web-mcp (Chang-Tong/web-mcp) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: there is no public source to read and no endpoint we can reach, so there is nothing for us to inspect. No publisher has claimed this listing.
MCP server for multi-engine web search and web page fetching, supporting parallel search, content extraction, and optional LLM-powered search summarization and deep search.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
Chang-Tong
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
DEEPSEEK_API_KEY一步完成:搜索 → 并行抓 top 结果正文 → DeepSeek 生成带 [1][2] 引用标注的结构化中文摘要(总述 + 要点 + 关键事实)。查资料写报告场景省去多次 search+fetch 往返。无 时退化为返回搜索+抓取结果。DEEPSEEK_BASE_URLDEEPSEEK_MODELdeepseek-chat LLM 模型名SEARCH_ENGINEauto auto / 单引擎名(baidu/brave/bing/csdn/duckduckgo/github/arxiv)/ serper / tavily / searxngSEARXNG_URL自托管 SearXNG 实例地址(可选引擎,需开启 JSON 格式)SERPER_API_KEYSerper 的 Google 搜索 key(免费 2500 次/月),最稳定,推荐配置SERPER_GL/ SERPER_HL cn / zh-cn Serper 搜索地区/语言SERPER_HLSERPER_GL / cn / zh-cn Serper 搜索地区/语言SITE_BLOCKLIST站点权重重排:内置权重表(github.com ×1.6、官方文档站加权;百家号 ×0.55、内容农场降权),黑名单域名直接剔除。可用 SITE_WEIGHTS(JSON)/ (逗号分隔)覆盖。SITE_WEIGHTS站点权重重排:内置权重表(github.com ×1.6、官方文档站加权;百家号 ×0.55、内容农场降权),黑名单域名直接剔除。可用 (JSON)/ SITE_BLOCKLIST(逗号分隔)覆盖。SITE_WEIGHTS_MERGESITE_WEIGHTS 内置表 JSON 格式域名→权重,如 {"github.com": 1.5};=1 时与内置合并TAVILY_API_KEYTavily key(可选引擎)WEB_MCP_AUTH_TOKENyour-secret node src/index.mjs --http 8787WEB_MCP_BROWSER_NO_PROXYWEB_MCP_BROWSER_PATH自动探测 指定浏览器可执行文件路径(系统 Chrome/Edge、playwright 缓存自动探测)WEB_MCP_DEBUG设为 1 输出每个引擎的执行日志(stderr)WEB_MCP_ENABLE_BROWSER自动 0 禁用浏览器兜底;1 强制启用http_proxy代理自动生效: / https_proxy / no_proxy(undici EnvHttpProxyAgent),无代理环境自动直连,无需额外配置。https_proxy代理自动生效:http_proxy / / no_proxy(undici EnvHttpProxyAgent),无代理环境自动直连,无需额外配置。Dependencies
7 dependencies, 1 flagged: playwright-core
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
4/4 tools missing one or more hints — web_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); fetch_page (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_summarize (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +1 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool handlers catch errors
Only 0/4 tool handlers wrap calls in try/catch (0%)
Wrap each tool handler body in try/catch and return a structured error response.
Tests exist
No test files found
Add tests that exercise each declared tool.
Shell command execution
1 child_process call — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/chang-tong-web-mcp-jkxefo)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check