MyWebSearch (wtznicy/my-websearch) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 2 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.
Name: MyWebSearch Type: MCP Server (stdio + streamable-http/SSE) Repository: https://github.com/wtznicy/my-websearch npm: my-websearch (npx -y my-websearch@latest) Description: Multi-engine web search MCP server, CLI and local daemon — no API keys or registration required. Searches bing/baidu/csdn/juejin/sogou (domestic, no proxy needed in mainland China) and duckduckgo/exa/brave/startpage (overse
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Monitored 0 days · every push re-verified
Who stands behind it
gmail.com (@wtznicy) · Verified Publisher
Source: Glama · also listed on modelscope
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
ALLOWED_SEARCH_ENGINESempty (all available) Comma-separated engine names Limit which search engines can be used; if the default engine is not in this list, the first allowed engine becomes the defaultBING_PLAYWRIGHT_FALLBACKCONTEXT7_API_KEYNote: Both Context7 tools call the public REST API directly (no API key required at low rate limits). Set for higher rate limits.CORS_ORIGINAny valid origin CORS origin configurationDEFAULT_SEARCH_ENGINEbing ENABLE_CORS=true npx my-websearch@latestENABLE_CORSDEFAULT_SEARCH_ENGINE=bing =true npx my-websearch@latestEXA_API_KEYempty Any valid Exa API key 可选(仅 exa 引擎需要)。exa 的免 key 网页端点已失效,想用 exa 引擎时在 [https://dashboard.exa.ai/api-keys](https://dashboard.exa.ai/api-keys) 免费申请并配置到 MCP 客户端 env;不配置只影响 exa 一个引擎,其余引擎不受影响FAKE_IP_CIDRSFor Clash fake-ip / TUN setups, configure synthetic DNS ranges with (for example 198.18.0.0/15)FETCH_WEB_INSECURE_TLSfalse true, false Disable TLS certificate verification for fetchWebContent only. Use only when a target site has a broken certificate chainGITHUB_README_CDN_FIRSTLOG_LEVELnormal normal, quiet quiet 抑制启动配置日志(MCP stdio 裸启动默认已静默;诊断时可用 LOG_LEVEL=normal 恢复)MODEset =stdio && set DEFAULT_SEARCH_ENGINE=bing && npx my-websearch@latestOPEN_WEBSEARCH_ALLOWED_HOSTSOPEN_WEBSEARCH_BING_HOSTOPEN_WEBSEARCH_DAEMON_ACTION_TIMEOUT_MSOPEN_WEBSEARCH_DAEMON_DISCOVERY_TIMEOUT_MSOPEN_WEBSEARCH_DAEMON_HOSTOPEN_WEBSEARCH_DAEMON_PORTOPEN_WEBSEARCH_DAEMON_TIMEOUT_MSOPEN_WEBSEARCH_DAEMON_URLOPEN_WEBSEARCH_DEBUGOPEN_WEBSEARCH_HOSTOPEN_WEBSEARCH_QUIET_STARTUPfalse true, false 抑制启动配置日志(兼容开关,LOG_LEVEL=quiet 与之等价)PLAYWRIGHT_HEADLESStrue true, false Whether Playwright Chromium runs in headless modePLAYWRIGHT_NAVIGATION_TIMEOUT_MS20000 Positive integer Timeout for Playwright navigation and Bing result waitsPLAYWRIGHT_PACKAGEauto auto, playwright, playwright-core Which Playwright client package to resolve when browser mode is enabledPROGRAMFILESPROGRAMFILES(X86)PROXY_ENGINESUse to keep domestic engines on a fast direct connection while routing only the overseas engines through the proxy (avoiding the redirects/timeouts that a global proxy causes for Chinese engines):PROXY_URLUSE_PROXY=true =http://127.0.0.1:7890 my-websearch serveSEARCH_MODEauto request, auto, playwright Search strategy. Currently only affects Bing: request only, request then Playwright fallback, or force PlaywrightSTARTPAGE_PLAYWRIGHT_FALLBACKUSE_PROXYtrue PROXY_URL=http://127.0.0.1:7890 my-websearch servePORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
2/2 tools missing one or more hints — resolveLibraryId (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); queryDocs (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 0/2 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
10 child_process/subprocess calls in production code — runs shell commands (src/cli/runCli.ts:858, src/utils/playwrightClient.ts:1034, src/utils/playwrightClient.ts:1047)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 16 high severity in production deps — @modelcontextprotocol/sdk@1.11.2 (high), @modelcontextprotocol/sdk@1.11.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
[](https://m8ven.ai/mcp/wtznicy-my-websearch-1nmaw4)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check