NexusCAUTION
MCP Server to make searching openrouter easy
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AI integration without the complexity
[](https://www.npmjs.com/package/nexus-mcp) [](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) [](https://coderabbit.ai)
[](https://archestra.ai/mcp-catalog/adawalli__nexus)
Intelligent AI model search and discovery with zero-install simplicity
Quick Start • Features • Documentation • Contributing
What is Nexus?
Nexus is a Model Context Protocol (MCP) server that provides AI-powered search functionality through the OpenRouter API. It integrates with MCP-compatible clients including Claude Desktop and Cursor, providing search capabilities via multiple model families including Perplexity Sonar (real-time web search) and Grok 4 (training-data knowledge).
Key Characteristics
- Zero-install deployment: Executable via
bunx(ornpx) with no build requirements - OpenRouter integration: Multiple AI models including Perplexity Sonar (web search) and Grok 4 (training data)
- MCP protocol compliance: Implements standard MCP tool and resource interfaces
- Production architecture: Includes request caching, deduplication, retry logic, and error handling
- Type-safe implementation: Full TypeScript coverage with strict type checking
F
8e0ab2399325OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add nexus-mcp --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} --env OPENROUTER_KEY=${OPENROUTER_KEY} -- npx -y [email protected]{
"mcpServers": {
"nexus-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}",
"OPENROUTER_KEY": "${OPENROUTER_KEY}"
}
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
GPT-4 | read | Most capable GPT model |
Sonar | read | A fast search model |
search | read | Nexus AI-powered search using Perplexity and Grok models via OpenRouter. Perplexity models (sonar, sonar-pro, sonar-reasoning-pro, sonar-deep-research) search the web for current information. Grok 4 provides responses from training data without real-time search. |
Trust audit
CAUTIONgrade C · trust 74/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (18)
apiKey: 'sk-or-valid-key-123456789',
apiKey: 'sk-or-valid-key-123456789',
apiKey: 'sk-or-valid-key-123456789',
apiKey: 'sk-or-valid-key-123456789',
apiKey: 'sk-or-valid-key-123456789',
.coderabbit.yaml
.gitleaks.toml
.pre-commit-config.yaml
.prettierignore
.release-it.json
AGENTS.md
import type { ChatCompletionResponse } from '../../src/types/openrouter.js';import { JSONValidator } from '../../src/utils/json-validator.js';import { JsonRpcValidator } from '../../src/utils/json-rpc-validator.js';import { ConfigurationManager } from '../../src/config/manager.js';import { SearchTool } from '../../src/tools/search';@modelcontextprotocol/sdk, axios, data-masking, dotenv, winston, @eslint/js, @release-it/conventional-changelog, @types/bun
- Install Bun: `curl -fsSL https://bun.sh/install | bash`
Gates applied: no_behavioural_pass.
8e0ab2399325full audit observations/trust-audit/mcp-server/adawalli__nexus.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 8e0ab2399325 | CAUTION | C | 74 | first audit |
Questions
What is the Nexus MCP server?
MCP Server to make searching openrouter easy
What tools does Nexus expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Nexus safe to connect to an agent?
With care. The audit graded it C (74/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Nexus need?
It reads OPENROUTER_API_KEY and OPENROUTER_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Nexus run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as nexus-mcp at 3.4.0.
How current is this page?
The grade is for one exact copy of the source (8e0ab2399325), read on 2026-10-09. The repository is watched and re-audited when it changes.