ZeroCrawl MCP (AgentNex/zerocrawl-mcp) is an MCP server listed on the M8ven Trust Index. It scores 72 out of 100, grade C. It declares 7 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.
ZeroCrawl MCP is a 100% free web crawling and scraping server for AI agents, offering tools like page scraping, domain crawling, metadata extraction, screenshots, sitemap parsing, batch scraping, and search-and-crawl. It requires no API keys and integrates with Claude Desktop, Cursor, and other MCP clients.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
every push re-verified
Who stands behind it
outlook.com (@AgentNex) · Verified Publisher
Source: Glama · also listed on Publisher
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
scrape_pageFetch URL and convert to clean Markdown. Fallbacks to Jina reader if initial fetch fails.
crawl_domainRecursively crawl same-domain internal links up to maxDepth or maxPages.
extract_metadataParse title, meta descriptions, OpenGraph tags, canonical links, and JSON-LD structured data.
search_crawlFetch web search results, isolate top target links, and concurrently scrape each target link.
parse_sitemapDiscover and parse sitemap.xml or sitemap_index.xml for a given domain.
take_screenshotReturn high-res screenshot URL via Microlink and extract all embedded page image links.
batch_scrapeAccept an array of up to 5 URLs, executing page processing concurrently.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
Production dependencies are patched
2 critical, 0 high severity in production deps — next@16.3.1 (critical), next@16.3.1 (critical)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
[](https://m8ven.ai/mcp/agentnex/zerocrawl-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check