Claude SearchSAFE
A MCP server that provides web search capabilities using the Claude API.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This MCP (Model Context Protocol) server provides web search capabilities using the Claude API. It allows LLMs to access up-to-date information from the web through a standardized interface.
Features
- Web search tool using Claude's web search API
- Support for domain filtering (allowed and blocked domains)
- Configurable maximum results per search
- Automatic configuration from Claude Desktop config file
Prerequisites
- Node.js 18 or higher
- An Anthropic API key with web search enabled
- Claude Desktop app for testing
Installation & Setup
- Clone the repository:
git clone https://github.com/Doriandarko/claude-search-mcp.git cd claude-search-mcp
- Install dependencies:
npm install
- Build the server:
npm run build
This compiles the TypeScript code and makes the server executable.
- Link the server for global access:
npm link
This makes the mcp-server-claude-search command available system-wide, allowing the Claude Desktop app to find it.
Running the Server with Claude Desktop App
Once the server is installed and linked, the Claude Desktop app can manage it automatically if configured correctly.
- Configure Claude Desktop App:
Open your Claude Desktop app's MCP server configuration file (usually claude_desktop_config.json). Add or update the entry for this server:
{
"mcpServers": {
// ... other servers ...
"claude-search": {
"command": "mcp-server-claude-search",
"env": {
"ANTHROPIC_API_KEY": "YOUR_ANTHROPIC_API_KEY_HERE"
}
}
// ... other servers ...
}
}Replace "YOUR_ANTHROPIC_API_KEY_HERE" with your actual Anthropic API key. The server will also attempt to read this key from ~/code/claude-search-mcp/claude_desktop_config.json if the env variab
47f92699a9d2OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add claude-search-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"claude-search-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
web_search | read | Search the web for real-time information about any topic. Use this tool when you need up-to-date information that might not be available in your training data, or when you need to verify current facts. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@anthropic-ai/sdk, @modelcontextprotocol/sdk, dotenv, express, @types/express, @types/node, shx, tsx
Gates applied: no_behavioural_pass, no_license.
47f92699a9d2full audit observations/trust-audit/mcp-server/doriandarko__claude-search.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 47f92699a9d2 | SAFE | B | 89 | first audit |
Questions
What is the Claude Search MCP server?
A MCP server that provides web search capabilities using the Claude API.
What tools does Claude Search expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Claude Search safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Claude Search need?
It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Claude Search run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-search-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (47f92699a9d2), read on 2026-10-08. The repository is watched and re-audited when it changes.