AutosearchBLOCK
Open-source deep research for AI agents: 40 channels, 10+ Chinese sources.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Open-source Deep Research for AI Agents
40 channels, including 10+ Chinese sources. MCP-native. LLM-decoupled. Plug into the agent host you already use.
[](https://github.com/0xmariowu/Autosearch/actions/workflows/ci.yml) [](https://github.com/0xmariowu/Autosearch/releases) [](https://www.npmjs.com/package/autosearch-ai) [](LICENSE) [](https://github.com/0xmariowu/Autosearch) [](https://modelcontextprotocol.io)
Install · Channels · MCP Setup · Examples · Docs · 中文
AutoSearch is open-source deep research infrastructure built for AI agents. Plug Claude Code, Cursor, Cline, GPT-Researcher, LangChain, LlamaIndex, AutoGen, and other hosts into MCP-native access across 40 channels, including 10+ Chinese sources.
The engine returns indexed multi-source results and stays uncoupled from LLM calls, so your agent keeps its own model, prompts, and workflow.
You ask your AI to research something. It answers from training data cutoff —
- "Show me this week's LLM papers on arxiv" → can't, no academic database access
- "What are people saying about this product on Reddit" → shallow, only surface-level web results
- "Find similar open-source projects on GitHub" → weak, general search misses most repos
- "Summarize the Twitter discussion on this topic" → blocked, no public API
- "Compare opinions on Hacker News vs Chinese tech forums" → two platforms, manual agg
d19a3680a96cOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add autosearch --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN=${AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN} --env AUTOSEARCH_PROXY_TOKEN=${AUTOSEARCH_PROXY_TOKEN} --env AUTOSEARCH_SECRETS_FILE=${AUTOSEARCH_SECRETS_FILE} -- uvx autosearch{
"mcpServers": {
"autosearch": {
"command": "uvx",
"args": [
"autosearch"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN": "${AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN}",
"AUTOSEARCH_PROXY_TOKEN": "${AUTOSEARCH_PROXY_TOKEN}",
"AUTOSEARCH_SECRETS_FILE": "${AUTOSEARCH_SECRETS_FILE}"
}
}
}
}Exposed tools (23)
15 read · 8 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
citation_add | write | Add URL to citation index (idempotent). Returns {index_id, citation_number, url}. |
citation_create | write | Create a citation index for a research session. Returns {index_id}. |
citation_export | read | Export citations as Markdown. Returns {index_id, markdown, count}. |
citation_merge | write | Merge source citation index into target. Returns {merged_count, skipped_duplicates}. |
consolidate_research | read | Compress accumulated evidence into a compact research brief. |
context_retention_policy | read | Trim evidence list to fit within token_budget, keeping highest-scored items. |
delegate_subtask | write | Run a query across multiple channels concurrently. |
doctor | read | Scan all configured channels and return their health status with fix hints. |
graph_search_plan | read | Build a DAG from subtasks and return topologically sorted parallel batches. |
health | read | Return a structured health snapshot for MCP clients. |
list_channels | read | List all channels with their runtime availability status. |
list_modes | read | List available search modes with their channel guidance. |
list_skills | read | List autosearch skills with their frontmatter metadata. |
loop_add_gap | write | Mark a topic as a coverage gap. Returns {state_id, gaps}. |
loop_get_gaps | read | Get coverage gaps for this loop. Returns {state_id, gaps}. |
loop_init | read | Initialize a reflective search loop. Returns {state_id}. |
loop_update | write | Update loop state with evidence from run_channel. Returns state summary. |
perspective_questioning | read | Generate n sub-questions covering different viewpoints on a topic. |
recent_signal_fusion | read | Filter evidence to items published within the last `days` days, newest first. |
run_channel | write | Run a single autosearch channel and return raw evidence. |
run_clarify | write | Run the autosearch clarifier on a user query, returning structured output. |
select_channels_tool | read | Select 3-8 channels using group-first two-stage algorithm. |
trace_harvest | read | Extract winning query patterns from a run_channel trace. |
Trust audit
BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"*/.ssh/*",
cmd: ANTHROPIC_API_KEY=sk-ant-invalid-fake-key-test-for-failure-path $HOME/work/autosearch/.venv/bin/autosearch query "Explain RAG architecture" 2>&1
body = "ANTHROPIC_API_KEY=sk-ant-abcdef0123456789ABCDEFGHIJKL"
monkeypatch.setenv("FAKE_API_KEY", "sk-ant-fake-secret-value-do-not-leak-12345")monkeypatch.setenv("ANTHROPIC_API_KEY", "sk-ant-test-secret-do-not-leak-abcd1234efgh")"upstream rejected Authorization: Bearer sk-ant-LEAKED-VALUE-12345-ABCDE"
.gitleaks.toml
.perf-baseline
importlib.import_module(m)
# Flag yaml.load / pickle.load / naked eval() usage in autosearch/ code
params["w_rid"] = hashlib.md5(f"{filtered}{salt}".encode()).hexdigest()result = run_install_script("--dry-run", "--version", "../../etc/passwd")# Try to coerce exfiltrating env vars via prompt injection
for i in $(seq 1 30); do curl -sf http://127.0.0.1:18081/health > /dev/null && break; sleep 1; done
for i in $(seq 1 30); do curl -sf http://127.0.0.1:18082/health > /dev/null && break; sleep 1; done
return f"http://127.0.0.1:{match.group(1)}"stdout_parts.append(base64.b64decode(d["stdout"]).decode("utf-8", errors="replace"))stderr_parts.append(base64.b64decode(d["stderr"]).decode("utf-8", errors="replace"))@commitlint/cli, @commitlint/config-conventional, commitlint, husky
- If something requires elevated permissions, **tell the user** and let them decide
hand the tool any file the autosearch process can read — `.env`, SSH
`curl | bash` install URL.
- **`npx autosearch-ai` works on Windows.** The wrapper used to hardcode `bash -c "curl ... | bash"`. It now picks an installer based on `process.platform`: pipx → `py -3.12 -m pip --user` → `python -
- New one-command installer: `curl -fsSL https://raw.githubusercontent.com/0xmariowu/Autosearch/main/scripts/install.sh | bash` — handles uv/pipx/pip automatically and shows the init screen
- Re-install: `curl -fsSL https://raw.githubusercontent.com/0xmariowu/autosearch/main/scripts/install.sh | bash`
Gates applied: no_behavioural_pass.
d19a3680a96cfull audit observations/trust-audit/mcp-server/0xmariowu__autosearch.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d19a3680a96c | BLOCK | D | 64 | first audit |
Questions
What is the Autosearch MCP server?
Open-source deep research for AI agents: 40 channels, 10+ Chinese sources.
What tools does Autosearch expose?
23 in total: 15 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Autosearch safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (64/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Autosearch need?
It reads ANTHROPIC_API_KEY, AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN, AUTOSEARCH_PROXY_TOKEN, AUTOSEARCH_SECRETS_FILE, AUTOSEARCH_SERVICE_TOKEN, CLI_STARTUP_SECRET_TEST, E2B_API_KEY, FIRECRAWL_API_KEY, FOO_API_KEY, GH_TOKEN, GOOGLE_API_KEY and GROQ_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Autosearch run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as autosearch.
How current is this page?
The grade is for one exact copy of the source (d19a3680a96c), read on 2026-10-08. The repository is watched and re-audited when it changes.