Atlas / MCP servers / shelpuk-ai-technology-consulting / Kindly Web Search

Kindly Web SearchCAUTION

mcp/shelpuk-ai-technology-consulting/kindly-web-search

Kindly Web Search MCP Server: Web search + robust content retrieval for AI coding tools (Claude Code, Codex, Cursor, GitHub Copilot, Gemini, etc.) and AI agents (Claude Desktop, OpenClaw, Hermes, etc.). Supports Serper, Tavily, and SearXNG.

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
2 2r · 0w · 0d
Transport
streamable-http
License
MIT
Stars
395
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Web search + robust content retrieval for AI coding tools.

Kindly Web Search is a part of the [Shelpuk AI Technology Consulting](https://shelpuk.com) agentic suite – a set of tools that together improve the code quality produced by AI coding agents by 15–20%. Read more on Claude Code generation quality improvement.

Works with Claude Code, Codex, Antigravity, Cursor, Windsurf, and any agent that supports skills or MCP servers.

If you like what we're building, please ⭐ star this repo – it's a huge motivation for us to keep going!

How to use the suite

1. Install three MCP servers and one skill:

2. Use the skill when requesting a feature:

Prompt your favorite AI coding agent (Claude Code, Codex, Cursor, etc.)

Read from source at commit eddc01a6b402OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add kindly-web-search-mcp-server --env APIFARE_TOKEN=${APIFARE_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env KINDLY_CHROME_PROXY_BYPASS=${KINDLY_CHROME_PROXY_BYPASS} --env SERPBASE_API_KEY=${SERPBASE_API_KEY} -- uvx kindly-web-search-mcp-server
claude-desktop
{
  "mcpServers": {
    "kindly-web-search-mcp-server": {
      "command": "uvx",
      "args": [
        "kindly-web-search-mcp-server"
      ],
      "env": {
        "APIFARE_TOKEN": "${APIFARE_TOKEN}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}",
        "KINDLY_CHROME_PROXY_BYPASS": "${KINDLY_CHROME_PROXY_BYPASS}",
        "SERPBASE_API_KEY": "${SERPBASE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
get_contentreadFetch a single URL and return best-effort, LLM-ready Markdown for that page.
web_searchreadSearch the web and return top results with best-effort Markdown for each result URL.
04

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (24)

MEDIUMSupply chain · supply.git_dep · CWE-829, CWE-1357
pyproject.toml:15
# (`uvx --from git+https://...`) re-resolves every one of them from PyPI on each
MEDIUMSupply chain · supply.git_dep · CWE-829, CWE-1357
pyproject.toml:36
# `FastMCP` from it. The documented install path (`uvx --from git+https://...`)
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coveragerc
.coveragerc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coveragerc-gate
.coveragerc-gate
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coveragerc-subprocess
.coveragerc-subprocess
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_min_selected_guard.py:313
exec(  # noqa: S102
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
.github/workflows/claude-code-review.yml:415
# classic exfiltration vector and is exactly what the paragraph above says GitHub
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
.system_design/TEST_SUITE.md:2629
| **Externally supplied** — `get_content`'s `url`, and the links `web_search` fans out to | **Public addresses only.** Loopback, RFC1918, link-local, IPv6 unique-local, cloud metadata (`169.254.169.25
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
.system_design/TEST_SUITE_IMPLEMENTATION_PLAN.md:1731
IPv6 ULA, `169.254.169.254`, IPv4-mapped IPv6), plus **mixed public/private
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/review/tests/test_review_scripts.py:2625
'{"version": 1, "egress": {"proxy_url": "http://10.0.0.1:8080", '
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/review/tests/test_review_scripts.py:2945
'{"version": 1, "egress": {"proxy_url": "http://10.0.0.1:8080", '
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/review/tests/test_review_scripts.py:3034
'{"proxy_url": "http://10.0.0.1:8080", '
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/review/tests/test_review_scripts.py:3060
'{"proxy_url": "http://10.0.0.1:8080"}}',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/review/tests/test_review_scripts.py:3113
'{"proxy_url": "http://10.0.0.1:8080", "auth_ref": null}',
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
.github/review/tests/test_review_scripts.py:3342
("a BOM", "" + self.PROFILES, "offset 0"),
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/review/scripts/ci_preflight.sh:174
if command -v sudo >/dev/null 2>&1 && sudo -n true 2>/dev/null; then
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/review/scripts/ci_preflight.sh:175
sudo apt-get update -qq && sudo apt-get install -y -qq "$package" && return 0
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/review/scripts/ci_preflight.sh:176
CI_PREFLIGHT_INSTALL_REASON="passwordless \`sudo\` works here and \`apt-get\` still \
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/review/scripts/ci_preflight.sh:180
CI_PREFLIGHT_INSTALL_REASON="this job is not root and has no passwordless sudo, so it \
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/review/scripts/ci_preflight.sh:349
printf '#!/bin/sh\n[ "$1" = "-n" ] && exit 0\nexec "$@"\n' > "$bin/sudo"
Why it matters. asks for elevated privileges
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.github/review/rules/python-tests.md:45
directly and pins every ambient input they read — the environment variables,
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.github/review/rules/search-providers.md:59
1. Read **its own** environment variable, the one named in its
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:113
All `httpx`-based handlers read standard proxy environment variables (`HTTP_PROXY`, `HTTPS_PROXY`, `ALL_PROXY`) and support both HTTP and SOCKS proxy URLs via the `socksio` dependency. The universal H
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:145
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha eddc01a6b402full audit observations/trust-audit/mcp-server/shelpuk-ai-technology-consulting__kindly-web-search.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02eddc01a6b402CAUTIONB81first audit
06

Questions

What is the Kindly Web Search MCP server?

Kindly Web Search MCP Server: Web search + robust content retrieval for AI coding tools (Claude Code, Codex, Cursor, GitHub Copilot, Gemini, etc.) and AI agents (Claude Desktop, OpenClaw, Hermes, etc.). Supports Serper, Tavily, and SearXNG.

What tools does Kindly Web Search expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kindly Web Search safe to connect to an agent?

With care. The audit graded it B (81/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Kindly Web Search need?

It reads APIFARE_TOKEN, GITHUB_TOKEN, KINDLY_CHROME_PROXY_BYPASS, SERPBASE_API_KEY, SERPER_API_KEY, SERPLY_API_KEY, SOFYA_API_KEY, STACKEXCHANGE_KEY, TAVILY_API_KEY and YDC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kindly Web Search run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as kindly-web-search-mcp-server.

How current is this page?

The grade is for one exact copy of the source (eddc01a6b402), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement