PerplexityCAUTION
Perplexity AI search, reasoning, research, and compute - MCP server, dashboard, and multi-IDE auto-config for VS Code.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Long‐lived Perplexity browser session, auto‐config for 20+ IDEs, and a VS Code extension – all in one monorepo.
835d7bf7d684OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add webview --env PERPLEXITY_CSRF_TOKEN=${PERPLEXITY_CSRF_TOKEN} --env PERPLEXITY_DISABLE_KEYCHAIN=${PERPLEXITY_DISABLE_KEYCHAIN} --env PERPLEXITY_OAUTH_CONSENT_TTL_HOURS=${PERPLEXITY_OAUTH_CONSENT_TTL_HOURS} --env PERPLEXITY_SESSION_TOKEN=${PERPLEXITY_SESSION_TOKEN} -- npx -y @perplexity-user-mcp/[email protected]{
"mcpServers": {
"webview": {
"command": "npx",
"args": [
"-y",
"@perplexity-user-mcp/[email protected]"
],
"env": {
"PERPLEXITY_CSRF_TOKEN": "${PERPLEXITY_CSRF_TOKEN}",
"PERPLEXITY_DISABLE_KEYCHAIN": "${PERPLEXITY_DISABLE_KEYCHAIN}",
"PERPLEXITY_OAUTH_CONSENT_TTL_HOURS": "${PERPLEXITY_OAUTH_CONSENT_TTL_HOURS}",
"PERPLEXITY_SESSION_TOKEN": "${PERPLEXITY_SESSION_TOKEN}"
}
}
}
}Exposed tools (17)
17 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
a | read | |
argy | read | |
claim | read | The statement to verify |
keep | read | |
my-cmd | read | mine |
no-args | read | static |
optionA | read | First option |
optionB | read | Second option |
perplexity-compare | read | Compare two options with a sourced comparison table. |
perplexity-fact-check | read | Verify a claim with cited primary sources via perplexity_search. |
perplexity-latest | read | Find the latest developments on a topic via perplexity_search. |
perplexity.reasoningPlan | read | Step-by-step reasoning on a question, routed to perplexity_reason. |
perplexity.researchPlan | read | Deep research brief on a topic, routed to perplexity_research. |
q | read | the query |
question | read | The question to reason about |
topic | read | The subject to research |
x | read | the x |
Trust audit
CAUTIONgrade C · trust 74/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
cookie-jar.js
tainted: { token: "pplx_local_old_YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY" },"-----BEGIN RSA PRIVATE KEY-----",
"-----BEGIN PRIVATE KEY-----",
.vscodeignore
const pkg = JSON.parse(readFileSync(join(__dirname, "../../mcp-server/package.json"), "utf-8"));
import { Vault } from "../../mcp-server/src/vault.js";import { httpLoopbackBuilder } from "../../src/auto-config/transports/http-loopback.js";import { StabilityGateError, type TransportBuildInput } from "../../src/auto-config/transports/index.js";import { httpTunnelBuilder } from "../../src/auto-config/transports/http-tunnel.js";- **A failed background reinit hard-killed the whole daemon → `ECONNREFUSED` in Copilot** ([`reinit-watcher.js`](packages/mcp-server/src/reinit-watcher.js), [`launcher.ts`](packages/mcp-server/src/dae
- **No design regression.** The static daemon bearer is now embedded in IDE `mcp.json` files only when the capability matrix allows http-loopback, and only for loopback URLs (`http://127.0.0.1:<port>/
url = "http://127.0.0.1:<port>/mcp"
"url": "http://127.0.0.1:11819/mcp",
5. Expected: `<configPath>` contains `{url: "http://127.0.0.1:<port>/mcp", headers.Authorization: "Bearer <daemon-static-bearer>"}`.@modelcontextprotocol/sdk, patchright, zod, @types/node, @vitest/coverage-v8, rimraf, tsx, typescript
@perplexity-user-mcp/shared, @types/vscode, @vscode/vsce, jszip, patchright, perplexity-user-mcp, tsup
@modelcontextprotocol/sdk, @ngrok/ngrok, express, got-scraping, gray-matter, helmet, patchright, zod
tsup
@perplexity-user-mcp/shared, lucide-react, motion, react, react-dom, zustand, @tailwindcss/vite, @testing-library/react
- **Keytar probe results are cached per-process** in `vault.js`. Previously `tryKeytar()` re-imported the native module on every vault read, triggering macOS Keychain permission dialogs repeatedly wit
4. If you click **Open GitHub issue**, `vscode.env.openExternal` opens a pre-filled URL against `.github/ISSUE_TEMPLATE/doctor-report.yml` (consent checkboxes gate submission).
| Has live MCP server access (online attack) | Limited by I/O / OS keychain rate | Same | Same — KDF cost is paid once per process lifetime via `_unsealMaterialCache` |
- **(kc.2)** Keychain-mocked process reading a v3 vault written by a passphrase-mocked process (cross-mode) → succeeds. (Conceptual: in practice users don't switch between modes mid-vault, but the for
- **Soft logout left you "logged in"**: [`logout.js`](packages/mcp-server/src/logout.js) now removes `models-cache.json` and `daemon-status.json` (browser-data is deliberately untouched — daemon singl
Gates applied: no_behavioural_pass.
835d7bf7d684full audit observations/trust-audit/mcp-server/automations-project__perplexity-30.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 835d7bf7d684 | CAUTION | C | 74 | first audit |
Questions
What is the Perplexity MCP server?
Perplexity AI search, reasoning, research, and compute - MCP server, dashboard, and multi-IDE auto-config for VS Code.
What tools does Perplexity expose?
17 in total: 17 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Perplexity safe to connect to an agent?
With care. The audit graded it C (74/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Perplexity need?
It reads PERPLEXITY_CSRF_TOKEN, PERPLEXITY_DISABLE_KEYCHAIN, PERPLEXITY_OAUTH_CONSENT_TTL_HOURS, PERPLEXITY_SESSION_TOKEN and PERPLEXITY_VAULT_PASSPHRASE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Perplexity run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @perplexity-user-mcp/webview at 0.1.23.
How current is this page?
The grade is for one exact copy of the source (835d7bf7d684), read on 2026-10-07. The repository is watched and re-audited when it changes.