Atlas / MCP servers / skernelx / MySearch

MySearchSAFE

mcp/skernelx/mysearch

Unified search MCP, proxy console, and skill for Tavily, Firecrawl, and Social / X.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 4r · 0w · 0d
Transport
streamable-http
License
—
Stars
159
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English Guide

MySearch Proxy 是一套给 AI 助手准备的统一搜索栈。

它把原本分散的 4 件事收成了同一个仓库:

  • mysearch/
  • 真正可安装的 MySearch MCP
  • skill/
  • 给 Codex / Claude Code 的 skill 与安装说明
  • openclaw/
  • 给 OpenClaw / ClawHub 的独立 skill bundle
  • proxy/
  • 给团队或公开部署使用的控制台与代理层

支持的搜索能力:

  • Tavily
  • Firecrawl
  • Exa
  • 可选 X / Social

目标很简单:

  • 让本地 AI 助手先用起来
  • 让 OpenClaw 直接装上去
  • 让团队共享一套统一搜索后端
  • 让调用方尽量少关心底层 provider 差异

项目入口:

  • GitHub:

skernelx/MySearch-Proxy

  • Docker Hub:

skernelx/mysearch-proxy

  • ClawHub:

clawhub.ai/skernelx/mysearch

为什么做这个项目

很多搜索类项目只解决其中一小段:

  • 只给一个 web_search
  • 只会搜,不会抓正文
  • 只会调官方 API,不方便接自建网关
  • 只给 prompt,不给真正能安装的运行时
  • 只做 key 面板,不解决 AI 如何调用

MySearch Proxy 选择直接把整条链补齐:

上游 provider / 聚合网关
-> Tavily / Firecrawl / Exa / X / Social

MySearch Proxy
-> 控制台、Token、额度同步、兼容代理接口

MySearch MCP / Codex Skill / OpenClaw Skill
-> 给 Codex、Claude Code、OpenClaw、其他 Agent 直接使用

推荐架构

当前最推荐的是 proxy-first:

上游 provider
-> MySearch Proxy
-> 生成 MySearch 通用 token
-> MySearch MCP / OpenClaw skill / 其他 Agent

这条路的好处很直接:

  • 客户端只需要一组 MYSEARCH_PROXY_*
  • Tavily / Firecrawl / Exa 不再散落到每台机器
  • 可以统一管理 token、调用统计和额度同步
  • OpenClaw、本地 Codex、团队代理都能复用同一套配置

如果你暂时还没有 Proxy,也可以让 mysearch/ 或 openclaw/ 直接连官方 provider。

最新优化(v0.1.11)

这次版本重点是把 provider 健康状态从“只看有没有 key”升级成“能看出 key 是不是活着”,并把 docs / resource 路由对失效 provider 的自保补齐;上一版 config-first、Python 3.10 兼容和 Firecrawl 域名过滤回退继续保留。

  • 配置入口收口:
  • MySearch runtime 现在会优先读取 ~/.codex/config.toml 的 mcp_servers.mysearch.env。
  • install.sh 会先继承宿主已注册的 MYSEARCH_*,再用 mysearch/.env 只补缺省值。
  • OpenClaw wrapper 现在会优先读取 openclaw.json 的 skills.entries.mysearch.env。
  • .env 继续支持,但明确只保留给本地单仓调试兜底,不再是推荐主路径。
  • 读取宿主 config 时不再强依赖 Python 3.11 的 tomllib,对 Pyt
Read from source at commit 81026da907c6OBSERVED · 2026-10-07
02

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
extract_urlread抓取单个 URL 的正文,默认优先 Firecrawl;失败或空正文时回退 Tavily extract。
mysearch_healthread查看 MySearch 当前 provider 配置、search mode、auth 模式、base URL 和 key 可用性。
researchread小型研究工作流:网页发现 + 正文抓取 + 可选 X 舆情补充。
searchread统一搜索入口。按任务类型自动选择 Tavily / Firecrawl / Exa / xAI。
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mysearch/.env.example:78
# MYSEARCH_XAI_SOCIAL_BASE_URL=http://127.0.0.1:9875
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_EN.md:359
http://127.0.0.1:8000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_EN.md:375
codex mcp add mysearch --url http://127.0.0.1:8000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mysearch/README.md:180
- `http://127.0.0.1:8000/mcp`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
mysearch/README.md:182
- `http://127.0.0.1:8000/sse`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mysearch/requirements.txt
fastapi, uvicorn, httpx
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
proxy/requirements.txt
fastapi, uvicorn, httpx, jinja2
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
INFOPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
openclaw/README_EN.md:54
If the user explicitly says "install from Hub", prefer the ClawHub route.

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 81026da907c6full audit observations/trust-audit/mcp-server/skernelx__mysearch.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0781026da907c6SAFEB89first audit
05

Questions

What is the MySearch MCP server?

Unified search MCP, proxy console, and skill for Tavily, Firecrawl, and Social / X.

What tools does MySearch expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is MySearch safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does MySearch need?

It reads ADMIN_PASSWORD, MYSEARCH_PROXY_API_KEY, SOCIAL_GATEWAY_ADMIN_APP_KEY, SOCIAL_GATEWAY_ADMIN_TOKENS_PATH, SOCIAL_GATEWAY_TOKEN and SOCIAL_GATEWAY_UPSTREAM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MySearch run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (81026da907c6), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement