Atlas / MCP servers / 0xmariowu / Autosearch

AutosearchBLOCK

mcp/0xmariowu/autosearch

Open-source deep research for AI agents: 40 channels, 10+ Chinese sources.

Verdict
BLOCK
Grade
D
Trust score
64 /100
Exposed tools
23 15r · 8w · 0d
Transport
stdio
License
MIT
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Open-source Deep Research for AI Agents

40 channels, including 10+ Chinese sources. MCP-native. LLM-decoupled. Plug into the agent host you already use.

[](https://github.com/0xmariowu/Autosearch/actions/workflows/ci.yml) [](https://github.com/0xmariowu/Autosearch/releases) [](https://www.npmjs.com/package/autosearch-ai) [](LICENSE) [](https://github.com/0xmariowu/Autosearch) [](https://modelcontextprotocol.io)

Install · Channels · MCP Setup · Examples · Docs · 中文

AutoSearch is open-source deep research infrastructure built for AI agents. Plug Claude Code, Cursor, Cline, GPT-Researcher, LangChain, LlamaIndex, AutoGen, and other hosts into MCP-native access across 40 channels, including 10+ Chinese sources.

The engine returns indexed multi-source results and stays uncoupled from LLM calls, so your agent keeps its own model, prompts, and workflow.

You ask your AI to research something. It answers from training data cutoff —

  • "Show me this week's LLM papers on arxiv" → can't, no academic database access
  • "What are people saying about this product on Reddit" → shallow, only surface-level web results
  • "Find similar open-source projects on GitHub" → weak, general search misses most repos
  • "Summarize the Twitter discussion on this topic" → blocked, no public API
  • "Compare opinions on Hacker News vs Chinese tech forums" → two platforms, manual agg
Read from source at commit d19a3680a96cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add autosearch --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN=${AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN} --env AUTOSEARCH_PROXY_TOKEN=${AUTOSEARCH_PROXY_TOKEN} --env AUTOSEARCH_SECRETS_FILE=${AUTOSEARCH_SECRETS_FILE} -- uvx autosearch
claude-desktop
{
  "mcpServers": {
    "autosearch": {
      "command": "uvx",
      "args": [
        "autosearch"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN": "${AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN}",
        "AUTOSEARCH_PROXY_TOKEN": "${AUTOSEARCH_PROXY_TOKEN}",
        "AUTOSEARCH_SECRETS_FILE": "${AUTOSEARCH_SECRETS_FILE}"
      }
    }
  }
}
03

Exposed tools (23)

15 read · 8 write · 0 destructive.

ToolRiskDescription
citation_addwriteAdd URL to citation index (idempotent). Returns {index_id, citation_number, url}.
citation_createwriteCreate a citation index for a research session. Returns {index_id}.
citation_exportreadExport citations as Markdown. Returns {index_id, markdown, count}.
citation_mergewriteMerge source citation index into target. Returns {merged_count, skipped_duplicates}.
consolidate_researchreadCompress accumulated evidence into a compact research brief.
context_retention_policyreadTrim evidence list to fit within token_budget, keeping highest-scored items.
delegate_subtaskwriteRun a query across multiple channels concurrently.
doctorreadScan all configured channels and return their health status with fix hints.
graph_search_planreadBuild a DAG from subtasks and return topologically sorted parallel batches.
healthreadReturn a structured health snapshot for MCP clients.
list_channelsreadList all channels with their runtime availability status.
list_modesreadList available search modes with their channel guidance.
list_skillsreadList autosearch skills with their frontmatter metadata.
loop_add_gapwriteMark a topic as a coverage gap. Returns {state_id, gaps}.
loop_get_gapsreadGet coverage gaps for this loop. Returns {state_id, gaps}.
loop_initreadInitialize a reflective search loop. Returns {state_id}.
loop_updatewriteUpdate loop state with evidence from run_channel. Returns state summary.
perspective_questioningreadGenerate n sub-questions covering different viewpoints on a topic.
recent_signal_fusionreadFilter evidence to items published within the last `days` days, newest first.
run_channelwriteRun a single autosearch channel and return raw evidence.
run_clarifywriteRun the autosearch clarifier on a user query, returning structured output.
select_channels_toolreadSelect 3-8 channels using group-first two-stage algorithm.
trace_harvestreadExtract winning query patterns from a run_channel trace.
04

Trust audit

BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
autosearch/core/transcribe_path_guard.py:21
"*/.ssh/*",
Why it matters. touches a credential store
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/e2b/matrix.yaml:648
cmd: ANTHROPIC_API_KEY=sk-ant-invalid-fake-key-test-for-failure-path $HOME/work/autosearch/.venv/bin/autosearch query "Explain RAG architecture" 2>&1
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/unit/test_diagnostics.py:19
body = "ANTHROPIC_API_KEY=sk-ant-abcdef0123456789ABCDEFGHIJKL"
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/unit/test_diagnostics.py:73
monkeypatch.setenv("FAKE_API_KEY", "sk-ant-fake-secret-value-do-not-leak-12345")
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/unit/test_diagnostics.py:106
monkeypatch.setenv("ANTHROPIC_API_KEY", "sk-ant-test-secret-do-not-leak-abcd1234efgh")
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/unit/test_mcp_error_redaction.py:51
"upstream rejected Authorization: Bearer sk-ant-LEAKED-VALUE-12345-ABCDE"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.perf-baseline
.perf-baseline
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/e2b/matrix.yaml:869
importlib.import_module(m)
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/e2b/matrix-w1w4-bench.yaml:309
# Flag yaml.load / pickle.load / naked eval() usage in autosearch/ code
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
autosearch/skills/channels/bilibili/methods/api_search.py:129
params["w_rid"] = hashlib.md5(f"{filtered}{salt}".encode()).hexdigest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/smoke/test_install_script.py:50
result = run_install_script("--dry-run", "--version", "../../etc/passwd")
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
tests/e2b/matrix-w1w4-bench.yaml:280
# Try to coerce exfiltrating env vars via prompt injection
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/e2b/matrix.yaml:304
for i in $(seq 1 30); do curl -sf http://127.0.0.1:18081/health > /dev/null && break; sleep 1; done
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/e2b/matrix.yaml:751
for i in $(seq 1 30); do curl -sf http://127.0.0.1:18082/health > /dev/null && break; sleep 1; done
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/smoke/conftest.py:203
return f"http://127.0.0.1:{match.group(1)}"
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/e2b/sandbox_runner.py:147
stdout_parts.append(base64.b64decode(d["stdout"]).decode("utf-8", errors="replace"))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/e2b/sandbox_runner.py:149
stderr_parts.append(base64.b64decode(d["stderr"]).decode("utf-8", errors="replace"))
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@commitlint/cli, @commitlint/config-conventional, commitlint, husky
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/install.md:23
- If something requires elevated permissions, **tell the user** and let them decide
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/security/transcribe-allowlist.md:13
hand the tool any file the autosearch process can read — `.env`, SSH
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CHANGELOG.md:198
`curl | bash` install URL.
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CHANGELOG.md:416
- **`npx autosearch-ai` works on Windows.** The wrapper used to hardcode `bash -c "curl ... | bash"`. It now picks an installer based on `process.platform`: pipx → `py -3.12 -m pip --user` → `python -
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CHANGELOG.md:507
- New one-command installer: `curl -fsSL https://raw.githubusercontent.com/0xmariowu/Autosearch/main/scripts/install.sh | bash` — handles uv/pipx/pip automatically and shows the init screen
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CLAUDE.md:110
- Re-install: `curl -fsSL https://raw.githubusercontent.com/0xmariowu/autosearch/main/scripts/install.sh | bash`

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d19a3680a96cfull audit observations/trust-audit/mcp-server/0xmariowu__autosearch.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d19a3680a96cBLOCKD64first audit
06

Questions

What is the Autosearch MCP server?

Open-source deep research for AI agents: 40 channels, 10+ Chinese sources.

What tools does Autosearch expose?

23 in total: 15 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Autosearch safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (64/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Autosearch need?

It reads ANTHROPIC_API_KEY, AUTOSEARCH_PACKING_REQUIRE_SECRET_SCAN, AUTOSEARCH_PROXY_TOKEN, AUTOSEARCH_SECRETS_FILE, AUTOSEARCH_SERVICE_TOKEN, CLI_STARTUP_SECRET_TEST, E2B_API_KEY, FIRECRAWL_API_KEY, FOO_API_KEY, GH_TOKEN, GOOGLE_API_KEY and GROQ_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Autosearch run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as autosearch.

How current is this page?

The grade is for one exact copy of the source (d19a3680a96c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement