The best OpenClaw SEO plugins, skills and MCP servers (October 2026)
OpenClaw gives you an agent that lives in your chat apps and keeps running when your laptop is closed. That makes it a very good SEO assistant, but only if it can see real data, and only if what you install to give it that data does not also give a stranger your credentials. This guide covers which SEO MCP servers and ClawHub skills are worth connecting, what each one is actually good at, and the config that wires them in, checked against OpenClaw's own documentation on October 5, 2026.
Disclosure: we build one of the servers on this list (the GSC Wizard MCP). It gets the same "watch for" section as everything else, and the free options that do a similar job are listed right after it.
On this page
A Search Console MCP server. Measured data about your own site, and the question most SEO work starts from.
The Semrush, Ahrefs or DataForSEO remote server, whichever you already pay for. All three are vendor-run.
ClawHub skills. Useful as written procedures, risky as credential holders. Read them before you run them.
Skills, plugins and MCP servers: three different things
People search for "OpenClaw SEO plugins", but OpenClaw has three separate extension points, and they carry very different amounts of risk:
Skills
A folder containing a SKILL.md file (YAML frontmatter plus Markdown instructions), sometimes with scripts next to it. Skills teach the agent a procedure, such as "how to run a content audit". They are installed from ClawHub with openclaw skills install, or written by hand into your workspace's skills/ directory.
Plugins
Code that extends the Gateway itself. OpenClaw's tool-permission docs are blunt about it: "Plugins run in-process with the Gateway - treat them as trusted code." Few SEO jobs need one.
MCP servers
Connections to an external data source, declared under mcp.servers in ~/.openclaw/openclaw.json. The MCP docs note that their tools "go through the same tool-profile and tool-policy controls as everything else - connecting a server does not bypass your policy." For a hosted server, the code runs on the vendor's side, not on your machine.
The rule of thumb that follows: get your data through MCP servers and your procedures through skills. A skill that pulls data itself usually means community code on your machine handling your Google or SEO-platform credentials. A vendor's remote MCP server keeps that credential flow with the vendor, and OpenClaw's tool policy can still restrict what the agent calls.
Vet before you install: what ClawHavoc taught everyone
In February 2026 Koi Security found 341 malicious skills on ClawHub. Most of them used fake "prerequisites" to install the Atomic Stealer macOS infostealer. OpenClaw responded by scanning uploads with VirusTotal, and the registry now shows security-audit verdicts. But ClawHub is, in its own words, "open by default: anyone can upload". SEO is an attractive category to impersonate, because SEO skills legitimately ask for API keys. Before you install anything:
- Run
clawhub inspect <skill>and read theSKILL.mdand every script in the folder. An instructions-only skill is low risk. A skill that tells you tocurl | sha "dependency" is a red flag. - Check where your credential goes. Does the skill call the vendor's API directly, a third-party gateway, or a server you have never heard of?
- Prefer the vendor's own MCP server to a community skill that wraps the same API.
- Give SEO keys the narrowest scope available. Read-only wherever the service offers it.
- Run
openclaw security auditafter any change to skills, plugins or MCP servers.
The shortlist at a glance
| Option | Type | Best at | Data | Runs where |
|---|---|---|---|---|
| GSC Wizard | Remote MCP | GSC + GA4 + Bing analysis, multi-year history | First-party | Hosted |
| Community GSC servers | Stdio MCP | Free Search Console pulls | First-party | Your Gateway host |
| Google Analytics MCP | Stdio MCP | GA4 reports and funnels | First-party | Your Gateway host |
| Semrush | Remote MCP | Competitive research | Modelled | Hosted |
| Ahrefs | Remote MCP | Backlinks | Modelled | Hosted |
| DataForSEO | Remote MCP | Raw SERP and keyword data | Raw / modelled | Hosted |
| Brave web_search | Built-in | Live SERP checks | Live web | Brave API |
| Managed browser | Built-in | Rendering and checking pages | Live web | Your Gateway host |
| ClawHub SEO skills | Skills | Audit and writing procedures | Whatever they call | Your Gateway host |
MCP servers for SEO data
Any MCP server you would use in Claude or Cursor also works in OpenClaw. What changes is that the agent can run unattended, so cost model, permission scope and tool-list size matter more than in an interactive chat. For the wider landscape, see the best SEO MCP servers; below is what is specific to OpenClaw.
1. GSC Wizard MCP
Good at: giving an always-on agent finished answers about your own Search Console, GA4 and Bing data. The server is hosted at https://mcp.gscwizard.com/mcp over Streamable HTTP, so there is no process to keep alive next to your Gateway. Analysis runs on the server against a ClickHouse warehouse, which matters for agents. detect_anomalies, find_decaying_content, analyze_cannibalization or score_opportunities return a computed result instead of 25,000 rows that the model would have to summarise after truncation. Stored properties keep up to ten years of history, past Google's 16-month limit, so the agent can compare against last year's season.
Watch for: it is a paid product, and it is ours. It also exposes well over a hundred tools. On OpenClaw, use --include to load only the families you need (see the config below). For a scheduled agent, use a read-scoped API key: a read key cannot call a mutation tool, whatever the prompt says.
Access: plans from €17/month with a 7-day free trial, MCP access on every plan. Create a key under Account → API keys.
2. Community Search Console servers
Good at: free Search Console access. ahonn/mcp-server-gsc and AminForou/mcp-gsc are stdio servers, and OpenClaw supports stdio, so they run on your Gateway host. The OpenClaw setup is actually friendlier than ChatGPT's or Claude's web clients, which cannot reach a local process at all.
Watch for: setup usually means a Google Cloud project and a service-account JSON key stored on the Gateway host, which is a broad, long-lived credential sitting next to an agent that reads untrusted web content. They also inherit the Search Console API's 16-month history ceiling and row limits.
3. Google Analytics MCP (official)
Good at: the conversion half of the picture: run_report and run_funnel_report against the GA4 Data API, from Google's own googleanalytics/google-analytics-mcp. Pair it with a Search Console server and the agent can answer "which pages earn clicks and convert".
Watch for: it is labelled experimental, it is read-only, and it runs locally against a Google Cloud project you set up yourself. GSC Wizard exposes GA4 through the same connection if you would rather run one server than two.
4. Semrush MCP
Good at: competitor and keyword research if Semrush is already your platform. The official endpoint is https://mcp.semrush.com/v2/mcp, Streamable HTTP only, with OAuth by default.
Watch for: it draws on your subscription's API units, and an unattended agent can spend units much faster than a person clicking through the UI. Cap date ranges and row counts in the prompt, and do not schedule open-ended research.
5. Ahrefs MCP
Good at: backlink work. Ahrefs runs a remote server at https://api.ahrefs.com/mcp/mcp (docs). The older local ahrefs-mcp-server repository is marked no longer maintained, so ignore guides that still point at it.
Watch for: row caps scale with your plan, and the traffic figures are modelled. Never let the agent put them unlabelled next to Search Console clicks.
6. DataForSEO MCP
Good at: raw SERP, keyword and backlink data billed per request, which suits a scheduled rank or SERP-feature check. The public remote URL is https://mcp.dataforseo.com/v3/mcp (note the /v3/; some guides drop it), and the TypeScript server can also be self-run.
Watch for: responses are large and uninterpreted. Constrain every scheduled call to a fixed keyword list and a fixed location.
Built-in OpenClaw tools you already have
Two built-ins cover a lot of SEO ground before you install anything:
web_searchwith the Brave provider. OpenClaw supports the Brave Search API as a search provider (setBRAVE_API_KEY). It is useful for spot-checking a live SERP, and Brave is also the index Claude leans on for citations (see how to rank in Brave Search). Remember it is Brave's ranking, not Google's.- The managed browser. A dedicated Chromium profile the agent controls, good for checking what a rendered page actually shows, its title, canonical and robots meta.
Both read untrusted content from the open web. OpenClaw's prompt-injection guidance recommends limiting exec, browser, web_fetch and web_search to trusted agents or allowlists. An agent that browses competitor pages should not also hold a write key to your properties.
ClawHub SEO skills
These are the most-downloaded SEO-related skills we found on ClawHub on October 5, 2026. All of them are community-published, none by the vendor they name, and none was flagged by ClawHub's scanner when we checked. That is a snapshot, not an endorsement: read each one before installing.
| Skill | What it covers | Check before installing |
|---|---|---|
| ivangdavila/seo | Site audit, content writing and competitor analysis (~18.5k downloads) | Which data sources it calls; whether "audit" means real data or the model's opinion |
| byungkyu/google-search-console | Search Console via the Maton managed-OAuth gateway (~8.1k) | Your Google token is held by a third-party gateway |
| jdrhyne/gsc | Search Console (~7.5k) | How the Google credential is created and stored |
| hith3sh/google-search-console-seo | Search Console SEO workflows (~7.1k) | Same as above |
| maverick-software/dataforseo | DataForSEO API | Whether the official remote MCP covers the same need |
| geozhu/ahrefs | Ahrefs API | Same; Ahrefs runs its own remote MCP |
| hith3sh/semrush-seo | Semrush API | Same; Semrush runs its own remote MCP |
| oomol/oo-bing-webmaster | Bing Webmaster Tools | Where the Bing API key is stored |
Our honest read: the most useful SEO skills are the ones you write yourself. A twenty-line SKILL.md that says "for a weekly review, call these four tools, label every figure with its source and date range, and post three actions" is safer than any download, and better fitted to your site. The continuous SEO analysis guide includes one you can copy.
Connect GSC Wizard to OpenClaw
The same pattern works for any remote server above. The one setting people get wrong is the transport: when it is omitted, OpenClaw uses SSE, and GSC Wizard, Semrush and Ahrefs all speak Streamable HTTP. Set it explicitly.
With an API key (best for unattended runs; create a read key under Account → API keys), in ~/.openclaw/openclaw.json:
{
mcp: {
servers: {
gscwizard: {
url: "https://mcp.gscwizard.com/mcp",
transport: "streamable-http",
headers: { Authorization: "Bearer gscw_live_..." }
}
}
}
}openclaw mcp doctor warns when a header holds a literal secret, and it is right to. Once the connection works, move the key into OpenClaw's secrets mechanism and never commit the file.
With OAuth (when the Gateway host can open a browser), use the CLI. GSC Wizard publishes standard MCP OAuth discovery with dynamic client registration, so there is no client ID to paste:
openclaw mcp set gscwizard '{"url":"https://mcp.gscwizard.com/mcp","transport":"streamable-http","auth":"oauth"}'
openclaw mcp login gscwizardThen probe it. As the docs put it, "saving a definition proves nothing about reachability - the probe does":
openclaw mcp doctor gscwizard --probeTrim the tool list. Every tool definition costs context on every turn. If you add the server with openclaw mcp add, the --include flag takes a comma-separated list of names or globs. For example, --include 'list_sites,get_site_summary,detect_*,find_*,get_ranking_changes,score_opportunities,analyze_*' keeps the analysis tools and leaves out the write tools entirely.
Technical details (endpoint, scopes, the 60-calls-per-minute rate limit) are in the GSC MCP server reference. The setup is the same whichever client connects.
Three stacks that work
Site owner, one property
One Search Console server (GSC Wizard or a community one) and Brave web_search. Add a weekly review automation that posts to your Telegram or Slack. No ClawHub installs needed.
Agency, many clients
A hosted first-party server with a read key per agent, plus the platform you already pay for (Semrush or Ahrefs). Keep the platform server out of the agent that writes client reports, so the reported numbers stay measured.
Builder, monitoring pipeline
GSC Wizard for ground truth and DataForSEO for fixed-keyword SERP checks, both on schedules, delivered with --webhook into your own system. Your own skills only.
Frequently asked questions
Does OpenClaw support MCP servers?
Yes: Streamable HTTP, SSE and stdio, declared under mcp.servers in openclaw.json, or added in the Control UI (Settings → MCP) or with openclaw mcp add / set. Note that it is mcp.servers, not the mcpServers key you see in Claude Desktop configs and in several third-party OpenClaw guides.
Should I use a ClawHub skill or an MCP server for SEO data?
MCP server for the data, skill for the procedure. A data-fetching skill is usually community code holding your credentials. A vendor's remote server keeps the credentials with the vendor.
Are ClawHub SEO skills safe?
Treat them as code you are about to run. ClawHub scans uploads since the ClawHavoc incident, but anyone can still publish. Inspect first, and prefer instructions-only skills.
Is there an official Google Search Console MCP server?
No. Google ships an official GA4 server but none for Search Console. Every option is community or commercial.
Why won't my remote MCP server connect?
Usually the transport: OpenClaw defaults to SSE when transport is omitted. Set "streamable-http" and run openclaw mcp doctor <name> --probe.
Written by Jan-Willem Bobbink · Published October 5, 2026 · OpenClaw details checked against docs.openclaw.ai on the same date