# Add to your Claude Code skills
git clone https://github.com/jina-ai/MCPGuides for using mcp servers skills like MCP.
Last scanned: 5/9/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@modelcontextprotocol/sdk: @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse",
"severity": "high"
},
{
"type": "npm-audit",
"message": "agents: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to path traversal via percent-encoded dot segments",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono vulnerable to XSS through ErrorBoundary component ",
"severity": "high"
},
{
"type": "npm-audit",
"message": "lodash: Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
"severity": "high"
},
{
"type": "npm-audit",
"message": "miniflare: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "undici: Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client",
"severity": "high"
},
{
"type": "npm-audit",
"message": "wrangler: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "yaml: yaml is vulnerable to Stack Overflow via deeply nested YAML collections",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-09T06:16:31.479Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how MCP compares with popular alternatives.
MCP is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by jina-ai. Official Jina AI Remote MCP Server. It has 876 GitHub stars.
MCP returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/jina-ai/MCP" and add it to your Claude Code skills directory (see the Installation section above).
MCP is primarily written in TypeScript. It is open-source under jina-ai on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh MCP against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A remote Model Context Protocol (MCP) server for the Jina Reader, Search, Embeddings and Reranker APIs:
[!WARNING] Some clients do not support env variable, so you may need to replace
${JINA_API_KEY}below to a hardcoded real API keyjina_xxx.
For client that supports remote MCP server:
{
"mcpServers": {
"jina-mcp-server": {
"url": "https://mcp.jina.ai/v1",
"headers": {
"Authorization": "Bearer ${JINA_API_KEY}" // optional
}
}
}
}
For Claude Code:
claude mcp add -s user --transport http jina https://mcp.jina.ai/v1 \
--header "Authorization: Bearer ${JINA_API_KEY}"
For OpenAI Codex: find ~/.codex/config.toml and add the following:
[mcp_servers.jina-mcp-server]
command = "npx"
args = [
"-y",
"mcp-remote",
"https://mcp.jina.ai/v1",
"--header",
"Authorization: Bearer ${JINA_API_KEY}"]
For client that does not support remote MCP server yet, you need mcp-remote a local proxy to connect to the remote MCP server.
{
"mcpServers": {
"jina-mcp-server": {
"command": "npx",
"args": [
"mcp-remote",
"https://mcp.jina.ai/v1",
"--header",
"Authorization: Bearer ${JINA_API_KEY}"
]
}
}
}
| Tool | Description | Is Jina API Key Required? |
|---|---|---|
primer |
Get current contextual information for localized, time-aware responses | No |
read_url |
Read a web page or PDF as markdown. Pass question for passages instead of the full body via Reader API |
Optional* |
capture_screenshot_url |
Capture a screenshot of a web page via Reader API | Optional* |
guess_datetime_url |
Guess a page's publish or last-update datetime, with a confidence score | No |
search_web |
Search the web. Returns titles, URLs and engine snippets via Reader API | Yes |
search_arxiv |
Search academic papers and preprints on arXiv repository via Reader API | Yes |
search_ssrn |
Search academic papers on SSRN (Social Science Research Network) via Reader API | Yes |
search_images |
Search the web for images via Reader API | Yes |
search_jina_blog |
Search Jina AI news and blog posts at jina.ai/news | No |
sort_by_relevance |
Rerank documents by relevance to a query via Reranker API | Yes |
deduplicate_strings |
Get top-k semantically unique strings via Embeddings API and submodular optimization | Yes |
extract_pdf |
Extract figures, tables, and equations from PDF documents (arXiv papers or any PDF URL) using layout detection | Yes |
Optional tools work without an API key at rate limits. Use a key for higher limits. Free keys: https://jina.ai
Registering a tool costs context tokens for its name, description and schema whether or not it is called. With 12 tools, that budget is spent before the first request.
Filtering server-side through query parameters on the endpoint URL (/v1?...) excludes tools before registration, so the client never sees them.
| Parameter | Description | Example |
|---|---|---|
exclude_tools |
Comma-separated tool names to exclude | exclude_tools=search_web,search_arxiv |
include_tools |
Comma-separated tool names to include | include_tools=read_url,search_web |
exclude_tags |
Comma-separated tags to exclude | exclude_tags=search,rerank |
include_tags |
Comma-separated tags to include | include_tags=search,read |
max_tokens |
Cap read_url response size in tokens. 0 disables truncation |
max_tokens=50000 |
| Tag | Tools |
|---|---|
search |
search_web, search_arxiv, search_ssrn, search_images, search_jina_blog |
read |
read_url, capture_screenshot_url |
utility |
primer, guess_datetime_url, extract_pdf |
rerank |
sort_by_relevance, deduplicate_strings |
Filters are applied in this order (highest to lowest priority):
exclude_tools - Always excludes specified toolsexclude_tags - Excludes tools in specified tagsinclude_tools - Includes specified toolsinclude_tags - Starts with only tools in specified tagsExclude the rerank and utility tags:
{
"mcpServers": {
"jina-mcp-server": {
"url": "https://mcp.jina.ai/v1?exclude_tags=rerank,utility",
"headers": {
"Authorization": "Bearer ${JINA_API_KEY}"
}
}
}
}
Only include search and read tools:
{
"mcpServers": {
"jina-mcp-server": {
"url": "https://mcp.jina.ai/v1?include_tags=search,read",
"headers": {
"Authorization": "Bearer ${JINA_API_KEY}"
}
}
}
}
Exclude specific tools:
{
"mcpServers": {
"jina-mcp-server": {
"url": "https://mcp.jina.ai/v1?exclude_tools=search_ssrn,search_images",
"headers": {
"Authorization": "Bearer ${JINA_API_KEY}"
}
}
}
}
This is a common issue with LMStudio when the default context window is 4096 and you're using a thinking model like gpt-oss-120b or qwen3-4b-thinking. As thinking and tool calling continue, the run hits the context limit, the model loses the start of the task, and it loops.
Load the model with enough context length to hold the whole tool-calling chain.

Some MCP clients have local caching and do not actively update tool definitions. If tools are missing or look outdated, remove and re-add the jina-mcp-server to force a refresh of the cached definitions. In LMStudio, you can click the refresh button to load new tools.

Cursor and Claude Desktop (Windows) have a bug where spaces inside args aren't escaped when it invokes npx, which ends up mangling these values. You can work around it using:
{
// rest of config...
"args": [
"mcp-remote",
"https://mcp.jina.ai/v1",
"--header",
"Authorization:${AUTH_HEADER}" // note no spaces around ':'
],
"env": {
"AUTH_HEADER": "Bearer <JINA_API_KEY>" // spaces OK in env vars
}
},
Likely a Cursor UI bug. The MCP works. Toggling off/on clears the dot; on a remote MCP that restarts the local proxy, not a server.

If all tools are enabled but the model still ignores some, that is expected: models call the tools they were trained on. Some research says LLMs must be trained to use a tool family. In Cursor, add this rule to a .mdc file:
---
alwaysApply: true
---
When you are uncertain about knowledge, or the user doubts your answer, always use Jina MCP tools to search and read best practices and latest information. Use search_arxiv and read_url together when questions relate to theoretical deep learning or algorithm details. Use search_ssrn for social sciences, economics, law, and finance research. search_web, search_arxiv, and search_ssrn cannot be used alone - always follow with read_url on the result URLs. One read_url call can take up to 5 URLs at once.
Claude Code, Claude Desktop, and Cursor enforce a fixed 25k token limit on MCP tool responses. To stop these clients from rejecting a large response outright, this server applies a token guardrail to read_url.
Items are kept whole, in order, while they fit. The first that does not fit is cut to a prefix that does, and later items are dropped. A [jina-mcp] ... note records what was truncated or omitted, so a partial document is marked partial. At least one item always survives, even one over budget.
The server targets below the limit. It counts tokens with cl100k, the client with its own tokenizer, the cut is a proportional character estimate, and the client measures the serialized JSON payload instead of the raw text. It therefore also enforces a ceiling of 3 bytes per allowed token, which holds across tokenizers for ASCII prose (~3.6 bytes/token) and CJK (~3 bytes/token). Cutting short loses part of the content. A rejected response loses all of it.
Any client can set its own budget with max_tokens on the endpoint URL (for example https://mcp.jina.ai/v1?max_tokens=50000), and max_tokens=0 disables truncation entirely. Clients with configurable limits, such as OpenAI Codex (tool_output_token_limit), are otherwise left alone.
search_web, search_arxiv, search_ssrn and read_url take a string or an array on query / url. An array runs every item concurrently in a single round trip. search_images takes one query at a time.
{ "url": ["https://react.dev/reference/react/useState",
"https://docs.python.org/3/library/functions.html"],
"question": "what does the hook or built-in return" }
Arrays cap at 5 entries, enforced by the schema. withAllLinks, withAllImages, question, chunk_size, topk, ocr and page are set once for the whole array, not per entry: every URL in the call gets the same