No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by alchaincyf · MCP Server · ★ 105
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is huashu-doubao-search safe to install? View the security audit →
huashu-doubao-search 「你给 Claude Code 换上了国产模型,然后发现它不会上网了」 一条命令,让你的 Agent 用上豆包搜索:字节系独家信源、千字级正文摘要、发布时间精确到秒,每月 500 次免费。 豆包搜索是火山引擎为 AI Agent 构建的联网信息服务,2026 年 7 月起面向企业和开发者开放。 为什么需要它 · 效果 · 安装 · 工具参数 · AI 增强层 English 为什么需要它 Claude Code 内置的 WebSearch 是 Anthropic 的服务端工具,跑在 Anthropic 的服务器上。一旦你把 指向国产模型的兼容端点(豆包 Seed、Kimi、GLM、DeepSeek……),WebSearch 就没了执行器:工具看着还在,agent 实际上断网了。很多人是切完模型才发现这件事。 海外搜索 API 能补上这个缺口,但对中文开发者有三个现实问题:美元结算(有的还强制绑信用卡)、Google 系索引搜不到中文生态内容、国内直连不稳定。 豆包搜索正好把这三个问题一起解决了,这个 MCP server 把它变成任何 agent 一条命令就能装上的搜索工具。 效果 以下是真实返回(工具调用一次的原始输出节选): 几个实测过的细节: 千字级正文摘要,不是两行摘要加一堆蓝链接。别家要「搜索 API + 抓取 API」两跳才能凑齐的链路,它一次返回 发布时间精确到秒,agent 自己就能判断信息新鲜度。实测查行业热点,返回过发布时间是「查询前一晚」的文章 字节系独家信源:今日头条正文高频返回;查「XX 是什么」「XX 是谁」这类实体问题,抖音百科基本排第一 每条结果自带正文 token 计数(ContentTokenCo
| Stars | 105 |
| Forks | 12 |
| Language | JavaScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 64.5783016694011/100 |
| Open Issues | 2 |
| Last Updated | 2026-07-25 |
| Created | 2026-07-11 |
| Platforms | browser, claude-code, mcp, node |
| Est. Tokens | ~8k |
These tools work well together with huashu-doubao-search for enhanced workflows:
Explore other popular mcp server tools:
huashu-doubao-search is 豆包搜索 MCP server — 给换了国产模型的 Claude Code 补上联网能力。字节系信源、千字正文、每月500次免费 | Agent-first web search MCP. It is categorized as a MCP Server with 105 GitHub stars.
huashu-doubao-search is primarily written in JavaScript.
You can find installation instructions and usage details in the huashu-doubao-search GitHub repository at github.com/alchaincyf/huashu-doubao-search. The project has 105 stars and 12 forks, indicating an active community.
huashu-doubao-search is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: