Atlas / MCP servers / doriandarko / Claude Search

Claude SearchSAFE

mcp/doriandarko/claude-search

A MCP server that provides web search capabilities using the Claude API.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
—
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This MCP (Model Context Protocol) server provides web search capabilities using the Claude API. It allows LLMs to access up-to-date information from the web through a standardized interface.

Features

  • Web search tool using Claude's web search API
  • Support for domain filtering (allowed and blocked domains)
  • Configurable maximum results per search
  • Automatic configuration from Claude Desktop config file

Prerequisites

  • Node.js 18 or higher
  • An Anthropic API key with web search enabled
  • Claude Desktop app for testing

Installation & Setup

  1. Clone the repository:
git clone https://github.com/Doriandarko/claude-search-mcp.git
cd claude-search-mcp
  1. Install dependencies:
npm install
  1. Build the server:
npm run build

This compiles the TypeScript code and makes the server executable.

  1. Link the server for global access:
npm link

This makes the mcp-server-claude-search command available system-wide, allowing the Claude Desktop app to find it.

Running the Server with Claude Desktop App

Once the server is installed and linked, the Claude Desktop app can manage it automatically if configured correctly.

  1. Configure Claude Desktop App:

Open your Claude Desktop app's MCP server configuration file (usually claude_desktop_config.json). Add or update the entry for this server:

{
"mcpServers": {
// ... other servers ...
"claude-search": {
"command": "mcp-server-claude-search",
"env": {
"ANTHROPIC_API_KEY": "YOUR_ANTHROPIC_API_KEY_HERE"
}
}
// ... other servers ...
}
}

Replace "YOUR_ANTHROPIC_API_KEY_HERE" with your actual Anthropic API key. The server will also attempt to read this key from ~/code/claude-search-mcp/claude_desktop_config.json if the env variab

Read from source at commit 47f92699a9d2OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add claude-search-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "claude-search-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
web_searchreadSearch the web for real-time information about any topic. Use this tool when you need up-to-date information that might not be available in your training data, or when you need to verify current facts.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @modelcontextprotocol/sdk, dotenv, express, @types/express, @types/node, shx, tsx
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 47f92699a9d2full audit observations/trust-audit/mcp-server/doriandarko__claude-search.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0847f92699a9d2SAFEB89first audit
06

Questions

What is the Claude Search MCP server?

A MCP server that provides web search capabilities using the Claude API.

What tools does Claude Search expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Claude Search safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Claude Search need?

It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claude Search run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-search-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (47f92699a9d2), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement