Atlas / MCP servers / bochaai / Bocha Search

Bocha SearchSAFE

mcp/bochaai/bocha-search

Bocha Search MCP Server.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
—
Stars
185
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

版本信息

v1

产品描述

短描述

博查是一个给AI用的搜索引擎,让你的AI应用从近百亿网页和生态内容源中获取高质量的世界知识,涵盖天气、新闻、百科、医疗、火车票、图片等多种领域。

长描述

博查是一个给AI用的搜索引擎,让你的AI应用从近百亿网页和生态内容源中获取高质量的世界知识,涵盖天气、新闻、百科、医疗、火车票、图片等多种领域。

分类

网页搜索

标签

搜索, 新闻, 天气, 百科

Tools

Tool1: Bocha Web Search

详细描述

从博查搜索全网信息和网页链接,返回结果包括网页标题、网页URL、网页摘要、网站名称、网站图标、发布时间、图片链接等。

调试所需要的参数

输入:

  • query: 搜索词(必填)
  • freshness: 搜索指定时间范围内的网页 (可选值 YYYY-MM-DD, YYYY-MM-DD..YYYY-MM-DD, noLimit, oneYear, oneMonth, oneWeek, oneDay. 默认为 noLimit)
  • count: 返回结果的条数 (1-50, 默认为 10)

输出:

  • 网页标题、网页链接、网页摘要、发布时间、网站名称

Tool2: Bocha AI Search

详细描述

在博查网页搜索的基础上,AI识别搜索词语义并额外返回垂直领域内容的结构化模态卡,例如天气卡、日历卡、百科卡等几十种模态卡,在语义识别、搜索结果时效性、内容丰富性等方面更好。

调试所需要的参数

输入:

  • query: 搜索词(必填)
  • freshness: 搜索指定时间范围内的网页 (可选值 YYYY-MM-DD, YYYY-MM-DD..YYYY-MM-DD, noLimit, oneYear, oneMonth, oneWeek, oneDay. 默认为 noLimit)
  • count: 返回结果的条数 (1-50, 默认为 10)

输出:

  • 网页标题、网页链接、网页摘要、发布时间、网站名称、模态卡

可适配平台

方舟, python, Claude, Cursor等

服务开通链接

您需要前往 博查AI开放平台,登陆后获取 API KEY。

鉴权方式

API Key

安装部署

步骤一:下载代码至本地

git clone [email protected]:BochaAI/bocha-search-mcp.git

步骤二: 在客户端中配置

Claude Desktop

Read from source at commit a9ec577606f7OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add bocha-search-mcp --env BOCHA_API_KEY=${BOCHA_API_KEY} -- uvx bocha-search-mcp
claude-desktop
{
  "mcpServers": {
    "bocha-search-mcp": {
      "command": "uvx",
      "args": [
        "bocha-search-mcp"
      ],
      "env": {
        "BOCHA_API_KEY": "${BOCHA_API_KEY}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
bocha_ai_searchreadSearch with Bocha AI Search, recognizes the semantics of search terms
bocha_web_searchreadSearch with Bocha Web Search and get enhanced search details from billions of web documents,
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha a9ec577606f7full audit observations/trust-audit/mcp-server/bochaai__bocha-search.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06a9ec577606f7SAFEB89first audit
06

Questions

What is the Bocha Search MCP server?

Bocha Search MCP Server.

What tools does Bocha Search expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Bocha Search safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Bocha Search need?

It reads BOCHA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Bocha Search run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as bocha-search-mcp.

How current is this page?

The grade is for one exact copy of the source (a9ec577606f7), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement