344 weekly downloads. As such, cited-mcp popularity was classified as not popular.
We found that cited-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.