SearchCAUTION
一个基于MCP协议的搜索服务实现,提供网络搜索和本地搜索功能,Cursor和Claude Desktop能与之无缝集成。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
一个基于MCP协议的搜索服务实现,提供多种搜索引擎支持,Cursor和Claude Desktop能与之无缝集成。
使用Python开发,支持异步处理和高并发请求,目前支持三种搜索引擎选择:
- Brave Search :国外一家专业提供搜索接口服务产品
- 秘塔(Metaso)搜索:秘塔AI搜索的逆向实现接口,非官方接口
- 博查(bocha)搜索:国内Search API市场占有率最高的搜索API产品
更多MCP知识,见AI全书( 一文看懂什么是MCP(大模型上下文)?用来干什么的?怎么用它?)
作者: 凌封(微信fengin)
网址:https://aibook.ren(AI全书)
使用示例
功能特点
- 多搜索引擎支持:
- Brave Search: 提供网络搜索和位置搜索
- Metaso搜索: 提供网络搜索和学术搜索,支持简洁和深入两种模式
- 博查搜索: 提供网络搜索,支持时间范围过滤、详细摘要和图片搜索
- 适用场景: Claude Desktop或者Cursor无缝集成使用,大大扩展工具的内容获取能力
- 模块化设计: 每个搜索引擎都是独立的模块,也可以单独拷出去其他地方使用
三种搜索的选择
运行时只能生效一种搜索引擎,为了方便大家选择配置哪个上线,我列了下大致的对比:
安装和使用
1. 环境要求
- Python 3.10+
- uv 0.24.0+
- node.js v20.15.0
- cursor >=0.45.10 (低于该版本mcp server配置老是连不上)
- 科学上网(仅使用Brave Search需要)
1.1 安装浏览器驱动(仅Metaso需要)
# 安装Playwright框架 pip install playwright>=1.35.0 # 安装浏览器驱动,仅安装chromium playwright install chromium
2.下载代码
git clone https://github.com/fengin/search-server.git
3. 启用你要的搜索引擎
打开项目根目录,修改server.py以下代码选择启用类型:
# 搜索引擎配置
SEARCH_ENGINE = os.getenv("SEARCH_ENGINE", "bocha")其中值分别对应有brave、metaso、bocha,也可以通过配置环境变量SEARCH_ENGIN
4\. 配置对应的搜索模块
以下三个模块目录下都对应有一个config.py文件:
- src\search\proxy\brave
- src\search\proxy\metaso
- src\search\proxy\bocha
根据你的选择,修改对应的config.py文件配置
4.1 brave search配置
# 检查API密钥
BRAVE_API_KEY = os.getenv("BRAVE_API_KEY")
if not BRAVE_API_KEY:
BRAVE_API_KEY = "你申请的 brave_api_key"在Claude Desktop里面使用的话,也可以在Claude Desktop里配置通过环境变量传这个参数,但是Cursor目前不支持环境变
b42512264dcaOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add search-server --env BOCHA_API_KEY=${BOCHA_API_KEY} --env BRAVE_API_KEY=${BRAVE_API_KEY} -- uvx search-server{
"mcpServers": {
"search-server": {
"command": "uvx",
"args": [
"search-server"
],
"env": {
"BOCHA_API_KEY": "${BOCHA_API_KEY}",
"BRAVE_API_KEY": "${BRAVE_API_KEY}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
search-by-key | read | 通地关键词搜索网络资料 |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
# HTTPS_PROXY=http://127.0.0.1:7890
# HTTP_PROXY=http://127.0.0.1:7890
httpx, asyncio, typing-extensions
aiohttp, beautifulsoup4, playwright, asyncio
Gates applied: no_behavioural_pass.
b42512264dcafull audit observations/trust-audit/mcp-server/fengin__search.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b42512264dca | CAUTION | B | 89 | first audit |
Questions
What is the Search MCP server?
一个基于MCP协议的搜索服务实现,提供网络搜索和本地搜索功能,Cursor和Claude Desktop能与之无缝集成。
What tools does Search expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Search safe to connect to an agent?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Search need?
It reads BOCHA_API_KEY and BRAVE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Search run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as search-server.
How current is this page?
The grade is for one exact copy of the source (b42512264dca), read on 2026-10-07. The repository is watched and re-audited when it changes.