
Company News
Meet the Socket Team at RSAC and BSidesSF 2026
Join Socket for live demos, rooftop happy hours, and one-on-one meetings during BSidesSF and RSA 2026 in San Francisco.
@guhcostan/web-search-mcp
Advanced tools
Minimal MCP server that can search the web and extract readable page content, similar to Cursor's built-in web context.
npm install
npm start
npm i -g @guhcostan/web-search-mcp
Then reference the binary web-search-mcp.
Add to your Cursor MCP settings:
{
"mcpServers": {
"web-search-mcp": { "command": "web-search-mcp" }
}
}
Alternatively, without global install, use npx:
{
"mcpServers": {
"web-search-mcp": {
"command": "npx",
"args": ["-y", "@guhcostan/web-search-mcp@latest"]
}
}
}
search_web
query (string, required)limit (number, optional, 1–10, default 5){ url: string; title?: string; snippet?: string }fetch_page
url (string URL, required){ url: string; title?: string; content: string }Type-check, lint and tests:
npm run check
Run individually:
npm run build
npm run lint
npm test
MIT
FAQs
MCP server to search the web and fetch page contents
The npm package @guhcostan/web-search-mcp receives a total of 95 weekly downloads. As such, @guhcostan/web-search-mcp popularity was classified as not popular.
We found that @guhcostan/web-search-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Join Socket for live demos, rooftop happy hours, and one-on-one meetings during BSidesSF and RSA 2026 in San Francisco.

Research
/Security News
Malicious Packagist packages disguised as Laravel utilities install an encrypted PHP RAT via Composer dependencies, enabling remote access and C2 callbacks.

Research
/Security News
OpenVSX releases of Aqua Trivy 1.8.12 and 1.8.13 contained injected natural-language prompts that abuse local AI coding agents for system inspection and potential data exfiltration.