Back to Browse

Mcp MCP Server

Developer ToolsModerate5.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Read any web page as clean Markdown for AI agents: fetch, search, metadata, links. SSRF-safe.

About

Read any web page as clean Markdown for AI agents: fetch, search, metadata, links. SSRF-safe.

Remote endpoints: streamable-http: https://mcp.vanshul.com/mcp

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-architected MCP server for web reading with strong security controls. The codebase implements proper SSRF defenses, input validation, and error handling. Permissions are narrowly scoped to HTTP network requests and environment variable access (for configuration). Minor code quality observations around exception handling and input sanitization do not materially impact security. Supply chain analysis found 5 known vulnerabilities in dependencies (2 critical, 2 high severity).

7 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

mcp.vanshul.com

MCP Registry Endpoint

A public Model Context Protocol (MCP) server, running as a Cloudflare Worker, that lets any AI agent read the live web as clean Markdown. It builds on the same extraction pipeline as the sibling reader/ project (Mozilla Readability + Turndown), exposed over the MCP Streamable HTTP transport so agentic clients can plug straight in.

Endpoint

POST https://mcp.vanshul.com/mcp     # JSON-RPC 2.0 (MCP)
GET  https://mcp.vanshul.com/health  # { ok: true, tools: [...] }

Tools

ToolInputReturns
fetch_markdown{ url, max_chars? }The page's main content as clean Markdown (optionally truncated to max_chars)
search_page{ url, query, max_matches?, context_chars? }Only the passages matching query, each with its heading breadcrumb, ranked by relevance — token-efficient alternative to fetch_markdown
fetch_metadata{ url }JSON: title, byline, siteName, excerpt, wordCount
extract_links{ url, limit? }JSON: all outbound http(s) links + anchor text

Connect from an MCP client

Remote/HTTP-capable clients (Claude Desktop, Cursor, Continue, …):

{
  "mcpServers": {
    "web-reader": { "url": "https://mcp.vanshul.com/mcp" }
  }
}

Stdio-only clients can bridge with mcp-remote:

npx mcp-remote https://mcp.vanshul.com/mcp

Add it to your client

  • Cursor — Settings → MCP → Add new server, or drop this into ~/.cursor/mcp.json:
    { "mcpServers": { "web-reader": { "url": "https://mcp.vanshul.com/mcp" } } }
    
  • Claude Desktop — add the same block to claude_desktop_config.json (Settings → Developer → Edit Config). If your version is stdio-only, use:
    { "mcpServers": { "web-reader": { "command": "npx", "args": ["mcp-remote", "https://mcp.vanshul.com/mcp"] } } }
    
  • Continue / VS Code — add web-reader with URL https://mcp.vanshul.com/mcp to your MCP servers config.

Try it with curl

curl -s https://mcp.vanshul.com/mcp \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

curl -s https://mcp.vanshul.com/mcp \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call",
       "params":{"name":"fetch_markdown","arguments":{"url":"https://example.com"}}}'

# Return only the passages matching a query (token-efficient):
curl -s https://mcp.vanshul.com/mcp \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":3,"method":"tools/call",
       "params":{"name":"search_page","arguments":{"url":"https://example.com","query":"more information"}}}'

Layout

mcp/
├── src/
│   ├── worker.ts     # entry: routes /mcp, /health, rate limit, CORS
│   ├── mcp.ts        # JSON-RPC dispatch + tool definitions
│   ├── extract.ts    # HTML -> Markdown / links (Readability + Turndown)
│   ├── search.ts     # query-focused passage search over extracted Markdown
│   ├── fetcher.ts    # fetch with timeout, size cap, re-validated redirects
│   └── security.ts   # SSRF guard (block private/internal addresses)
├── public/
│   ├── index.html    # landing page (served for non-API paths)
│   ├── og.png        # social share image (1200×630)
│   ├── og.svg        # social image source
│   ├── robots.txt
│   └── sitemap.xml
├── tests/            # vitest: security, extract, search, mcp dispatch, fetcher, worker
├── wrangler.toml
├── package.json
├── tsconfig.json
└── README.md

Develop & deploy

cd mcp
npm install
npm run typecheck
npm test          # vitest — security, extraction, search, MCP dispatch, fetcher, worker
npm run dev        # local worker at http://localhost:8787  (POST /mcp)
npm run deploy     # wrangler deploy

After the first deploy, attach the custom domain mcp.vanshul.com in the Cloudflare dashboard (Workers & Pages → this worker → Settings → Domains), or uncomment the [[routes]] block in wrangler.toml.

Security

  • SSRF-safe: only public http(s) URLs; localhost, private ranges, cloud metadata and every redirect hop are blocked/re-validated.
  • Bounded: 10s fetch timeout, ~3 MB page cap, max 5 redirects, per-IP rate limit.
  • Stateless & private: no page content is stored; extraction is deterministic with no LLM in the loop.

MCP protocol

Implements initialize, ping, tools/list, tools/call and notifications (protocol version 2025-06-18). Tool failures are returned as { content, isError: true } so the agent can read the message and recover; malformed requests use standard JSON-RPC error codes.

Documentation

License

MIT © Vanshul Goyal

Reviews

No reviews yet

Be the first to review this server!