Atlas / MCP servers / fengin / Search

SearchCAUTION

mcp/fengin/search

一个基于MCP协议的搜索服务实现,提供网络搜索和本地搜索功能,Cursor和Claude Desktop能与之无缝集成。

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
78
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

一个基于MCP协议的搜索服务实现,提供多种搜索引擎支持,Cursor和Claude Desktop能与之无缝集成。

使用Python开发,支持异步处理和高并发请求,目前支持三种搜索引擎选择:

  • Brave Search :国外一家专业提供搜索接口服务产品
  • 秘塔(Metaso)搜索:秘塔AI搜索的逆向实现接口,非官方接口
  • 博查(bocha)搜索:国内Search API市场占有率最高的搜索API产品

更多MCP知识,见AI全书( 一文看懂什么是MCP(大模型上下文)?用来干什么的?怎么用它?)

作者: 凌封(微信fengin)

网址:https://aibook.ren(AI全书)

使用示例

功能特点

  • 多搜索引擎支持:
  • Brave Search: 提供网络搜索和位置搜索
  • Metaso搜索: 提供网络搜索和学术搜索,支持简洁和深入两种模式
  • 博查搜索: 提供网络搜索,支持时间范围过滤、详细摘要和图片搜索
  • 适用场景: Claude Desktop或者Cursor无缝集成使用,大大扩展工具的内容获取能力
  • 模块化设计: 每个搜索引擎都是独立的模块,也可以单独拷出去其他地方使用

三种搜索的选择

运行时只能生效一种搜索引擎,为了方便大家选择配置哪个上线,我列了下大致的对比:

安装和使用

1. 环境要求

  • Python 3.10+
  • uv 0.24.0+
  • node.js v20.15.0
  • cursor >=0.45.10 (低于该版本mcp server配置老是连不上)
  • 科学上网(仅使用Brave Search需要)

1.1 安装浏览器驱动(仅Metaso需要)

# 安装Playwright框架
pip install playwright>=1.35.0
# 安装浏览器驱动,仅安装chromium
playwright install chromium

2.下载代码

git clone https://github.com/fengin/search-server.git

3. 启用你要的搜索引擎

打开项目根目录,修改server.py以下代码选择启用类型:

# 搜索引擎配置
SEARCH_ENGINE = os.getenv("SEARCH_ENGINE", "bocha")

其中值分别对应有brave、metaso、bocha,也可以通过配置环境变量SEARCH_ENGIN

4\. 配置对应的搜索模块

以下三个模块目录下都对应有一个config.py文件:

  • src\search\proxy\brave
  • src\search\proxy\metaso
  • src\search\proxy\bocha

根据你的选择,修改对应的config.py文件配置

4.1 brave search配置

# 检查API密钥
BRAVE_API_KEY = os.getenv("BRAVE_API_KEY")
if not BRAVE_API_KEY:
BRAVE_API_KEY = "你申请的 brave_api_key"

在Claude Desktop里面使用的话,也可以在Claude Desktop里配置通过环境变量传这个参数,但是Cursor目前不支持环境变

Read from source at commit b42512264dcaOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add search-server --env BOCHA_API_KEY=${BOCHA_API_KEY} --env BRAVE_API_KEY=${BRAVE_API_KEY} -- uvx search-server
claude-desktop
{
  "mcpServers": {
    "search-server": {
      "command": "uvx",
      "args": [
        "search-server"
      ],
      "env": {
        "BOCHA_API_KEY": "${BOCHA_API_KEY}",
        "BRAVE_API_KEY": "${BRAVE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
search-by-keyread通地关键词搜索网络资料
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:16
# HTTPS_PROXY=http://127.0.0.1:7890
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:17
# HTTP_PROXY=http://127.0.0.1:7890
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/search/proxy/bocha/requirements.txt
httpx, asyncio, typing-extensions
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/search/proxy/metaso/requirements.txt
aiohttp, beautifulsoup4, playwright, asyncio
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b42512264dcafull audit observations/trust-audit/mcp-server/fengin__search.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b42512264dcaCAUTIONB89first audit
06

Questions

What is the Search MCP server?

一个基于MCP协议的搜索服务实现,提供网络搜索和本地搜索功能,Cursor和Claude Desktop能与之无缝集成。

What tools does Search expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Search safe to connect to an agent?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Search need?

It reads BOCHA_API_KEY and BRAVE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Search run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as search-server.

How current is this page?

The grade is for one exact copy of the source (b42512264dca), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement