Brave Search (archived)
Archived official reference server for Brave Search web and local queries. Moved to modelcontextprotocol/servers-archived and no longer actively maintained.
Automated danger grade: this page reports detected or inferred risk from a scan. It is not an endorsement, certification, or claim that the server is malicious.
Low transparency: this server declares few or no tool behavior annotations, so the danger score is inferred from defaults. Treat as cannot verify safe — not necessarily dangerous.
Grade history
13 scans on record between 2026-07-03 and 2026-07-04. The grade changed once in that time.
| Scanned (UTC) | Grade | Engine | Attributed cause |
|---|---|---|---|
| 2026-07-03 02:46 | C | mcpaudit 2.1.0 | First scan on record |
| 2026-07-03 02:50 | C | mcpaudit 2.1.0 | No change |
| 2026-07-03 09:44 | B | mcpaudit 2.3.0 | Scanner engine changed |
| 2026-07-03 10:00 | B | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:01 | B | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:12 | B | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:16 | B | mcpaudit 2.3.0 | No change |
| 2026-07-03 12:42 | B | mcpaudit 2.3.0 | No change |
| 2026-07-03 13:20 | B | mcpaudit 2.4.0 | No change |
| 2026-07-03 14:13 | B | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:13 | B | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:16 | B | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:18 | B | mcpaudit 2.4.0 | No change |
History as recorded by this registry's own scans. The cause is an attribution from the inputs the registry records — the scanner engine identity and the declared tool surface — not proof of what changed on the server. Generated 2026-08-02.
How to read this grade
- What was scanned: @modelcontextprotocol/server-brave-search@0.6.2, as distributed.
- When: 2026-07-04 08:18:03.
- By what: mcpaudit 2.4.0, applied to the published danger rubric (weights, bands, and the critical cap are all public).
- What the grade means: this registry's opinion, computed by the disclosed automated methodology against the artifact version above, on the scan date above. It measures conformance to the rubric at scan time.
- What it does not claim: it is not a statement that the product is malicious, insecure in your deployment, or unfit for use, and it is not an endorsement or certification.
- Disagree? Grades are re-checkable against the same package version, and corrections are welcome: open a dispute — see the dispute & correction policy.
Spec-shift exposure
READY against MCP 2026-07-28-rc · confidence high · ruled 2026-07-18
| Dimension | Area | Verdict |
|---|---|---|
| D1 | Stateless-core compatibility | READY |
| D2 | Deprecated-capability reliance | READY |
| D3 | Authorization posture | N_A |
| D4 | Schema and wire conformance | READY |
| D5 | Extensions readiness | NOTE |
This is a point-in-time ruling against a release candidate, not the published specification, and it is independent of the danger grade above. Neither figure constrains the other.
Provenance & dispute
- Listing basis: operator-listed from a public catalog. This entry was not submitted by its vendor.
- Scan target: the published npm artifact
@modelcontextprotocol/server-brave-search@0.6.2, installed and scanned locally using sandbox imagemcp-trust-scan:corpus-2026-07-03. The public record stores the sandbox image, but not the network mode, so this page does not claim network isolation for that run. - Credentials: this server declares required environment variables (
BRAVE_API_KEY). Scans never use real credentials; at most inert placeholder values are used for scan execution. - Dispute: vendor or maintainer of this server? Dispute this grade — first response within 14 days.
Add this badge to your README
Copy the Markdown below only if you want to link readers to the latest danger grade and scan caveats:
[](https://mcp-trust.vercel.app/ui/servers/mcp-archived-brave-search)
Findings
| Severity | Rule | Title | Category | Detail |
|---|---|---|---|---|
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=null (spec default: true) |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| high | MCP001 | File read capability | file_read | query; search |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=null (spec default: true) |
| low | MCP003 | Network access capability | network | openWorldHint=null (spec default: true) |
| high | MCP001 | File read capability | file_read | query; search |
Score breakdown
| Dimension | Raw (0–10) | Weight | Weighted |
|---|---|---|---|
| File access | 0.9 | ×1.2 | 1.08 |
| Network access | 1.5 | ×1.0 | 1.50 |
| Shell execution | 0.0 | ×2.0 | 0.00 |
| Destructive | 2.0 | ×0.3 | 0.60 |
| Exfiltration | 0.0 | ×0.4 | 0.00 |