Kindly Web SearchCAUTION
Kindly Web Search MCP Server: Web search + robust content retrieval for AI coding tools (Claude Code, Codex, Cursor, GitHub Copilot, Gemini, etc.) and AI agents (Claude Desktop, OpenClaw, Hermes, etc.). Supports Serper, Tavily, and SearXNG.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Web search + robust content retrieval for AI coding tools.
Kindly Web Search is a part of the [Shelpuk AI Technology Consulting](https://shelpuk.com) agentic suite – a set of tools that together improve the code quality produced by AI coding agents by 15–20%. Read more on Claude Code generation quality improvement.
Works with Claude Code, Codex, Antigravity, Cursor, Windsurf, and any agent that supports skills or MCP servers.
If you like what we're building, please ⭐ star this repo – it's a huge motivation for us to keep going!
How to use the suite
1. Install three MCP servers and one skill:
2. Use the skill when requesting a feature:
Prompt your favorite AI coding agent (Claude Code, Codex, Cursor, etc.)
eddc01a6b402OBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add kindly-web-search-mcp-server --env APIFARE_TOKEN=${APIFARE_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env KINDLY_CHROME_PROXY_BYPASS=${KINDLY_CHROME_PROXY_BYPASS} --env SERPBASE_API_KEY=${SERPBASE_API_KEY} -- uvx kindly-web-search-mcp-server{
"mcpServers": {
"kindly-web-search-mcp-server": {
"command": "uvx",
"args": [
"kindly-web-search-mcp-server"
],
"env": {
"APIFARE_TOKEN": "${APIFARE_TOKEN}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}",
"KINDLY_CHROME_PROXY_BYPASS": "${KINDLY_CHROME_PROXY_BYPASS}",
"SERPBASE_API_KEY": "${SERPBASE_API_KEY}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_content | read | Fetch a single URL and return best-effort, LLM-ready Markdown for that page. |
web_search | read | Search the web and return top results with best-effort Markdown for each result URL. |
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (24)
# (`uvx --from git+https://...`) re-resolves every one of them from PyPI on each
# `FastMCP` from it. The documented install path (`uvx --from git+https://...`)
.coveragerc
.coveragerc-gate
.coveragerc-subprocess
exec( # noqa: S102
# classic exfiltration vector and is exactly what the paragraph above says GitHub
| **Externally supplied** — `get_content`'s `url`, and the links `web_search` fans out to | **Public addresses only.** Loopback, RFC1918, link-local, IPv6 unique-local, cloud metadata (`169.254.169.25
IPv6 ULA, `169.254.169.254`, IPv4-mapped IPv6), plus **mixed public/private
'{"version": 1, "egress": {"proxy_url": "http://10.0.0.1:8080", ''{"version": 1, "egress": {"proxy_url": "http://10.0.0.1:8080", ''{"proxy_url": "http://10.0.0.1:8080", ''{"proxy_url": "http://10.0.0.1:8080"}}','{"proxy_url": "http://10.0.0.1:8080", "auth_ref": null}',("a BOM", "" + self.PROFILES, "offset 0"),if command -v sudo >/dev/null 2>&1 && sudo -n true 2>/dev/null; then
sudo apt-get update -qq && sudo apt-get install -y -qq "$package" && return 0
CI_PREFLIGHT_INSTALL_REASON="passwordless \`sudo\` works here and \`apt-get\` still \
CI_PREFLIGHT_INSTALL_REASON="this job is not root and has no passwordless sudo, so it \
printf '#!/bin/sh\n[ "$1" = "-n" ] && exit 0\nexec "$@"\n' > "$bin/sudo"
directly and pins every ambient input they read — the environment variables,
1. Read **its own** environment variable, the one named in its
All `httpx`-based handlers read standard proxy environment variables (`HTTP_PROXY`, `HTTPS_PROXY`, `ALL_PROXY`) and support both HTTP and SOCKS proxy URLs via the `socksio` dependency. The universal H
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
eddc01a6b402full audit observations/trust-audit/mcp-server/shelpuk-ai-technology-consulting__kindly-web-search.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | eddc01a6b402 | CAUTION | B | 81 | first audit |
Questions
What is the Kindly Web Search MCP server?
Kindly Web Search MCP Server: Web search + robust content retrieval for AI coding tools (Claude Code, Codex, Cursor, GitHub Copilot, Gemini, etc.) and AI agents (Claude Desktop, OpenClaw, Hermes, etc.). Supports Serper, Tavily, and SearXNG.
What tools does Kindly Web Search expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Kindly Web Search safe to connect to an agent?
With care. The audit graded it B (81/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Kindly Web Search need?
It reads APIFARE_TOKEN, GITHUB_TOKEN, KINDLY_CHROME_PROXY_BYPASS, SERPBASE_API_KEY, SERPER_API_KEY, SERPLY_API_KEY, SOFYA_API_KEY, STACKEXCHANGE_KEY, TAVILY_API_KEY and YDC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Kindly Web Search run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as kindly-web-search-mcp-server.
How current is this page?
The grade is for one exact copy of the source (eddc01a6b402), read on 2026-10-02. The repository is watched and re-audited when it changes.