Web SearchCAUTION
一个简单的本地 web search mcp ,可以集群规模化进行对外提供服务。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
High-performance web search service for LLM clients via Model Context Protocol. Powered by Camoufox stealth browser.
English | 中文
Features
- 3 Search Engines — Google, Bing, DuckDuckGo with automatic fallback
- Multi-depth Scraping — SERP parsing → full-text extraction → outbound link crawling
- Stealth Browser — Camoufox anti-detection Firefox (GeoIP, Humanize, Locale)
- Auto-scaling Pool — Browser pool auto-scales at 80% utilization, configurable upper limit
- Admin Dashboard — Search analytics, system monitoring, API key management, IP banning
- API Key Auth — Built-in key generation (
wsm_prefix) with call limits and revocation - Dual Output — JSON and Markdown formats
- REST API — Standard HTTP API alongside MCP protocol
Quick Start
Docker (Recommended)
git clone https://github.com/nicepkg/web-search-mcp.git cd web-search-mcp # Configure cp .env.example .env # Edit .env — set ADMIN_TOKEN # Launch docker compose up -d # Verify curl http://127.0.0.1:8897/health
Create API Key & Register to Claude Code
# 1. Create an API key via Admin API
curl -X POST http://127.0.0.1:8897/admin/api/keys \
-H "Authorization: Bearer $ADMIN_TOKEN" \
-H "Content-Type: application/json" \
-d '{"name": "claude-code", "call_limit": 10000}'
# Save the returned wsm_xxx key (only shown once)
# 2. Register MCP to Claude Code
claude mcp add-json -s user web-search-fast '{
"type": "http",
"url": "http://127.0.0.1:8897/mcp",
"headers": {"Authorization": "Bearer wsm_your-api-key-here"}
}'
# 3. Restart Claude Code sessionOr use the Admin Dashboard at http://127.0.0.1:8897/admin to create keys visually.
MCP Tools
2686040c0075OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add admin-ui --env ADMIN_TOKEN=${ADMIN_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"admin-ui": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ADMIN_TOKEN": "${ADMIN_TOKEN}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
list_search_engines | read | List available search engines. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
async with httpx.AsyncClient(proxy=proxy_url, timeout=timeout, verify=False) as client:
# MCP 端点: http://127.0.0.1:8897/mcp
# Admin 面板: http://127.0.0.1:8897/admin
# 健康检查: http://127.0.0.1:8897/health
- 端点: `http://127.0.0.1:8897/mcp`
curl http://127.0.0.1:8897/health
assert base64.b64decode(content.data) == data
@tailwindcss/vite, @tanstack/react-table, class-variance-authority, clsx, lucide-react, react, react-dom, react-router-dom
img/img_2.png
Gates applied: no_behavioural_pass.
2686040c0075full audit observations/trust-audit/mcp-server/uk0__web-search-18.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 2686040c0075 | CAUTION | B | 89 | first audit |
Questions
What is the Web Search MCP server?
一个简单的本地 web search mcp ,可以集群规模化进行对外提供服务。
What tools does Web Search expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Web Search safe to connect to an agent?
With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Web Search need?
It reads ADMIN_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Web Search run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as admin-ui at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (2686040c0075), read on 2026-10-07. The repository is watched and re-audited when it changes.