Atlas / MCP servers / mzxrai / Web Research

Web ResearchSAFE

mcp/mzxrai/web-research-2

MCP web research server (give Claude real-time info from the web)

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
MIT
Stars
298
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for web research.

Bring real-time info into Claude and easily research any topic.

Features

  • Google search integration
  • Webpage content extraction
  • Research session tracking (list of visited pages, search queries, etc.)
  • Screenshot capture

Prerequisites

Installation

First, ensure you've downloaded and installed the Claude Desktop app and you have npm installed.

Next, add this entry to your claude_desktop_config.json (on Mac, found at ~/Library/Application\ Support/Claude/claude_desktop_config.json):

{
"mcpServers": {
"webresearch": {
"command": "npx",
"args": ["-y", "@mzxrai/mcp-webresearch@latest"]
}
}
}

This config allows Claude Desktop to automatically start the web research MCP server when needed.

Usage

Simply start a chat with Claude and send a prompt that would benefit from web research. If you'd like a prebuilt prompt customized for deeper web research, you can use the agentic-research prompt that we provide through this package. Access that prompt in Claude Desktop by clicking the Paperclip icon in the chat input and then selecting Choose an integration → webresearch → agentic-research.

Tools

  1. search_google
  2. Performs Google searches and extracts results
  3. Arguments: { query: string }
  1. visit_page
  2. Visits a webpage and extracts its content
  3. Arguments: { url: string, takeScreenshot?: boolean }
  1. take_screenshot
  2. Takes a screenshot of the current page
  3. No arguments required

Prompts

agentic-research

A guided research prompt that helps Claude conduct thorough web research. The prompt instructs

Read from source at commit 7caf6d7902e4OBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-webresearch -- npx -y @mzxrai/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-webresearch": {
      "command": "npx",
      "args": [
        "-y",
        "@mzxrai/[email protected]"
      ]
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
search_googlereadSearch Google for a query
take_screenshotreadTake a screenshot of the current page
visit_pagereadVisit a webpage and extract its content
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
playwright, turndown, shx, tsx, typescript, @types/turndown
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mcp_spec/llms-full.txt:2197
# Load environment variables
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 7caf6d7902e4full audit observations/trust-audit/mcp-server/mzxrai__web-research-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-057caf6d7902e4SAFEB89first audit
06

Questions

What is the Web Research MCP server?

MCP web research server (give Claude real-time info from the web)

What tools does Web Research expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Web Research safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Web Research need?

No credential environment variables were found in its source, so it appears to need none.

How does Web Research run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mzxrai/mcp-webresearch at 0.1.7.

How current is this page?

The grade is for one exact copy of the source (7caf6d7902e4), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement