TL;DR
- What it is: a model, tools, a loop and rules. Not a chatbot with a publish button.
- What it can do: read data, find gaps, draft. It can't see prompt volume or promise a citation.
- Build one: three parts. An MCP server for data, a skill for the method, rules for the stops.
- A real run: ours made 6 read calls, 0 writes, and proposed 0 new posts.
- Guardrails: five of them. The agent stops before it writes a file.
- Schedule it: three ways in Claude Code. Schedule reads, not writes.
Does AI name your brand? Check your site.
Lots of pages sell an AI SEO agent.
I wanted to see one work.
So we ran one. On our own project. With our own data.
It read our AI search data. It checked our blog. It wrote a plan.
The plan said: write zero new posts.
That's an agent I'd trust. Here's how it's built.
What an AI SEO agent is

Four parts.
- A model. It reads and writes text.
- Tools. How it reaches your data, your files, the web.
- A loop. It looks at the last result and picks the next step.
- Rules. What it must not do.
A chatbot answers. An agent does steps.
Anthropic drew the line in Building effective agents (19 December 2024). A workflow follows a code path that someone wrote in advance. An agent directs its own process and its own tool use.
The same article gives advice most vendors skip. Find the simplest solution. Add complexity only when you need it.
So an "AI SEO agent" is that, pointed at SEO work.

What an agent can and cannot do

| It can | It cannot |
|---|---|
| Read your AI search data | See prompt volume. No engine publishes it |
| Find the pages AI cites for your prompts | Promise a citation |
| Compare those pages with your blog | Hear your sales calls |
| Draft a plan, a post, an email | Be you on Reddit |
The left column is reading and drafting.
The right column is judgment, or facts that don't exist.
An agent that claims the right column is guessing.
Build one in three parts

This build uses Claude Code. Any MCP client works the same way.
1. Data: connect the MCP server
An agent with no data makes things up.
Our MCP server gives it your real AI search data. Eight tools. Seven only read.
claude mcp add --transport http aiseotracker https://aiseotracker.com/api/agent/mcp
Then run /mcp in Claude Code and sign in through the browser.
You need a project with a finished scan. Without one, the tools return no_data.
2. Method: add a skill
A skill is a Markdown file with steps and rules.
Ours for content planning is public. Paste this:
Fetch https://aiseotracker.com/content-coverage/SKILL.md and follow it for [your-domain.com].
It sets the call order. It sets where to stop.
3. Rules: write the stops down
Put them in your CLAUDE.md. So they hold for each session.
## AI SEO agent rules
- Read data with the aiseo_* tools. Do not call aiseo_add_prompts unless I ask.
- Use numbers from tool output only. No invented ranks, URLs or trends.
- Stop and show me the plan before you write a file.
- Do not commit, push, publish, email or post.
That's the agent. A model, eight tools, one skill, four rules.
A real run on our own project
3 October 2026. Claude Code in the desktop app. Our own project. The content coverage skill.
First it read the data.

- 7 prompts tracked. The latest answers name us on 0.
- 215 cited pages.
- Only 5 of those pages are cited for more than one prompt.
- One page is cited for 3 prompts: Zapier's list.
Then it read our blog folder. 54 posts.
It grouped the 7 prompts into 5 intents. Then it looked for a page per intent.
Each of the 5 had one.
Then it opened the lists the engines cite.

Named on 0 of the 4 lists it could open.
Then it stopped.

The plan:
- New posts: 0. Each intent has a page.
- Rewrites: later. All 5 pages were updated on 2 or 3 October. No scan has seen them yet.
- One risk: 3 of our pages sit near the same intent.
- Three lists to pitch. As drafts. It sent nothing.
The agent's reading: our gap isn't content. It's the lists.
I agree. With a caveat. 7 prompts is a small set.
Notice what it didn't do.
It didn't write 5 posts because the cap allows 5.
Write-first agents fill the quota. This one read first, and the data said no.
Five guardrails

1. Read-only by default.
Seven of our eight tools read. The one write adds prompts to track, and only when you ask.
2. Data before prose.
The skill fills a data block from tool output first. Then it writes. A number with no source has nowhere to hide.
3. Stop before it writes.
Phase 4 of the skill is a stop.
4. Cap the batch.
5 posts. Not 50.
5. No outward actions.
No deploy. No push. No email. No public post.
Here are the lines, from the file itself:

Why so strict?
Because the failure mode is public.
Google's spam policies list scaled content abuse: many pages made mainly to manipulate rankings, however they're made.
An agent that publishes on its own can get you there fast.
What to automate and what to keep

Agent alone
- Read the data.
- Write the weekly recap.
- Find the pages AI cites.
Agent drafts, you approve
- The content plan.
- Post drafts.
- Outreach emails.
- New prompts to track.
You only
- Publish.
- Post on Reddit.
- Pick the strategy.
My test for the lanes: can you undo it?
A read can't hurt. A draft can be thrown away. A published post, a sent email, a Reddit comment: those are out.
Run it on a schedule
A recap is more useful when it shows up without you.
Claude Code has three ways to schedule a prompt.

| Way | Runs on | Good for |
|---|---|---|
/loop | Your open session | Polling for an hour or a day. Recurring tasks expire after 7 days |
| Desktop task | Your machine, app open, computer awake | A weekly recap that needs your files |
| Routine | The cloud | A run that must happen when your laptop is off. Minimum interval: 1 hour |
For a weekly recap I'd pick a Desktop task.
The prompt:
Fetch https://aiseotracker.com/ai-seo-report/SKILL.md and write the weekly brief for [your-domain.com]. Read only. Do not add prompts. Do not write files.
We run one agent on a schedule ourselves. A read-only analytics check, every Monday morning. It reports. It changes nothing.
One limit to know. I haven't tested our MCP server in a cloud Routine. The run above was on the desktop.
And one rule: schedule reads, not writes.
Nobody is there to approve at 9am on Monday.
Build or buy
Vendors sell hosted SEO agents. I haven't tested them, so I won't rank them.
Four questions work for any of them. Ours too.

- What data does it read? Real AI answers for your prompts? Or the model's memory?
- What can it publish without you? If the answer is "posts", ask how you stop it.
- Can you read its rules? Ours are a public file.
- Does it show the numbers behind each claim? A rank with no source is a guess.
Building costs you an hour and a Claude plan.
Buying saves the hour. Check the four answers first.
FAQ
What is an AI SEO agent?
A language model with tools, a loop and rules, used for SEO work. It reads data, decides the next step, and drafts.
Can an AI agent do SEO on its own?
Parts of it. Reading data and drafting: yes.
Publishing and outreach: I'd keep a person in the loop.
Do I need to code?
Not for this setup. One command to connect, one prompt to paste, four rules in a file.
Is it safe to let an agent publish posts?
I wouldn't. Mass-made pages are what Google's scaled content abuse policy targets. And a wrong number in public is hard to take back.
Let it draft. You publish.
What does it cost?
The agent runs on your own Claude plan.
The data needs an AI SEO Tracker project with a scan. A report is $49 once: up to 50 prompts, five engines, 7 days of scans.
Does the agent ask ChatGPT my prompts itself?
No. The skill tells it not to scrape live AI answers. It reads the scans in your project.
Why did your agent propose zero posts?
Each of our 5 prompt intents had a page. And the lists that engines cite don't name us.
More posts wouldn't fix that. Getting on the lists might.





