Atlas / MCP servers / pwilkin / SearXNG Scraper

SearXNG ScraperSAFE

mcp/pwilkin/searxng-scraper

An MCP server that queries public SearXNG instances, parsing HTML contents into a JSON result

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
MIT
Stars
55
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server that queries public SearXNG instances, parsing HTML contents into a JSON result

Rationale

All the MCP servers for SearXNG that I've seen use "json" as the output format. While that is certainly a faster way to code a SearXNG MCP server, it will make it fail on virtually all public servers since they don't expose the JSON format.

This server will read from up to three public SearXNG servers (using one as main and the others as fallback) and will parse the results into JSON.

Installation

Install via npm install mcp-searxng-public.

If the server is installed, the run configuration is (for Cursor or Cursor-compatible clients) as follows:

{
"SearXNGScraper": {
"command": "npx",
"args": ["mcp-searxng-public"],
"capabilities": {
"tool-calls": true
},
"env": {
"SEARXNG_BASE_URL": "https://metacat.online;https://nyc1.sx.ggtyler.dev;https://ooglester.com;https://search.080609.xyz;https://search.canine.tools;https://search.catboy.house;https://search.citw.lgbt;https://search.einfachzocken.eu;https://search.federicociro.com;https://search.hbubli.cc;https://search.im-in.space;https://search.indst.eu",
"DEFAULT_LANGUAGE": "en"
}
}
}

Note: You may need to adjust the env variables, particularly SEARXNG_BASE_URL, to point to your preferred SearXNG instances. The DEFAULT_LANGUAGE can also be set as needed. You can run the report task to get a report on good (accessible) SearXNG instances which you can put in the URLs line.

[](https://lmstudio.ai/install-mcp?name=sear-xng-scraper&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyJtY3Atc2VhcnhuZy1wdWJsaWMiXSwiZW52

Read from source at commit 55b421599db7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-searxng-public -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-searxng-public": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
searchreadPerforms a web search for a given query using the public SearXNG search servers. Returns an array of result objects with \
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:38
[![Add MCP Server sear-xng-scraper to LM Studio](https://files.lmstudio.ai/deeplink/mcp-install-light.svg)](https://lmstudio.ai/install-mcp?name=sear-xng-scraper&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
fastmcp, zod, @types/node, typescript, vitest
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 55b421599db7full audit observations/trust-audit/mcp-server/pwilkin__searxng-scraper.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0855b421599db7SAFEB89first audit
06

Questions

What is the SearXNG Scraper MCP server?

An MCP server that queries public SearXNG instances, parsing HTML contents into a JSON result

What tools does SearXNG Scraper expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SearXNG Scraper safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does SearXNG Scraper need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (55b421599db7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement