Atlas / MCP servers / blazickjp / arxiv-mcp-server

arxiv-mcp-serverSAFE

mcp/blazickjp/arxiv-mcp-server

A local MCP server for agent literature work. Original-LaTeX section reads, BibTeX from arXiv metadata, and topic watches. Papers stay on disk. Search is optional.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio · streamable-http
License
Apache-2.0
Stars
3,181
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/arxiv-mcp-server/) [](https://pypi.org/project/arxiv-mcp-server/) [](LICENSE) [](https://registry.modelcontextprotocol.io/v0.1/servers/io.github.blazickjp%2Farxiv-mcp-server/versions/latest) [](https://github.com/blazickjp/arxiv-mcp-server/actions/workflows/tests.yml) [](https://github.com/blazickjp/arxiv-mcp-server/stargazers)

[](https://vscode.dev/redirect/mcp/install?name=arxiv-mcp-server&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22uvx%22%2C%22args%22%3A%5B%22arxiv-mcp-server%22%5D%7D) [](https://cursor.com/en/install-mcp?name=arxiv-mcp-server&config=eyJ0eXBlIjoic3RkaW8iLCJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJhcnhpdi1tY3Atc2VydmVyIl19) [](https://kiro.dev/launch/mcp/add?name=arxiv-mcp-server&config=%7B%22command%22%3A%22uvx%22%2C%22args%22%3A%5B%22arxiv-mcp-server%22%5D%2C%22disabled%22%3Afalse%2C%22autoApprove%22%3A%5B%5D%7D) [](#claude-code) [](#openai-codex) [![Hermes Agent](https://img.shields.io/badge/H

Read from source at commit 8d2bf88d38edOBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add arxiv-mcp-server -- uvx arxiv-mcp-server==0.7.3 ${ARXIV_STORAGE_PATH}
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (7)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.codex-mcp.json
.codex-mcp.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/test_latex.py:83
links={"escape.tex": "../../secret"},
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:445
"url": "http://127.0.0.1:8080/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_transport.py:114
assert "http://127.0.0.1:9000" in security_settings.allowed_origins
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_transport.py:132
assert middleware._validate_origin("https://127.0.0.1:9000")
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 8d2bf88d38edfull audit observations/trust-audit/mcp-server/blazickjp__arxiv-mcp-server.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-308d2bf88d38edSAFEB89first audit
05

Questions

What is the arxiv-mcp-server MCP server?

A local MCP server for agent literature work. Original-LaTeX section reads, BibTeX from arXiv metadata, and topic watches. Papers stay on disk. Search is optional.

Is arxiv-mcp-server safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does arxiv-mcp-server need?

No credential environment variables were found in its source, so it appears to need none.

How does arxiv-mcp-server run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as arxiv-mcp-server.

How current is this page?

The grade is for one exact copy of the source (8d2bf88d38ed), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement