Atlas / MCP servers / jae-jae / G-Search

G-SearchBLOCK

mcp/jae-jae/g-search

A powerful MCP server for Google search that enables parallel searching with multiple keywords simultaneously.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
273
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful MCP server for Google search that enables parallel searching with multiple keywords simultaneously.

This project is modified from google-search.
🌟 Recommended: OllaMan - Powerful Ollama AI Model Manager.

Advantages

  • Parallel Searching: Supports searching with multiple keywords on Google simultaneously, improving search efficiency
  • Browser Optimization: Opens multiple tabs in a single browser instance for efficient parallel searching
  • Automatic Verification Handling: Intelligently detects CAPTCHA and enables visible browser mode for user verification when needed
  • User Behavior Simulation: Simulates real user browsing patterns to reduce the possibility of detection by search engines
  • Structured Data: Returns structured search results in JSON format for easy processing and analysis
  • Configurable Parameters: Supports various parameter configurations such as search result limits, timeout settings, locale settings, etc.

Quick Start

Run directly with npx:

npx -y g-search-mcp

First time setup - install the required browser by running the following command in your terminal:

npx playwright install chromium

Debug Mode

Use the --debug option to run in debug mode (showing browser window):

npx -y g-search-mcp --debug

Configure MCP

Configure this MCP server in Claude Desktop:

MacOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%/Claude/claude_desktop_config.json

{
"mcpServers": {
"g-search": {
"command": "npx",
"args": ["-y", "g-search-mcp"]
}
}
}

Features

  • search - Execute Google searches with multiple keywords and return results
  • Uses Play
Read from source at commit 412e4c7f9372OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add g-search-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "g-search-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
searchreadSearch on Google for multiple keywords and return the results
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/services/googleSearch.ts:800
results = await page.$$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/services/googleSearch.ts:854
results = await page.$$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, playwright, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 412e4c7f9372full audit observations/trust-audit/mcp-server/jae-jae__g-search.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06412e4c7f9372BLOCKD69first audit
06

Questions

What is the G-Search MCP server?

A powerful MCP server for Google search that enables parallel searching with multiple keywords simultaneously.

What tools does G-Search expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is G-Search safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does G-Search need?

No credential environment variables were found in its source, so it appears to need none.

How does G-Search run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as g-search-mcp at 0.1.5.

How current is this page?

The grade is for one exact copy of the source (412e4c7f9372), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement