
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
geoaeo makes any app discoverable, quotable, and usable by AI answer engines and search —
SEO, GEO, and AEO in one tool. It audits a site, scores it 0–100, and generates the files
answer engines need. It ships a library, a CLI, and an MCP server, all at one version.
npm install geoaeo
The package name is unscoped: geoaeo, geoaeo (CLI), and geoaeo-mcp (MCP server).
Create geoaeo.config.ts from geoaeo.config.example.ts.
The config holds the site facts used by every generator.
Audit a live site:
npx geoaeo audit https://example.com
npx geoaeo audit https://example.com --json
Audit a local build or source directory:
npx geoaeo audit ./apps/website
Scaffold a Next.js App Router site:
npx geoaeo init ./apps/website
npx geoaeo init ./apps/website --force
The command detects the framework — Next.js, Astro, SvelteKit, Nuxt, or Remix — and writes
the routes that emit each artifact. Other directories receive static files. Existing files
stay unchanged unless you pass --force.
npx geoaeo gen llms
npx geoaeo gen llms-full --output public/llms-full.txt
npx geoaeo gen jsonld --type faq
npx geoaeo gen webmcp
npx geoaeo gen sitemap --output public/sitemap.xml
npx geoaeo gen robots
npx geoaeo gen ogimage --output public/og.svg
npx geoaeo gen rss --output public/feed.xml
npx geoaeo gen hreflang
npx geoaeo gen mdmirror
The generators use the same config as the generated framework routes.
The JSON-LD generator supports software, product, faq, breadcrumb, organization,
website, article, howto, person, and review kinds.
Use --ci in a pipeline to fail when a site drops below a minimum score:
npx geoaeo audit https://example.com --ci --min-score 85
The command exits non-zero when the score is below the threshold.
Run a report for Markdown and JSX files:
npx geoaeo humanize 'content/**/*.md' --check
Rewrite prose in place:
npx geoaeo humanize 'src/**/*.tsx' --write
The humanizer keeps YAML frontmatter, code fences, JSX tags, imports, class names, and expressions. It checks for em dashes, AI vocabulary, filler, hype, fake-depth tails, and title-case headings.
Use the stdio server in an MCP client such as Claude Code or Cursor:
{
"mcpServers": {
"geoaeo": {
"command": "npx",
"args": ["geoaeo-mcp"]
}
}
}
The server exposes audit, gen, and humanize tools.
You can also run it through the CLI:
npx geoaeo mcp
| Command | Purpose |
|---|---|
audit <url-or-dir> | Score the site and list missing artifacts. |
init [dir] | Add Next.js routes or static artifacts. |
gen <artifact> | Print one generated artifact or write it to a file. |
humanize <glob> | Check or rewrite prose files. |
mcp | Run the MCP server over stdio. |
npm test
npm run typecheck
npm run build
FAQs
GEO and AEO artifacts for answer engines and agents
The npm package geoaeo receives a total of 16 weekly downloads. As such, geoaeo popularity was classified as not popular.
We found that geoaeo demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.