Atlas / MCP servers / cookjohn / Zotero

ZoteroCAUTION

mcp/cookjohn/zotero-4

It's a plugin extension in Zotero. Zotero MCP Plugin enables integration between AI assistants and Zotero through MCP. Zotero MCP Plugin 是一个 Zotero 插件,通过 MCP协议实现 AI 助手与 Zotero深度集成。插件支持文献检索、元 数据管理、全文分析和智能问答等功能,让 Claude、ChatGPT 等 AI 工具能够直接访问和操作您的文献库。

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
32 22r · 7w · 3d
Transport
streamable-http
License
MIT
Stars
1,182
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Zotero MCP is an open-source project designed to seamlessly integrate powerful AI capabilities with the leading reference management tool, Zotero, through the Model Context Protocol (MCP). This project consists of two core components: a Zotero plugin and an MCP server, which work together to provide AI assistants (like Claude) with the ability to interact with your local Zotero library. This README is also available in: :cn: 简体中文 | :gb: English. [](https://github.com/cookjohn/zotero-mcp) [](https://www.zotero.org) [](https://nodejs.org) [](https://www.typescriptlang.org) []() [](README.md) [](README-zh.md)

Fork us on Wechat

📚 Project Overview

The Zotero MCP server is a tool server based on the Model Context Protocol that provides seamless integration with the Zotero reference management system for AI applications like Claude Desktop. Through this server, AI assistants can:

  • 🔍 Smart Search: Multi-dimensional library search (title/creator/year/tags/fulltext/semantic) with boolean operators and relevance scoring
  • 📖 Content Extraction: Extract PDF full-text, notes, abstracts, webpage snapshots with fine-grained mode control
  • 📝 Annotation Analysis: Search and analyze PDF highlights and annotations by color, tags, and keywords
  • 📂 Collection Browsing: Browse and search collect
Read from source at commit 8eba39b78299OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add zotero-mcp-plugin -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "zotero-mcp-plugin": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (32)

22 read · 7 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_by_identifierwriteAdd items to Zotero by identifier (DOI, arXiv ID, ISBN, PMID, or ADS bibcode) using Zotero
add_items_to_collectionwriteAdd one or more items to a collection by their item keys.
create_collectionwriteCreate a new collection in the library. Optionally nest it under a parent collection.
delete_collectiondestructiveDelete a collection. WARNING: This is a destructive operation. By default, items in the collection are NOT deleted (only removed from the collection). Set deleteItems=true to also send items to trash.
find_similarreadFind items semantically similar to a given item using AI embeddings. Useful for expanding research from a known relevant paper and discovering thematic clusters.
fulltext_databasereadAccess the cached full-text content database (read-only). Faster than re-extracting from Zotero. Actions: list (cached items), search (find text), get (retrieve content), stats (database info).
get_annotation_by_idreadGet complete content of a specific annotation by ID
get_annotationsreadGet annotations and notes for specific items with color/tag filtering. REQUIRED: provide one of itemKey, annotationId, or annotationIds (use search_library first to find the itemKey; use search_annotations to search by colors/tags across the library). Returns user\
get_annotations_batchreadGet complete content of multiple annotations by IDs
get_attachment_contentreadExtract text content from a specific attachment (PDF, HTML, text files). Returns: {attachmentKey, filename, filePath, contentType, type, content, length, extractionMethod, extractedAt}
get_collection_detailsreadGet detailed information about a specific collection
get_collection_itemsreadGet items in a specific collection
get_collectionsreadGet list of all collections in the library
get_contentreadGet full-text content from PDFs, attachments, notes, and abstracts. May contain OCR artifacts. When user asks for complete text, provide it without summarization.
get_item_abstractreadGet the abstract/summary of a specific item
get_item_detailsreadGet detailed bibliographic metadata for a specific item (title, authors, dates, identifiers, attachments, notes, tags). Use get_content for full text. Suitable for generating citations and references.
get_item_pdf_contentreadExtract text content from PDF attachments
get_librariesreadList all Zotero libraries available in the current client. Returns: [{libraryID, name, libraryType}]
get_subcollectionsreadGet subcollections (child collections) of a specific collection. Use recursive=true to retrieve the full nested hierarchy of all descendant collections.
remove_items_from_collectiondestructiveRemove one or more items from a collection. Items are NOT deleted from the library, only removed from this collection.
search_annotationsreadSearch all notes, PDF annotations and highlights with smart content processing
search_collectionsreadSearch collections by name
search_fulltextreadSearch within fulltext content of items with context and relevance scoring
search_librariesreadSearch libraries by name. Returns: [{libraryID, name, libraryType}]
search_libraryreadSearch the Zotero library with advanced parameters, boolean operators, relevance scoring, and pagination. Results are from user\
semantic_searchreadAI-powered semantic search using embeddings. Finds conceptually related content even without exact keyword matches. Combine with keyword search (search_library, search_fulltext) for comprehensive results.
semantic_statusreadGet the status of the semantic search service including index statistics.
trash_itemwriteMove one or more items to Zotero Trash. Items remain recoverable until the user empties Trash; permanent deletion is not supported.
update_collectionwriteRename or move an existing collection. Provide name to rename, parentCollection to move (empty string moves to top level).
write_metadatawriteUpdate metadata fields on Zotero items (title, abstract, date, URL, DOI, creators, etc.). Only works on regular items, not notes or attachments. Confirm with user before executing.
write_notewriteCreate or modify Zotero notes. Supports child notes (attached to items), standalone notes, updating, or appending. Markdown is auto-converted to HTML. Confirm with user before writing.
write_tagdestructiveAdd, remove, or replace tags on Zotero items. Works on any item type. Response includes before/after tag lists for verification. Confirm with user before executing.
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

MEDIUMInventory / provenance · inv.binary · CWE-1104
zotero-mcp-plugin/zotero-mcp-plugin-tree-1.2.3.xpi
zotero-mcp-plugin-tree-1.2.3.xpi
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_collection, remove_items_from_collection, write_tag
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
zotero-mcp-plugin/.mocharc.json
.mocharc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
zotero-mcp-plugin/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
zotero-mcp-plugin/src/modules/preferenceScript.ts:1
import { config } from "../../package.json";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
zotero-mcp-plugin/src/modules/semanticIndexColumn.ts:8
import { config } from "../../package.json";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
zotero-mcp-plugin/src/modules/serverPreferences.ts:1
import { config } from "../../package.json";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
zotero-mcp-plugin/src/utils/locale.ts:1
import { config } from "../../package.json";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
zotero-mcp-plugin/src/utils/locale.ts:2
import { FluentMessageId } from "../../typings/i10n";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README-zh.md:82
"url": "http://127.0.0.1:23120/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README-zh.md:247
"url": "http://127.0.0.1:23120/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README-zh.md:511
- 确认 URL 格式正确:`http://127.0.0.1:23120/mcp`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:150
"url": "http://127.0.0.1:23120/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
layout-mockup.html:252
http://127.0.0.1:23120/mcp</div></div>
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
zotero-mcp-plugin/src/modules/semantic/vectorStore.ts:1446
const binary = atob(base64);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
zotero-mcp-plugin/package.json
zotero-plugin-toolkit, @types/chai, @types/mocha, @types/node, @zotero-plugin/eslint-config, chai, eslint, mocha
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 8eba39b78299full audit observations/trust-audit/mcp-server/cookjohn__zotero-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-258eba39b78299CAUTIONB86first audit
06

Questions

What is the Zotero MCP server?

It's a plugin extension in Zotero. Zotero MCP Plugin enables integration between AI assistants and Zotero through MCP. Zotero MCP Plugin 是一个 Zotero 插件,通过 MCP协议实现 AI 助手与 Zotero深度集成。插件支持文献检索、元 数据管理、全文分析和智能问答等功能,让 Claude、ChatGPT 等 AI 工具能够直接访问和操作您的文献库。

What tools does Zotero expose?

32 in total: 22 read-only, 7 that write, and 3 that can delete or overwrite (delete_collection, remove_items_from_collection, write_tag). Every one is listed on this page with its risk.

Is Zotero safe to connect to an agent?

With care. The audit graded it B (86/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Zotero need?

No credential environment variables were found in its source, so it appears to need none.

How does Zotero run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as zotero-mcp-plugin at 1.6.0.

How current is this page?

The grade is for one exact copy of the source (8eba39b78299), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement