
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@usestring/mcp
Advanced tools
Official String AI Web Access MCP Server – fetch and search the web via the String AI API from any MCP client
The official Model Context Protocol (MCP) server for String AI's Web Access API. Connect any MCP-compatible client — VS Code, Cursor, Windsurf, Claude Desktop, and more — to String AI's powerful web access capabilities.
| Tool | Description |
|---|---|
web_access_fetch | Fetch any webpage with automatic anti-bot bypass, CAPTCHA handling, and JavaScript rendering |
web_access_search | Search the web with reliable results — bypasses rate limits and bot protection on search engines |
web_access_sitemap | Crawl a whole site and map its URLs as an asynchronous job — one tool drives the lifecycle via action |
web_access_sitemap — sitemap crawl jobsA crawl is a two-phase, asynchronous quote → approve → poll → read job: nothing is crawled or billed until the quote is explicitly approved.
action | What it does |
|---|---|
submit | Quote a crawl (url required; maxPages ≤ 10000 default 10, maxDepth ≤ 100 default 2, pathPrefix, budgetUsd, useSitemap optional). Returns jobId + estimatedCostUsd + estimatedPages, status awaiting_approval. |
approve | Billing consent — starts the crawl. 402 = insufficient funds; 409 partial_state = retry approve. |
status | Poll progress: awaiting_approval → running (pending/processed) → completed | failed | canceled | token_cap_exceeded; partial_state = retry approve. Returns counts only — URLs come from results. |
results | Paginated discovered URLs (limit ≤ 5000 default 1000, offset). Durable after completion; per-URL discoveredUrls is only present for ~1h. |
cancel | Stop a non-terminal job; already-fetched pages stay billed and readable. |
list | The account's recent crawl jobs (limit ≤ 100 default 20, offset). |
env STRING_AI_API_KEY=your-key npx @usestring/mcp
npm install -g @usestring/mcp
STRING_AI_API_KEY=your-key string-ai-mcp
git clone https://github.com/usestring/string-ai-mcp.git
cd string-ai-mcp
npm install
npm run build
STRING_AI_API_KEY=your-key node build/index.js
| Variable | Required | Description |
|---|---|---|
STRING_AI_API_KEY | Yes | Your String AI API key |
Press Ctrl+Shift+P → Preferences: Open User Settings (JSON) and add:
{
"inputs": [
{
"type": "promptString",
"id": "stringAiKey",
"description": "String AI API Key",
"password": true
}
],
"servers": {
"string-ai": {
"command": "npx",
"args": ["-y", "@usestring/mcp"],
"env": {
"STRING_AI_API_KEY": "${input:stringAiKey}"
}
}
}
}
Or add a .vscode/mcp.json file to share the configuration with your team.
Open Settings → Features → MCP Servers → + Add new global MCP server and paste:
{
"mcpServers": {
"string-ai": {
"command": "npx",
"args": ["-y", "@usestring/mcp"],
"env": {
"STRING_AI_API_KEY": "YOUR_API_KEY"
}
}
}
}
Add to ~/.codeium/windsurf/model_config.json:
{
"mcpServers": {
"string-ai": {
"command": "npx",
"args": ["-y", "@usestring/mcp"],
"env": {
"STRING_AI_API_KEY": "YOUR_API_KEY"
}
}
}
}
Add to your claude_desktop_config.json:
{
"mcpServers": {
"string-ai": {
"command": "npx",
"args": ["-y", "@usestring/mcp"],
"env": {
"STRING_AI_API_KEY": "YOUR_API_KEY"
}
}
}
}
The MCP Inspector lets you test your server interactively in a browser:
npx @modelcontextprotocol/inspector node build/index.js
Then open http://127.0.0.1:6274, connect via stdio, and try calling each
tool from the UI.
┌──────────────────┐ stdio (JSON-RPC) ┌──────────────────┐ HTTPS ┌──────────────────┐
│ VS Code / Cursor │ ◄──────────────────► │ String AI │ ────────► │ String AI │
│ Windsurf / Claude│ │ Web Access MCP │ │ Web Access API │
└──────────────────┘ └──────────────────┘ └──────────────────┘
web_access_fetch
or web_access_search.String AI provides a powerful web access API that handles proxies, anti-bot measures, and JavaScript rendering automatically. Get your API key at usestring.ai.
MIT
Please report security vulnerabilities privately as described in SECURITY.md.
FAQs
Official String AI Web Access MCP Server – fetch and search the web via the String AI API from any MCP client
We found that @usestring/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.