Atlas / MCP servers / acedatacloud / WebExtratorMCP

WebExtratorMCPCAUTION

mcp/acedatacloud/webextratormcp

MCP server for web extraction and rendering via Ace Data Cloud.

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for web rendering and structured content extraction via the AceDataCloud WebExtrator platform.

Features

  • Structured extraction: Pull structured data out of any URL via WebExtrator
  • Web rendering: Render dynamic JavaScript pages and capture the rendered output
  • Asynchronous tasks: Submit extract / render jobs and poll for results
  • Batch task lookup: Query multiple task results in one call

Connect: hosted OAuth, API token, or local stdio

The hosted endpoint is https://webextrator.mcp.acedata.cloud/mcp. Choose one route for the MCP client:

The hosted service advertises OAuth metadata and Dynamic Client Registration (DCR). DCR registers the client application; it is not an API key. OAuth signs you in and the client sends the resulting Bearer token; it may reuse or create an API credential for the account. Browser sign-in still requires an AceDataCloud account. The hosted service can be metered: review current service documentation and displayed pricing before a real operation. Do not configure both an OAuth login and a

Read from source at commit db01a60898cdOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add mcp-webextrator --env ACEDATACLOUD_API_TOKEN=${ACEDATACLOUD_API_TOKEN} -- uvx mcp-webextrator==2026.4.25.0
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
webextrator_get_usage_guidereadGet a comprehensive guide for using the WebExtrator tools.
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (7)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
core/oauth.py:279
logger.info(f"Revoked token: {token.token[:8]}...")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/client.py:111
callback_url: str | None = None,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/client.py:151
if callback_url is not None:
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/client.py:152
payload["callback_url"] = callback_url
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/client.py:201
callback_url: str | None = None,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/client.py:235
if callback_url is not None:
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ruff.toml
.ruff.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha db01a60898cdfull audit observations/trust-audit/mcp-server/acedatacloud__webextratormcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07db01a60898cdCAUTIONB88first audit
06

Questions

What is the WebExtratorMCP MCP server?

MCP server for web extraction and rendering via Ace Data Cloud.

What tools does WebExtratorMCP expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is WebExtratorMCP safe to connect to an agent?

With care. The audit graded it B (88/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does WebExtratorMCP need?

It reads ACEDATACLOUD_API_TOKEN, ACEDATACLOUD_AUTH_BASE_URL and ACEDATACLOUD_OAUTH_CLIENT_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does WebExtratorMCP run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-webextrator.

How current is this page?

The grade is for one exact copy of the source (db01a60898cd), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement