Perplexity AskSAFE
The official MCP server implementation for the Perplexity API Platform
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://cursor.com/install-mcp?name=perplexity&config=eyJ1cmwiOiJodHRwczovL2FwaS5wZXJwbGV4aXR5LmFpL21jcCIsImhlYWRlcnMiOnsiQXV0aG9yaXphdGlvbiI6IkJlYXJlciBZT1VSX0FQSV9LRVkifX0%3D)
[](https://vscode.dev/redirect/mcp/install?name=perplexity&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fapi.perplexity.ai%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20%24%7Binput%3Aperplexity-api-key%7D%22%7D%7D&inputs=%5B%7B%22type%22%3A%22promptString%22%2C%22id%22%3A%22perplexity-api-key%22%2C%22description%22%3A%22Perplexity%20API%20Key%22%2C%22password%22%3Atrue%7D%5D)
[
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
perplexity_ask | read | |
perplexity_reason | read | |
perplexity_research | read | |
perplexity_search | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
baseUrl = `http://127.0.0.1:${port}`;baseUrl = `http://127.0.0.1:${port}`;[. Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Perplexity Ask need?
It reads PERPLEXITY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Perplexity Ask run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @perplexity-ai/mcp-server at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (0ed911c73ae0), read on 2026-09-24. The repository is watched and re-audited when it changes.