ArXivSAFE
A local MCP server for agent literature work. Original-LaTeX section reads, BibTeX from arXiv metadata, and topic watches. Papers stay on disk. Search is optional.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pypi.org/project/arxiv-mcp-server/) [](https://pypi.org/project/arxiv-mcp-server/) [](LICENSE) [](https://registry.modelcontextprotocol.io/v0.1/servers/io.github.blazickjp%2Farxiv-mcp-server/versions/latest) [](https://github.com/blazickjp/arxiv-mcp-server/actions/workflows/tests.yml) [](https://github.com/blazickjp/arxiv-mcp-server/stargazers)
[](https://vscode.dev/redirect/mcp/install?name=arxiv-mcp-server&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22uvx%22%2C%22args%22%3A%5B%22arxiv-mcp-server%22%5D%7D) [](https://cursor.com/en/install-mcp?name=arxiv-mcp-server&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJhcnhpdi1tY3Atc2VydmVyIl19) [](https://kiro.dev/launch/mcp/add?name=arxiv-mcp-server&config=%7B%22command%22%3A%22uvx%22%2C%22args%22%3A%5B%22arxiv-mcp-server%22%5D%2C%22disabled%22%3Afalse%2C%22autoApprove%22%3A%5B%5D%7D) [](#claude-code) [](#openai-codex) [ | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
.codex-mcp.json
.pre-commit-config.yaml
links={"escape.tex": "../../secret"},"url": "http://127.0.0.1:8080/mcp"
assert "http://127.0.0.1:9000" in security_settings.allowed_origins
assert middleware._validate_origin("https://127.0.0.1:9000")Gates applied: no_behavioural_pass.
3f0fbe554c8bfull audit observations/trust-audit/mcp-server/blazickjp__arxiv-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | 3f0fbe554c8b | SAFE | B | 89 | source changed, verdict held |
Questions
What is the ArXiv MCP server?
A local MCP server for agent literature work. Original-LaTeX section reads, BibTeX from arXiv metadata, and topic watches. Papers stay on disk. Search is optional.
Is ArXiv safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does ArXiv need?
No credential environment variables were found in its source, so it appears to need none.
How does ArXiv run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as arxiv-mcp-server.
How current is this page?
The grade is for one exact copy of the source (3f0fbe554c8b), read on 2026-09-22. The repository is watched and re-audited when it changes.