io.github.HarimxChoi/google-surf-mcp
NPM · GOOGLE-SURF-MCP · SCANNED SEP 20
Web, academic and code search with graph RAG, data lineage, ontology and cross-project schema links.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 76 of 222 dependencies flagged as unhealthy (3 deprecated). View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 9 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability55
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 5358 tokens (~765/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management83
- Stability observed for 25 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage94
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 77% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.HarimxChoi/google-surf-mcp server?
io.github.HarimxChoi/google-surf-mcp runs locally as an npm package, launched with npx -y google-surf-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · google-surf-mcp
claude mcp add harimxchoi-google-surf-mcp -- npx -y google-surf-mcp
{
"mcpServers": {
"harimxchoi-google-surf-mcp": {
"command": "npx",
"args": [
"-y",
"google-surf-mcp"
]
}
}
} {
"servers": {
"harimxchoi-google-surf-mcp": {
"command": "npx",
"args": [
"-y",
"google-surf-mcp"
]
}
}
} codex mcp add harimxchoi-google-surf-mcp -- npx -y google-surf-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"harimxchoi-google-surf-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"google-surf-mcp"
],
"enabled": true
}
}
} openclaw mcp add harimxchoi-google-surf-mcp --command npx --arg -y --arg google-surf-mcp
mcp_servers:
harimxchoi-google-surf-mcp:
command: "npx"
args: ["-y", "google-surf-mcp"] {
"McpServers": {
"harimxchoi-google-surf-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"google-surf-mcp"
]
}
}
} assistant mcp add harimxchoi-google-surf-mcp -t stdio -c npx -a -y google-surf-mcp
{
"mcpServers": {
"harimxchoi-google-surf-mcp": {
"command": "npx",
"args": [
"-y",
"google-surf-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 18 Sept 26 0
- Stability: fail → 0.77 functional
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70.
- 12 Sept 26 +16
- CVE-2026-76845 no longer affects this package ▲ security
- Malware scan: unverified → pass ▲ security
- Known CVEs: partial → pass ▲ security
- 11 Sept 26 −3
No change was recorded against any check on this day. Stability & Change Management went from 80 to 60.
- 10 Sept 26 −11
- CVE-2026-76845 affects this package ▼ security
- Known CVEs: fail → unverified ▼ security
- Malware scan: pass → unverified ▼ security
- GHSA-rgj7-g3m4-5g8c no longer affects this package ▲ security
- Known CVEs: fail → partial ▲ security
- Schema quality: 597 → 765 ▼ functional
- Tool coverage: 100% → 77% ▼ functional
- Schema quality: 597 → 755 ▼ functional
- Schema quality: 597 → 718 ▼ functional
- Tool coverage: 100% → 76% ▼ functional
- Dependency health: 0.86 → unverified ▼ functional
- Package version: 1.0.9 → 1.1.3 functional
- Package version: 0.7.0 → 1.1.2 functional
- Package version: 0.7.0 → 1.1.1 functional
- Package version: 1.0.9 → 1.0.10 functional
- 9 Sept 26 −4
- GHSA-rgj7-g3m4-5g8c affects this package: high ▼ security
- Known CVEs: pass → fail ▼ security
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/google-surf-mcp@1.1.3
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 222 packages
| Packages resolved | 222 |
|---|---|
| Deprecated | 3 |
| Stale | 74 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
extract Known URL Extract ~639
SECONDARY KNOWN-URL CONTENT EXTRACTION TOOL. Use only when the exact public URL is already known and no new web discovery is required. If sources still need to be found, use search or search_parallel with extract_mode instead. For semantic reading of a public PDF or GitHub repository, use this tool before local download or parsing. Local PDF tools are for local files, forms, OCR recovery, or visual layout inspection; general repository tools are for editing, building, testing, or full Git history. Fetch one public URL and return clean content. With research enabled, one local broker lets multiple MCP sessions query the same knowledge base concurrently and orders writes safely. For GitHub repository URLs, metadata reads the README; abstract and full use the same bounded download gate and differ only in indexed source depth. HTML via Mozilla Readability; academic PDFs (arxiv/biorxiv/Nature/OpenReview/NeurIPS/JMLR/PMLR/Springer/PubMed-via-PMC) auto-detected via Content-Type, %PDF magic, citation_pdf_url meta, and per-domain URL rules. Tiered depth: `mode="metadata"` returns document metadata without body text, `mode="abstract"` returns about 1500 chars for relevance checks, and `mode="full"` reads the full bounded source. response_content controls whether the response contains a 1500-character summary or up to 50000 characters. PDF and landing-page metadata are merged when available. With research enabled, abstract and full PDF reads are stored as searchable evidence with bibliographic metadata and provenance. Best-effort: failures return an errorInfo instead of throwing.
| Name | Type | Req | Description |
|---|---|---|---|
| max_chars | integer | – | Maximum returned characters when response_content=full. Defaults to 1500 for abstract and 50000 for full. |
| memory_handle | string | – | Reuse the handle returned by a prior project-aware call. |
| mode | string | – | Extraction depth. `full` = whole article body (default; uses Playwright if needed). `abstract` = cheap survey: PDF page 1 OR HTML meta description (~1500 chars); use to triage relevance before paying… |
| project_id | string | – | Project memory id. |
| response_content | string | – | Controls only the returned body. full returns up to max_chars; summary returns a 1500-character evidence excerpt. Research storage keeps the full captured text in deterministic chunks. |
| session_id | string | – | Stable host task id. Reuses the same project session after restart. |
| session_intent | string | – | Current durable task intent. A changed value creates an immutable revision. |
| url | string | yes | Public http(s) URL. Loopback/private IPs blocked unless SURF_ALLOW_PRIVATE=true. |
| Name | Type | Req | Description |
|---|---|---|---|
| authors | string | – | – |
| canonical_url | string | – | – |
| content | string | – | – |
| created_at | string | – | – |
| creator | string | – | – |
| description | string | – | – |
| doi | string | – | – |
| elapsed_ms | number | – | – |
| error | – | – | – |
| excerpt | string | – | – |
| extraction_quality | string | – | – |
| is_pdf | boolean | – | – |
| keywords | array | – | – |
| language | string | – | – |
| length | number | – | – |
| memory | string | – | – |
| memory_handle | string | – | – |
| meta | object | – | – |
| modified_at | string | – | – |
| page_count | number | – | – |
| producer | string | – | – |
| publication | string | – | – |
| published_at | string | – | – |
| source_length | number | – | – |
| subject | string | – | – |
| title | string | – | – |
| truncated | boolean | – | – |
| url | string | – | – |
| year | integer | – | – |
No examples provided.
health MCP Health Check ~56
MCP server status: cascade mode + transitions, rate-limiter usage, cache size, config. Call this if searches start failing or returning empty -- check cascade.totalCaptchas and rateLimiter.queueSize, and reduce search volume if they are high.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| cache | object | – | – |
| cascade | object | – | – |
| config | object | – | – |
| error | object | – | – |
| nativeBrowser | object | – | – |
| pool | object | – | – |
| rateLimiter | object | – | – |
| research | object | – | – |
| selfHealing | object | – | – |
| telemetry | object | – | – |
| version | string | – | – |
No examples provided.
project_memory Project Memory ~2,203
PROJECT MEMORY MANAGEMENT. With research enabled, one local broker lets multiple MCP sessions query the same knowledge base concurrently and orders writes safely. It links session intent, immutable plan revisions, experiments, decisions, versioned ontology, and bitemporal data lineage; corrections can use entity merge or split without discarding history. Use project_update for revision-checked changes to an existing project profile; context reads that same versioned profile. Use query_status/query_cancel with a caller-supplied search request_id to inspect or cooperatively stop a long retrieval. Use context for the bounded current project view; current to generate a compact CURRENT.md; get/get_batch for exact records and body spans; record/record_batch for durable idempotent writes; timeline/diff for history; sync for declared source deltas; job_status/job_wait/job_cancel for background progress and safe stage-boundary cancellation; verify for preservation levels; snapshot/snapshot_import/snapshot_rollback for versioned offline transfer and append-only recovery; doctor for passive diagnostics; rebuild for derived indexes; export for graph views; and forget for reversible deletion. Typed record writes return compact receipts and never echo submitted bodies. action=search remains a compatibility alias, but project_memory_search should be used for local knowledge retrieval. Ontology revisions use supersedes_term_id. Corrections preserve bitemporal data lineage and support assertion replacement plus entity merge or split. rebuild indexes approved local roots and code structure into a reproducible snapshot; export writes an interactive HTML viewer, Graphviz DOT, D3 JSON, or a Neo4j import bundle. HTML always includes PKM, Lineage, and Ontology tabs, an embedded-project selector, empty-canvas focus reset, and visible PNG or JSON download. forget previews impact before reversible project or assertion deletion. Search, search_parallel, scholar_search, and extract automatica…
| Name | Type | Req | Description |
|---|---|---|---|
| access_tier | string | – | Operational access tier. It does not rank scientific quality. |
| action | string | yes | Typed project-memory operation. create: project_id and name required. project_update: versioned profile update with expected_revision and idempotency_key. get/get_batch: exact IDs and bounded body sp… |
| after | string | – | – |
| after_revision | integer | – | – |
| aliases | array | – | Ontology term aliases, or aliases moved during entity_split. |
| all_projects | boolean | – | Search or export every active named project. Excludes Inbox and cannot be combined with project ids. |
| artifact_limit | integer | – | – |
| artifact_offset | integer | – | – |
| artifact_references | array | – | – |
| artifacts | array | – | Legacy experiment artifact paths. Typed writes should use artifact_references; no values are silently sliced. |
| as_of | string | – | For context, reconstruct the project and plan view at this effective or recorded time. |
| asset_id | string | – | Stable logical identity. Revisions remain under this ID. |
| asset_kind | string | – | – |
| based_on_experiment_id | string | – | Experiment that motivated a plan revision. |
| before | string | – | – |
| body | string | – | Complete UTF-8 record body. Typed writes preserve it losslessly and return byte counts plus an exact get route. |
| body_bytes | integer | – | UTF-8 bytes to return. Use 0 for metadata-only readback; use a positive value and next_body_offset for exact paging. |
| body_offset | integer | – | – |
| body_path | string | – | Local UTF-8 file for a streamed versioned body attachment up to 256 MiB. Use instead of body; only a compact receipt is returned. |
| budget_bytes | integer | – | – |
| cancel_reason | string | – | – |
| change_reason | string | – | Reason for a new plan revision. |
| changed_paths | array | – | Explicit root-relative files or collection boundaries to re-read. Existing roots and all unlisted entries are preserved. |
| confirm_token | string | – | Token returned by the matching forget preview. |
| correction_kind | string | – | Correction operation. Defaults to assertion. |
| correction_reason | string | – | – |
| detail_level | string | – | For show with project_id and no target_id, both values return a bounded summary. full is retained only for compatibility and never returns every durable record body. |
| dry_run | boolean | – | – |
| effective_at | string | – | – |
| evidence_ids | array | – | Evidence retained on a corrected assertion. |
| expected_revision | integer | – | Optimistic concurrency revision. Stale values return a conflict. |
| experiment_id | string | – | Experiment to finish or associate with a decision. |
| export_format | string | – | Visualization file format. html writes one offline explorer with PKM, Lineage, Ontology, project selection, and current-view PNG or anonymized JSON download; d3 writes node-link JSON; dot writes Grap… |
| export_view | string | – | Initial HTML tab or non-HTML export scope. graph is PKM; ontology shows types, shared schema, verified identity links, and typed instances; lineage shows aligned data and research lineage. |
| fields | object | – | Typed structured fields stored with the record revision. measurement requires metric, value, unit, evaluator_contract, dataset, split, tokenizer, context_length, targets, carrier_precision, and sourc… |
| filters | object | – | Optional project, source, type, role, lane, and recorded-time filters. Excluded lanes are not executed. |
| forget_mode | string | – | Preview first. Apply requires its confirm_token. Restore reverses deletion. |
| from_revision | integer | – | – |
| git_root | string | – | Optional Git root recorded with a rebuild snapshot. |
| hypothesis | string | – | Hypothesis when starting an experiment. |
| idempotency_key | string | – | Stable operation key. Reuse it after an uncertain response. |
| include_project_ids | array | – | Additional read-only projects for one local search or integrated visualization export. |
| intent | string | – | Durable intent for record_type=session. |
| job_id | string | – | – |
| limit | integer | – | Maximum local RAG results for action=search. |
| memory_handle | string | – | Existing project session handle for a session intent revision. |
| metrics | object | – | Terminal experiment metrics. |
| missing_fields | array | – | – |
| name | string | – | Project name for create/project_update, or entity name lookup for show. |
| ontology_kind | string | – | Ontology term kind for record_type=ontology. |
| operation | string | – | Typed durable write operation. Use with asset_kind and idempotency_key. |
| plan_revision_id | string | – | Plan revision associated with an experiment or decision. |
| project_id | string | – | Stable project id. For search, this is the write-isolated primary scope. Omit to list projects or use all_projects. |
| protected | boolean | – | – |
| protected_parent_ids | array | – | – |
| purpose | string | – | – |
| queries | array | – | Independent questions returned as separate ranked groups inside one broker request. |
| query | string | – | Required for action=search. Searches stored local knowledge only and does not start live web discovery. |
| query_variants | array | – | Optional local retrieval variants for action=search. They run inside one broker request and are fused before one rerank. |
| reason | string | – | Required reason for any correction. |
| record_id | string | – | Known exact record or alias ID for get, diff, or verify. |
| record_ids | array | – | – |
| record_type | string | – | Required for record. session stores intent; plan creates an immutable revision; experiment starts or finishes a run; decision links a conclusion; ontology creates a versioned type or relation; correc… |
| records | array | – | – |
| removed_paths | array | – | Explicit root-relative entries to remove from the active snapshot. Historical snapshots remain addressable. |
| replacement | – | – | New assertion value, or new entity name for entity_split. |
| request_id | string | – | Caller-chosen ID for one local query. Supply it before a long request so project_memory query_status/query_cancel can inspect or cancel the same operation. |
| response_budget_bytes | integer | – | Explicit result-array byte budget. Without an override, summaries adapt to unique result, question and source-family counts. Stored bodies and retrieval scope are not truncated by this budget; envelo… |
| response_deadline_ms | integer | – | Caller-selected 1-300 second response deadline. Returns available lane results or QUERY_TIMEOUT with request_id. Native reads remain tracked until they settle; stored evidence and writes are unaffect… |
| revision | integer | – | – |
| root_mode | string | – | – |
| roots | array | – | Approved local roots and optional path-independent role/alias manifest. sync merges roots by default; removal is explicit. |
| set_current | boolean | – | For plan writes, select this revision as current. Defaults to true; use false for historical imports. |
| since_revision | integer | – | – |
| snapshot_path | string | – | – |
| source_ids | array | – | Entity ids merged into target_id by entity_merge. |
| source_reference | string | – | – |
| source_sequence | integer | – | – |
| status | string | – | Use success, failed, or inconclusive to finish an experiment. Omit or use running when starting it. |
| summary | string | – | Experiment result or decision summary. |
| supersedes_term_id | string | – | Prior ontology term replaced by this revision. |
| target_id | string | – | Assertion or entity id for show or correction. |
| title | string | – | Plan title, experiment name, or decision title. |
| to_revision | integer | – | – |
| user_constraints | array | – | – |
| valid_from | string | – | Corrected assertion valid-time start. |
| valid_to | string | – | Corrected assertion valid-time end. |
| verification_level | string | – | – |
| version | integer | – | Ontology revision number. Defaults to 1 or the superseded term version plus one. |
| wait_timeout_ms | integer | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| active_source_snapshot | object | – | – |
| assertion | object | – | – |
| assertion_count | number | – | – |
| citation_observation_count | number | – | – |
| context | object | – | – |
| correction_count | number | – | – |
| current | object | – | – |
| decision_count | number | – | – |
| decisions | array | – | – |
| diff | object | – | – |
| doctor | object | – | – |
| document_count | number | – | – |
| elapsed_ms | number | – | – |
| entities | array | – | – |
| entity | object | – | – |
| entity_count | number | – | – |
| entity_operation_count | number | – | – |
| error | object | – | – |
| experiment_count | number | – | – |
| experiments | array | – | – |
| forget | object | – | – |
| groups | array | – | – |
| imported | object | – | – |
| index | object | – | – |
| job | object | – | – |
| job_counts | object | – | – |
| memory | string | – | – |
| memory_handle | string | – | – |
| meta | object | – | – |
| plan_count | number | – | – |
| plans | array | – | – |
| project | object | – | – |
| projects | array | – | – |
| query | string | – | – |
| query_status | object | – | – |
| receipt | object | – | – |
| receipts | array | – | – |
| record | object | – | – |
| records | array | – | – |
| results | array | – | – |
| search_event_count | number | – | – |
| session | object | – | – |
| session_count | number | – | – |
| snapshot | object | – | – |
| source_entry_count | number | – | – |
| timeline | object | – | – |
| verification | object | – | – |
| visualization | object | – | – |
No examples provided.
project_memory_search Local Project Memory Search ~545
LOCAL PROJECT KNOWLEDGE SEARCH ONLY. With research enabled, one local broker lets multiple MCP sessions query the same knowledge base concurrently and orders writes safely. Always use this tool when the user asks to find, recall, inspect, or search information already stored in project memory, indexed local roots, papers, codebases, plans, experiments, or decisions. Use query_variants for multiple retrieval angles in one call instead of opening terminals or calling this tool repeatedly. Query embeddings are batched, candidates are fused with RRF, graph expansion starts from retrieved evidence, and the primary query is reranked once. Only bounded query-focused summaries from that final ranking are returned; stored bodies never bypass this response gate. If one retrieval lane times out, the other lanes still return and meta.degraded_lanes identifies the partial lane; do not repeat the same query automatically. Uses exact, BM25, vector, and graph retrieval. It never opens Google, a browser, or SearchApi. Use search or search_parallel only when new external information is required.
| Name | Type | Req | Description |
|---|---|---|---|
| all_projects | boolean | – | Search every active named project. Excludes Inbox and cannot be combined with project ids. |
| filters | object | – | Optional project, source, type, role, lane, and recorded-time filters. Excluded lanes are not executed. |
| include_project_ids | array | – | Additional read-only projects searched with the primary project. |
| limit | integer | – | Maximum local RAG results. |
| project_id | string | – | Primary project to search. Required unless all_projects=true. |
| queries | array | – | Independent questions returned as separate ranked groups inside one broker request. |
| query | string | – | One natural-language query over indexed local project knowledge. Use queries instead for independent grouped answers. |
| query_variants | array | – | Optional retrieval variants executed inside this one broker request. Exact identifiers and quoted phrases are added deterministically, candidates are fused with RRF, and the primary query is reranked… |
| request_id | string | – | Caller-chosen ID for one local query. Supply it before a long request so project_memory query_status/query_cancel can inspect or cancel the same operation. |
| response_budget_bytes | integer | – | Explicit result-array byte budget. Without an override, summaries adapt to unique result, question and source-family counts. Stored bodies and retrieval scope are not truncated by this budget; envelo… |
| response_deadline_ms | integer | – | Caller-selected 1-300 second response deadline. Returns available lane results or QUERY_TIMEOUT with request_id. Native reads remain tracked until they settle; stored evidence and writes are unaffect… |
| Name | Type | Req | Description |
|---|---|---|---|
| active_source_snapshot | object | – | – |
| assertion | object | – | – |
| assertion_count | number | – | – |
| citation_observation_count | number | – | – |
| context | object | – | – |
| correction_count | number | – | – |
| current | object | – | – |
| decision_count | number | – | – |
| decisions | array | – | – |
| diff | object | – | – |
| doctor | object | – | – |
| document_count | number | – | – |
| elapsed_ms | number | – | – |
| entities | array | – | – |
| entity | object | – | – |
| entity_count | number | – | – |
| entity_operation_count | number | – | – |
| error | object | – | – |
| experiment_count | number | – | – |
| experiments | array | – | – |
| forget | object | – | – |
| groups | array | – | – |
| imported | object | – | – |
| index | object | – | – |
| job | object | – | – |
| job_counts | object | – | – |
| memory | string | – | – |
| memory_handle | string | – | – |
| meta | object | – | – |
| plan_count | number | – | – |
| plans | array | – | – |
| project | object | – | – |
| projects | array | – | – |
| query | string | – | – |
| query_status | object | – | – |
| receipt | object | – | – |
| receipts | array | – | – |
| record | object | – | – |
| records | array | – | – |
| results | array | – | – |
| search_event_count | number | – | – |
| session | object | – | – |
| session_count | number | – | – |
| snapshot | object | – | – |
| source_entry_count | number | – | – |
| timeline | object | – | – |
| verification | object | – | – |
| visualization | object | – | – |
No examples provided.
scholar_search Google Scholar Search ~250
Use only for paper metadata such as authors, venue, year, versions, and citation counts. With research enabled, one local broker lets multiple MCP sessions query the same knowledge base concurrently and orders writes safely. Do not use it to discover or read paper content; use search with extract_mode instead. Returns title, authors, publication, year, snippet, citation count, related/version links, and an available full-text link. With research enabled, metadata and citation observations retain provider provenance and research_context exposes related prior searches. Google Scholar uses browser search, SearchApi primary, or configured fallback. Results are cached with the same TTL as search. Max 10 papers per call.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Maximum papers. Integer 1-10, default 10. |
| memory_handle | string | – | Reuse the handle returned by a prior project-aware call. |
| project_id | string | – | Project memory id. |
| query | string | yes | Google Scholar query. Supports quotes and author: operators. |
| session_id | string | – | Stable host task id. Reuses the same project session after restart. |
| session_intent | string | – | Current durable task intent. A changed value creates an immutable revision. |
| Name | Type | Req | Description |
|---|---|---|---|
| elapsed_ms | number | – | – |
| error | object | – | – |
| memory | string | – | – |
| memory_handle | string | – | – |
| meta | object | – | – |
| query | string | – | – |
| research_context | object | – | – |
| results | array | – | – |
No examples provided.
search Web Search and Extract ~826
PRIMARY SINGLE-QUERY LIVE DISCOVERY AND CONTENT INGESTION TOOL. ALWAYS PERFORMS LIVE WEB SEARCH. With research enabled, one local broker lets multiple MCP sessions query the same knowledge base concurrently and orders writes safely. Use this tool only when new external information from Google, public websites, papers, or repositories is required. When the task requires both finding and reading public web pages, PDFs, papers, or GitHub repositories, set extract_mode=abstract or full in this call. Do not download public PDFs, clone repositories, or invoke local parsers first. Select extract_mode=full, not abstract, when the user asks to read originals, full text, document bodies, or code, or to compare source contents. Use extract separately only when the exact public URL is already known and no new discovery is required. Use general repository tools only for editing, building, testing, or full Git history. Providing project_id also fuses stored project evidence with live results, but never makes this a local-only search. For stored project knowledge without live web discovery, use project_memory_search. limit accepts integers from 1 to 20. extract_limit accepts integers from 1 to 10, defaults to 5, and limits unique extracted URLs. Final results use one bounded response budget after ranking; full captured bodies remain local. Use extract on one selected URL when longer response text is explicitly required. The response includes applied, skipped, truncated, total_chars, and a bounded remaining_urls list. GitHub none mode reads the README; abstract and full can sparse-index eligible repositories with Tree-sitter. With research enabled and project_id set, live web, exact, BM25, vector, code, and graph lanes are fused by RRF and one reranker. With research disabled, provider order and query BM25 rank are fused by a lightweight in-memory RRF reranker without opening local storage or loading the vector model. research_context returns up to three prior searches for deeper…
| Name | Type | Req | Description |
|---|---|---|---|
| extract_limit | integer | – | Maximum unique result URLs to extract. Integer 1-10, default 5. |
| extract_mode | string | – | Content depth in this search call. Use none only when titles and snippets are enough, abstract for relevance evidence, and full when the user asks to read originals, full text, document bodies, or co… |
| include_project_ids | array | – | Additional read-only projects joined through ontology-aligned schema and identity links. New records stay in project_id. |
| limit | integer | – | Maximum results. Integer 1-20, default 10. |
| max_chars | integer | – | Maximum returned characters per extracted result in response_content=full. Defaults to 1500 for abstract and 50000 for full. |
| memory_handle | string | – | Reuse the handle returned by a prior project-aware call. |
| project_id | string | – | Project memory id. |
| query | string | yes | Google search query. Use site: filters and quotes for exact match. |
| response_content | string | – | Controls only the returned body. summary is the default and returns a 1500-character evidence excerpt; full returns up to max_chars. Research storage keeps the full captured text in deterministic chu… |
| session_id | string | – | Stable host task id. Reuses the same project session after restart. |
| session_intent | string | – | Current durable task intent. A changed value creates an immutable revision. |
| Name | Type | Req | Description |
|---|---|---|---|
| elapsed_ms | number | – | – |
| error | object | – | – |
| memory | string | – | – |
| memory_handle | string | – | – |
| meta | object | – | – |
| query | string | – | – |
| research_context | object | – | – |
| results | array | – | – |
No examples provided.
search_parallel Parallel Web Search and Extract ~839
PRIMARY MULTI-QUERY LIVE DISCOVERY AND CONTENT INGESTION TOOL. ALWAYS PERFORMS MULTIPLE LIVE WEB SEARCHES. With research enabled, one local broker lets multiple MCP sessions query the same knowledge base concurrently and orders writes safely. Use this tool only when 2-12 new external queries are required. Providing project_id adds stored evidence but never makes the searches local-only. When the task requires broad discovery plus reading public web pages, PDFs, papers, or GitHub repositories, set extract_mode=abstract or full in this call. Do not download public PDFs, clone repositories, or invoke local parsers first. Select extract_mode=full, not abstract, when the user asks to read originals, full text, document bodies, or code, or to compare source contents. Use extract separately only when the exact public URL is already known and no new discovery is required. Use general repository tools only for editing, building, testing, or full Git history. For stored project knowledge without live web discovery, use project_memory_search. Each query limit accepts integers from 1 to 20. Call-wide extract_limit accepts 1-20 with default 12 for abstract, and 1-10 with default 10 for full. Final results use one call-wide bounded response budget after ranking; at most 36 ranked rows are returned across query groups and full captured bodies remain local. Use extract on one selected URL when longer response text is explicitly required. The response includes applied, skipped, truncated, total_chars, and a bounded remaining_urls list. GitHub none mode reads the README; abstract and full can sparse-index eligible repositories with Tree-sitter. With research enabled and project_id set, each query fuses live, exact, BM25, vector, code, and graph lanes through RRF and one reranker. With research disabled, each query independently fuses provider order and query BM25 rank through a lightweight in-memory RRF reranker without opening local storage or loading the vector model. research_con…
| Name | Type | Req | Description |
|---|---|---|---|
| extract_limit | integer | – | Call-wide maximum unique result URLs to extract. Integer 1-20, default 12 for abstract; full defaults to and allows at most 10. |
| extract_mode | string | – | Content depth in this search call. Use none only when titles and snippets are enough, abstract for relevance evidence, and full when the user asks to read originals, full text, document bodies, or co… |
| include_project_ids | array | – | Additional read-only projects joined through ontology-aligned schema and identity links. New records stay in project_id. |
| limit | integer | – | Maximum results per query. Integer 1-20, default 10. |
| max_chars | integer | – | Maximum returned characters per extracted result in response_content=full. Defaults to 1500 for abstract and 50000 for full. |
| memory_handle | string | – | Reuse the handle returned by a prior project-aware call. |
| project_id | string | – | Project memory id. |
| queries | array | yes | 2-12 independent live queries. |
| response_content | string | – | Controls only returned bodies. summary is the default and returns 1500-character evidence excerpts; full returns up to max_chars. Research storage keeps the full captured text in deterministic chunks. |
| session_id | string | – | Stable host task id. Reuses the same project session after restart. |
| session_intent | string | – | Current durable task intent. A changed value creates an immutable revision. |
| Name | Type | Req | Description |
|---|---|---|---|
| elapsed_ms | number | – | – |
| error | object | – | – |
| memory | string | – | – |
| memory_handle | string | – | – |
| meta | object | – | – |
| research_context | object | – | – |
| results | array | – | – |
No examples provided.
What is the io.github.HarimxChoi/google-surf-mcp server?
io.github.HarimxChoi/google-surf-mcp is listed in the public MCP registry as io.github.HarimxChoi/google-surf-mcp. Web, academic and code search with graph RAG, data lineage, ontology and cross-project schema links. This page covers its npm package (google-surf-mcp).
Is the io.github.HarimxChoi/google-surf-mcp server safe to use?
io.github.HarimxChoi/google-surf-mcp scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.HarimxChoi/google-surf-mcp server expose?
io.github.HarimxChoi/google-surf-mcp exposes 7 tools: search, scholar_search, search_parallel, extract, project_memory_search, and 2 more. Their descriptions and schemas cost roughly 5,358 tokens of context every time the server is loaded.
Is the io.github.HarimxChoi/google-surf-mcp server still maintained?
io.github.HarimxChoi/google-surf-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.HarimxChoi/google-surf-mcp server under?
io.github.HarimxChoi/google-surf-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.