MySearchSAFE
Unified search MCP, proxy console, and skill for Tavily, Firecrawl, and Social / X.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English Guide
MySearch Proxy 是一套给 AI 助手准备的统一搜索栈。
它把原本分散的 4 件事收成了同一个仓库:
mysearch/- 真正可安装的 MySearch MCP
skill/- 给 Codex / Claude Code 的 skill 与安装说明
openclaw/- 给 OpenClaw / ClawHub 的独立 skill bundle
proxy/- 给团队或公开部署使用的控制台与代理层
支持的搜索能力:
- Tavily
- Firecrawl
- Exa
- 可选 X / Social
目标很简单:
- 让本地 AI 助手先用起来
- 让 OpenClaw 直接装上去
- 让团队共享一套统一搜索后端
- 让调用方尽量少关心底层 provider 差异
项目入口:
- GitHub:
- Docker Hub:
- ClawHub:
为什么做这个项目
很多搜索类项目只解决其中一小段:
- 只给一个
web_search - 只会搜,不会抓正文
- 只会调官方 API,不方便接自建网关
- 只给 prompt,不给真正能安装的运行时
- 只做 key 面板,不解决 AI 如何调用
MySearch Proxy 选择直接把整条链补齐:
上游 provider / 聚合网关 -> Tavily / Firecrawl / Exa / X / Social MySearch Proxy -> 控制台、Token、额度同步、兼容代理接口 MySearch MCP / Codex Skill / OpenClaw Skill -> 给 Codex、Claude Code、OpenClaw、其他 Agent 直接使用
推荐架构
当前最推荐的是 proxy-first:
上游 provider -> MySearch Proxy -> 生成 MySearch 通用 token -> MySearch MCP / OpenClaw skill / 其他 Agent
这条路的好处很直接:
- 客户端只需要一组
MYSEARCH_PROXY_* - Tavily / Firecrawl / Exa 不再散落到每台机器
- 可以统一管理 token、调用统计和额度同步
- OpenClaw、本地 Codex、团队代理都能复用同一套配置
如果你暂时还没有 Proxy,也可以让 mysearch/ 或 openclaw/ 直接连官方 provider。
最新优化(v0.1.11)
这次版本重点是把 provider 健康状态从“只看有没有 key”升级成“能看出 key 是不是活着”,并把 docs / resource 路由对失效 provider 的自保补齐;上一版 config-first、Python 3.10 兼容和 Firecrawl 域名过滤回退继续保留。
- 配置入口收口:
MySearchruntime 现在会优先读取~/.codex/config.toml的mcp_servers.mysearch.env。install.sh会先继承宿主已注册的MYSEARCH_*,再用mysearch/.env只补缺省值。- OpenClaw wrapper 现在会优先读取
openclaw.json的skills.entries.mysearch.env。 .env继续支持,但明确只保留给本地单仓调试兜底,不再是推荐主路径。- 读取宿主 config 时不再强依赖 Python 3.11 的
tomllib,对 Pyt
81026da907c6OBSERVED · 2026-10-07Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
extract_url | read | 抓取单个 URL 的正文,默认优先 Firecrawl;失败或空正文时回退 Tavily extract。 |
mysearch_health | read | 查看 MySearch 当前 provider 配置、search mode、auth 模式、base URL 和 key 可用性。 |
research | read | 小型研究工作流:网页发现 + 正文抓取 + 可选 X 舆情补充。 |
search | read | 统一搜索入口。按任务类型自动选择 Tavily / Firecrawl / Exa / xAI。 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
# MYSEARCH_XAI_SOCIAL_BASE_URL=http://127.0.0.1:9875
http://127.0.0.1:8000/mcp
codex mcp add mysearch --url http://127.0.0.1:8000/mcp
- `http://127.0.0.1:8000/mcp`
- `http://127.0.0.1:8000/sse`
fastapi, uvicorn, httpx
fastapi, uvicorn, httpx, jinja2
If the user explicitly says "install from Hub", prefer the ClawHub route.
Gates applied: no_behavioural_pass, no_license.
81026da907c6full audit observations/trust-audit/mcp-server/skernelx__mysearch.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 81026da907c6 | SAFE | B | 89 | first audit |
Questions
What is the MySearch MCP server?
Unified search MCP, proxy console, and skill for Tavily, Firecrawl, and Social / X.
What tools does MySearch expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MySearch safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does MySearch need?
It reads ADMIN_PASSWORD, MYSEARCH_PROXY_API_KEY, SOCIAL_GATEWAY_ADMIN_APP_KEY, SOCIAL_GATEWAY_ADMIN_TOKENS_PATH, SOCIAL_GATEWAY_TOKEN and SOCIAL_GATEWAY_UPSTREAM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MySearch run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (81026da907c6), read on 2026-10-07. The repository is watched and re-audited when it changes.