Explore / Brave Search MCP Server
MCP ServerRisk reviewedmedium risk

Brave Search MCP Server

Brave Search MCP Server is an MCP server for research and automation workflows on Claude, Claude Code, Codex, Cursor, Cline and self-hosted. Verified from source metadata and risk-reviewed by AgentMaps.

Repository
Preview · 94

Preview: the curated catalog plus the latest auto-checked entries. 47 newly auto-checked

63/100
Recommended
Confidence: medium
65/100
Benchmark
Confidence: medium
Needs human reviewRisk reviewed · Verification tier is risk-reviewed; this reflects automated evidence, not a full install or execution test.
Why
Recommendation 63/100, fits Research, setup is medium.
Best for
Research workflows that need retrieval, summarization, or structured source gathering.
Not for
Production use without reviewing the upstream documentation and permission scope.
Boundary
Checked up to "Risk reviewed"; deeper install and interface testing isn't covered yet — confirm in your own environment.
Remaining risk
Requires or commonly uses an API token. Use least-privilege scopes, keep tokens out of prompts/logs, and rotate credentials after testing.
Next step
Review tokens, write access, and network scope in a sandbox before team adoption.
Check before you adopt
This capability uses higher-risk permissions (tokens, write access, shell, and the like). Try it in an isolated environment and confirm what it actually does before using it for real work.

What it is good for

Brave Search MCP Server is an MCP server for research and automation workflows on Claude, Claude Code, Codex, Cursor, Cline and self-hosted. Verified from source metadata and risk-reviewed by AgentMaps. This profile is auto-verified by the AgentMaps daily pipeline and passed publish review before being listed.

Use cases

  • - Research workflows that need retrieval, summarization, or structured source gathering.
  • - Automation workflows where repeatable tool calls are more useful than one-off prompts.
  • - Users who already run an MCP-compatible client such as Claude Code, Codex, Cursor, Cline, or a self-hosted agent.

Best for

  • - Research workflows that need retrieval, summarization, or structured source gathering.
  • - Automation workflows where repeatable tool calls are more useful than one-off prompts.
  • - Users who already run an MCP-compatible client such as Claude Code, Codex, Cursor, Cline, or a self-hosted agent.

Not for

  • - Production use without reviewing the upstream documentation and permission scope.
  • - Users who require full install, execution, and interface verification before trying a tool.
  • - Environments where API keys or service tokens cannot be scoped or rotated.

Limitations

  • - Production use without reviewing the upstream documentation and permission scope.
  • - Users who require full install, execution, and interface verification before trying a tool.
  • - Environments where API keys or service tokens cannot be scoped or rotated.
How it runsTool/runtime connector

How to use it & what to watch

AI may help filter, explain, and draft a trial plan, but must not perform write, shell, external side effects, or production publishing before review.

What you'll see

  • Start from your task and the platform you use
  • Review its setup, source, and permission scope
  • Try it first in an isolated or low-permission environment
  • For high-risk actions, wait for a review before continuing

Where you can step in

  • Adjust task/platform filters
  • Add to compare
  • Open the source to check
  • Stop a high-risk adoption
  • Add what you've learned

Actions needing approval

  • Token/API key scope approval
  • Approval before writes or state mutation
  • Sandbox approval before shell execution
  • External network target approval
  • Login-required path not fully tested

If something goes wrong

  • Auth path needs manual reproduction or a constrained test account.

How to judge a trial

  • Can you find a task-fit candidate within two minutes
  • Can it explain why it's recommended and where it doesn't fit
  • Can you see the token, write, shell, network, or local-file risks
  • Can you tell 'checked the docs' apart from 'actually verified in a run'
  • If a trial fails, is there a fallback or a way to take over manually

Verification evidence

Below is the result of each check — passed, partial, skipped, or not yet tested. It shows how far checking has gone, not that the capability is cleared for production use.

Info checked

Source, docs, license, or package metadata exists.

passed
Risk reviewed

Static review assigns permission and risk boundaries.

passed
Install-verified

Install path can be checked, but not necessarily in your environment.

skipped
Interface-verified

Interface or entrypoint parsed; not a production safety approval.

skipped
  • Verification tier is risk-reviewed; this reflects automated evidence, not a full install or execution test.
  • Static audit status is passed; the source code was reviewed for risk signals but not cloned, installed, or executed.
  • Benchmark score is 65 and recommendation score is 63, based on automated evaluation.
  • Trust metadata came from read-only GitHub live metadata enrichment.

Evaluation summary

Detailed check
Needs reviewTrigger evalMisfire risk: High

Best for

  • - Research tasks with explicit source and risk review
  • - Automation tasks with explicit source and risk review

Avoid when

  • - You need unattended publish, production write access, or bypassed manual review.
  • - Secrets or long-lived tokens cannot be scoped safely.

Risk findings

  • - Requires Token
  • - External Network
  • - Credential or sensitive token access is required or implied.
  • - External network access is present or implied.

Verified evidence

  • - L2 static benchmark status: passed

Safety findings

  • hightoken

    Credential or sensitive token access is required or implied.

    Recommendation: Require manual review and avoid browser-exposed secrets or NEXT_PUBLIC service keys.

  • mediumnetwork

    External network access is present or implied.

    Recommendation: Keep network assumptions visible and source-backed.

Evidence references

  • Canonical source URL

    Used only as source evidence; no source code was executed.

  • Normalized source artifact

    Provides object type, platform fit, risk guess, risk flags, and publish blockers.

  • Static trigger prompt generation

    Positive, negative, and ambiguous prompts generated from metadata; not a runtime model benchmark.

  • L2 benchmark run

    Benchmark status: passed.

Score breakdown

Safety & permissions64
How well it works70
Actively maintained78
Setup & integration72
Interface quality60
Follows standards66
Task fit63
Works across platforms84

Why it scores well

  • - Research workflows that need retrieval, summarization, or structured source gathering.
  • - Automation workflows where repeatable tool calls are more useful than one-off prompts.
  • - Users who already run an MCP-compatible client such as Claude Code, Codex, Cursor, Cline, or a self-hosted agent.

Watch outs

  • - Production use without reviewing the upstream documentation and permission scope.
  • - Users who require full install, execution, and interface verification before trying a tool.
  • - Environments where API keys or service tokens cannot be scoped or rotated.

Alternatives

GitHub MCP Server
MCP Server · Coding, Automation
66/100
Rec

Connect agents to GitHub repositories, issues, pull requests, and code search.

Interface-verifiedhigh riskSelf-hosted
Compare Brave Search MCP Server vs GitHub MCP Server
Playwright MCP
MCP Server · Browser, Automation
84/100
Rec

Expose browser automation primitives through MCP for web navigation and testing.

Interface-verifiedmedium riskSelf-hosted
Compare Brave Search MCP Server vs Playwright MCP
Context7 MCP
MCP Server · Coding, Research
87/100
Rec

Fetch current library documentation and examples directly into coding agents.

Interface-verifiedlow riskCursor
Compare Brave Search MCP Server vs Context7 MCP