Atlas / MCP servers / dorukardahan / Domain Search

Domain SearchCAUTION

mcp/dorukardahan/domain-search

Zero-config domain availability MCP server for Claude & ChatGPT. Live pricing via Porkbun, premium/auction detection via GoDaddy, AI suggestions, RDAP/WHOIS fallback. Stdio + HTTP.

Verdict
CAUTION
Grade
C
Trust score
80 /100
Exposed tools
8 8r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/domain-search-mcp) [](https://www.npmjs.com/package/domain-search-mcp) [](LICENSE) [](https://www.npmjs.com/package/domain-search-mcp) [](https://registry.modelcontextprotocol.io) [](https://glama.ai/mcp/servers/@dorukardahan/domain-search-mcp) [](https://context7.com/dorukardahan/domain-search-mcp)

Naming engine with availability intelligence — an MCP server that scores the names your model generates and runs availability checks against domains, socials, and package registries. Works with zero configuration using public RDAP/WHOIS, and optionally enriches results with registrar pricing via a backend you control.

🆕 v1.12.0: name_project — a two-phase naming engine. Call it once to get generation instructions for your model, call it again with candidates[] to get anti-slop scoring, ranking, and live availability checks across domains, socials, and npm. See name_project below.

🆕 v1.10.0: GoDaddy public endpoint integration! Enhanced fallback chain (RDAP → GoDaddy → WHOIS) with premium/auction domain detection. Circuit breaker pattern ensures resilience.

🤖 v1.9.0+: AI-powered domain suggestions work out of the box! No API keys needed - suggest_domains_smart uses our public fine-tuned Qwen 7B-DPO model. Plus: Redis distributed caching and /metrics endpoint for observability.

Built on the Model Context Protocol for Claude, Codex, VS Code, Cursor, Cline, and other MCP-compatible clients.

Fe

Read from source at commit 24a77aad42f6OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add domain-search-mcp --env PRICING_API_TOKEN=${PRICING_API_TOKEN} --env PORKBUN_API_KEY=${PORKBUN_API_KEY} --env PORKBUN_API_SECRET=${PORKBUN_API_SECRET} --env NAMECHEAP_API_KEY=${NAMECHEAP_API_KEY} -- npx -y [email protected]
03

Exposed tools (8)

8 read · 0 write · 0 destructive.

ToolRiskDescription
bulk_searchreadCheck availability for multiple domain names at once. Efficiently searches up to 100 domains in parallel with rate limiting. Use a single TLD for best performance. Returns: - Availability status for each domain - Pricing where available - Summary statistics Example: - bulk_search([
demo-projreada demo
domainsreadDomain availability and search operations
name_projectreadTwo-phase naming engine. Call without candidates to receive generation instructions for YOUR model
search_domainreadSearch for domain availability and pricing across multiple TLDs. Returns: - Availability status for each domain - Pricing (first year and renewal) when Pricing API is configured - Whether WHOIS privacy is included - Human-readable insights and next steps Examples: - search_domain(
socialreadSocial media handle availability
suggestionsreadAI-powered domain name suggestions
tld_inforeadGet information about a Top Level Domain (TLD). Returns: - Description and typical use case - Price range - Any special restrictions - Popularity and recommendations Example: - tld_info(
04

Trust audit

CAUTIONgrade C · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
training/eval/__pycache__/__init__.cpython-314.pyc
__init__.cpython-314.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
training/eval/__pycache__/constraint_satisfaction.cpython-314.pyc
constraint_satisfaction.cpython-314.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
training/eval/__pycache__/diversity_metrics.cpython-314.pyc
diversity_metrics.cpython-314.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
training/eval/__pycache__/premium_score.cpython-314.pyc
premium_score.cpython-314.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
training/eval/__pycache__/pronounceability.cpython-314.pyc
pronounceability.cpython-314.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/services/domain-hunter.ts:175
'prime', 'apex', 'elite', 'summit', 'vertex', 'titan', 'atlas', 'beacon',
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/utils/semantic-engine.ts:183
'wallet', 'oracle', 'monitor', 'tracker', 'scan', 'pulse', 'beacon', 'sentry',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:29
# QWEN_INFERENCE_ENDPOINT=http://127.0.0.1:8070
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/openapi/generator.ts:209
const apiVersion = version || require('../../package.json').version;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/adaptive-concurrency.test.ts:1
import { AdaptiveConcurrencyLimiter } from '../../src/utils/adaptive-concurrency';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/aftermarket-regression.test.ts:19
import type { DomainResult } from '../../src/types';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/aftermarket-regression.test.ts:28
jest.mock('../../src/fallbacks/rdap', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/aftermarket-regression.test.ts:35
jest.mock('../../src/services/pricing-api', () => ({
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:304
QWEN_INFERENCE_ENDPOINT=http://127.0.0.1:8070
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CONFIGURATION.md:85
QWEN_INFERENCE_ENDPOINT=http://127.0.0.1:8070
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/MULTI_PLATFORM_EXPANSION.md:138
Environment=PRICING_API_BASE_URL=http://127.0.0.1:3000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/config.test.ts:48
process.env[QWEN_ENV] = 'http://127.0.0.1:8070';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
cache-backend/package.json
fastify, @fastify/cors, @fastify/rate-limit, pg, ioredis, dotenv, zod, @types/node
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@asteasolutions/zod-to-openapi, @modelcontextprotocol/sdk, axios, cors, dotenv, express, express-rate-limit, ioredis
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
training/requirements.txt
torch, transformers, accelerate, peft, bitsandbytes, datasets, sentencepiece, trl
Why it matters. 13 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
training/output-full/adapter_model.safetensors
training/output-full/adapter_model.safetensors
Why it matters. 3451752 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
training/output-full/checkpoint-2000/adapter_model.safetensors
training/output-full/checkpoint-2000/adapter_model.safetensors
Why it matters. 3451752 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
training/output-full/checkpoint-2000/merges.txt
training/output-full/checkpoint-2000/merges.txt
Why it matters. 1671853 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
training/output-full/checkpoint-2000/optimizer.pt
training/output-full/checkpoint-2000/optimizer.pt
Why it matters. 3594810 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
training/output-full/checkpoint-2000/tokenizer.json
training/output-full/checkpoint-2000/tokenizer.json
Why it matters. 11421896 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 24a77aad42f6full audit observations/trust-audit/mcp-server/dorukardahan__domain-search.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0924a77aad42f6CAUTIONC80first audit
06

Questions

What is the Domain Search MCP server?

Zero-config domain availability MCP server for Claude & ChatGPT. Live pricing via Porkbun, premium/auction detection via GoDaddy, AI suggestions, RDAP/WHOIS fallback. Stdio + HTTP.

What tools does Domain Search expose?

8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Domain Search safe to connect to an agent?

With care. The audit graded it C (80/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Domain Search need?

It reads API_TOKEN, NAMECHEAP_API_KEY, OPENROUTER_API_KEY, PORKBUN_API_KEY, PORKBUN_API_SECRET, PRICING_API_TOKEN and TOGETHER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Domain Search run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as domain-search-mcp at 1.13.1.

How current is this page?

The grade is for one exact copy of the source (24a77aad42f6), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement