Atlas / MCP servers / yokingma / OneSearch

OneSearchSAFE

mcp/yokingma/onesearch

🚀 OneSearch MCP Server: Web Search & Scraper & Extract, Support agent-browser, SearXNG, Tavily, DuckDuckGo, Bing, etc.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 4r · 0w · 0d
Transport
stdio
License
MIT
Stars
144
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server implementation that integrates with multiple search providers for web search, local browser search, URL discovery, and scraping capabilities with agent-browser.

Features

  • Web search, scrape, discover URLs, and preprocess content from websites.
  • Support multiple search engines and web scrapers: SearXNG, Tavily, DuckDuckGo, Bing, Google, Zhipu (智谱), Exa, Bocha (博查), You.com, etc.
  • Local web search (browser search), support multiple search engines: Bing, Google, Baidu, Sogou, etc.
  • Use agent-browser for browser automation.
  • Free, no API keys required.
  • Enabled tools: one_search, one_scrape, one_map, one_extract

Current Tool Surface

  • one_search
  • Returns search results from the configured provider.
  • one_map
  • Discovers links from a starting URL by loading the page in the browser and extracting links from its HTML.
  • Supported input fields: url, search, includeSubdomains, limit.
  • This is not a sitemap crawler; removed fields such as ignoreSitemap and sitemapOnly are rejected at the schema boundary.
  • one_scrape
  • Scrapes one page and returns content selected by formats.
  • Supported input fields: url, formats, waitFor, timeout, skipTlsVerification, allowExecuteJavascript, actions.
  • Supported formats: markdown, html, rawHtml, links, screenshot, screenshot@fullPage.
  • Supported bounded pre-scrape actions: wait, click, write, press, scroll.
  • Advanced pre-scrape action: executeJavascript. If actions contains executeJavascript, you must set allowExecuteJavascript: true.
  • actions run serially before content capture and fail fast on the first action error.
  • Removed fields such as onlyMainContent, extract, and location are rejected at the schema boundary.
  • one_extract
  • Acce
Read from source at commit fa5cb44b6f2bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add one-search-mcp --env SEARCH_API_KEY=${SEARCH_API_KEY} --env YDC_API_KEY=${YDC_API_KEY} -- npx -y [email protected]
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
one_extractreadFetch and preprocess page content from one or more URLs. Returns cleaned text blocks that can be passed to downstream tools or models.
one_mapreadDiscover URLs from a starting point by loading a page in the browser and extracting links from its HTML.
one_scrapereadScrape a single webpage and return markdown, HTML, links, or a screenshot. Supports navigation timeout, TLS verification control, full-page screenshots, bounded pre-scrape actions, and advanced executeJavascript only when allowExecuteJavascript is true.
one_searchreadSearch and retrieve content from web pages. Returns SERP results by default (url, title, description).
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/url-guard.test.ts:76
const redirectLookup = createLookup([{ address: '169.254.169.254', family: 4 }]);
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/url-guard.test.ts:86
const route = createRoute('http://169.254.169.254/latest/meta-data/');
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/url-guard.test.ts:100
const lookup = createLookup([{ address: '169.254.169.254', family: 4 }]);
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/url-guard.test.ts:122
await installUrlProtection(page, createLookup([{ address: '169.254.169.254', family: 4 }]));
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
test/url-guard.test.ts:124
const route = createRoute('http://169.254.169.254/latest/meta-data/');
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:89
claude mcp add one-search-mcp -e SEARCH_PROVIDER=searxng -e SEARCH_API_URL=http://127.0.0.1:8080 -- npx -y one-search-mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:282
After deployment, SearXNG will be available at `http://127.0.0.1:8080` by default.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:289
export SEARCH_API_URL=http://127.0.0.1:8080
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/agent-browser.test.ts:127
const result = await browser.scrapeUrl('https://93.184.216.34', {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/agent-browser.test.ts:138
'https://93.184.216.34',
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@dotenvx/dotenvx, @modelcontextprotocol/sdk, @tavily/core, agent-browser, async-retry, cheerio, duck-duck-scrape, exa-js
Why it matters. 29 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fa5cb44b6f2bfull audit observations/trust-audit/mcp-server/yokingma__onesearch.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fa5cb44b6f2bSAFEB89first audit
06

Questions

What is the OneSearch MCP server?

🚀 OneSearch MCP Server: Web Search & Scraper & Extract, Support agent-browser, SearXNG, Tavily, DuckDuckGo, Bing, etc.

What tools does OneSearch expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is OneSearch safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does OneSearch need?

It reads SEARCH_API_KEY and YDC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OneSearch run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as one-search-mcp at 1.2.4.

How current is this page?

The grade is for one exact copy of the source (fa5cb44b6f2b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement