ZoteroCAUTION
It's a plugin extension in Zotero. Zotero MCP Plugin enables integration between AI assistants and Zotero through MCP. Zotero MCP Plugin 是一个 Zotero 插件,通过 MCP协议实现 AI 助手与 Zotero深度集成。插件支持文献检索、元 数据管理、全文分析和智能问答等功能,让 Claude、ChatGPT 等 AI 工具能够直接访问和操作您的文献库。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Zotero MCP is an open-source project designed to seamlessly integrate powerful AI capabilities with the leading reference management tool, Zotero, through the Model Context Protocol (MCP). This project consists of two core components: a Zotero plugin and an MCP server, which work together to provide AI assistants (like Claude) with the ability to interact with your local Zotero library. This README is also available in: :cn: 简体中文 | :gb: English. [](https://github.com/cookjohn/zotero-mcp) [](https://www.zotero.org) [](https://nodejs.org) [](https://www.typescriptlang.org) []() [](README.md) [](README-zh.md)
Fork us on Wechat
📚 Project Overview
The Zotero MCP server is a tool server based on the Model Context Protocol that provides seamless integration with the Zotero reference management system for AI applications like Claude Desktop. Through this server, AI assistants can:
- 🔍 Smart Search: Multi-dimensional library search (title/creator/year/tags/fulltext/semantic) with boolean operators and relevance scoring
- 📖 Content Extraction: Extract PDF full-text, notes, abstracts, webpage snapshots with fine-grained mode control
- 📝 Annotation Analysis: Search and analyze PDF highlights and annotations by color, tags, and keywords
- 📂 Collection Browsing: Browse and search collect
8eba39b78299OBSERVED · 2026-09-25Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add zotero-mcp-plugin -- npx -y [email protected]
{
"mcpServers": {
"zotero-mcp-plugin": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (32)
22 read · 7 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_by_identifier | write | Add items to Zotero by identifier (DOI, arXiv ID, ISBN, PMID, or ADS bibcode) using Zotero |
add_items_to_collection | write | Add one or more items to a collection by their item keys. |
create_collection | write | Create a new collection in the library. Optionally nest it under a parent collection. |
delete_collection | destructive | Delete a collection. WARNING: This is a destructive operation. By default, items in the collection are NOT deleted (only removed from the collection). Set deleteItems=true to also send items to trash. |
find_similar | read | Find items semantically similar to a given item using AI embeddings. Useful for expanding research from a known relevant paper and discovering thematic clusters. |
fulltext_database | read | Access the cached full-text content database (read-only). Faster than re-extracting from Zotero. Actions: list (cached items), search (find text), get (retrieve content), stats (database info). |
get_annotation_by_id | read | Get complete content of a specific annotation by ID |
get_annotations | read | Get annotations and notes for specific items with color/tag filtering. REQUIRED: provide one of itemKey, annotationId, or annotationIds (use search_library first to find the itemKey; use search_annotations to search by colors/tags across the library). Returns user\ |
get_annotations_batch | read | Get complete content of multiple annotations by IDs |
get_attachment_content | read | Extract text content from a specific attachment (PDF, HTML, text files). Returns: {attachmentKey, filename, filePath, contentType, type, content, length, extractionMethod, extractedAt} |
get_collection_details | read | Get detailed information about a specific collection |
get_collection_items | read | Get items in a specific collection |
get_collections | read | Get list of all collections in the library |
get_content | read | Get full-text content from PDFs, attachments, notes, and abstracts. May contain OCR artifacts. When user asks for complete text, provide it without summarization. |
get_item_abstract | read | Get the abstract/summary of a specific item |
get_item_details | read | Get detailed bibliographic metadata for a specific item (title, authors, dates, identifiers, attachments, notes, tags). Use get_content for full text. Suitable for generating citations and references. |
get_item_pdf_content | read | Extract text content from PDF attachments |
get_libraries | read | List all Zotero libraries available in the current client. Returns: [{libraryID, name, libraryType}] |
get_subcollections | read | Get subcollections (child collections) of a specific collection. Use recursive=true to retrieve the full nested hierarchy of all descendant collections. |
remove_items_from_collection | destructive | Remove one or more items from a collection. Items are NOT deleted from the library, only removed from this collection. |
search_annotations | read | Search all notes, PDF annotations and highlights with smart content processing |
search_collections | read | Search collections by name |
search_fulltext | read | Search within fulltext content of items with context and relevance scoring |
search_libraries | read | Search libraries by name. Returns: [{libraryID, name, libraryType}] |
search_library | read | Search the Zotero library with advanced parameters, boolean operators, relevance scoring, and pagination. Results are from user\ |
semantic_search | read | AI-powered semantic search using embeddings. Finds conceptually related content even without exact keyword matches. Combine with keyword search (search_library, search_fulltext) for comprehensive results. |
semantic_status | read | Get the status of the semantic search service including index statistics. |
trash_item | write | Move one or more items to Zotero Trash. Items remain recoverable until the user empties Trash; permanent deletion is not supported. |
update_collection | write | Rename or move an existing collection. Provide name to rename, parentCollection to move (empty string moves to top level). |
write_metadata | write | Update metadata fields on Zotero items (title, abstract, date, URL, DOI, creators, etc.). Only works on regular items, not notes or attachments. Confirm with user before executing. |
write_note | write | Create or modify Zotero notes. Supports child notes (attached to items), standalone notes, updating, or appending. Markdown is auto-converted to HTML. Confirm with user before writing. |
write_tag | destructive | Add, remove, or replace tags on Zotero items. Works on any item type. Response includes before/after tag lists for verification. Confirm with user before executing. |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
zotero-mcp-plugin-tree-1.2.3.xpi
delete_collection, remove_items_from_collection, write_tag
streamable-http
.mocharc.json
.prettierignore
import { config } from "../../package.json";import { config } from "../../package.json";import { config } from "../../package.json";import { config } from "../../package.json";import { FluentMessageId } from "../../typings/i10n";"url": "http://127.0.0.1:23120/mcp"
"url": "http://127.0.0.1:23120/mcp"
- 确认 URL 格式正确:`http://127.0.0.1:23120/mcp`
"url": "http://127.0.0.1:23120/mcp"
http://127.0.0.1:23120/mcp</div></div>
const binary = atob(base64);
zotero-plugin-toolkit, @types/chai, @types/mocha, @types/node, @zotero-plugin/eslint-config, chai, eslint, mocha
Gates applied: no_behavioural_pass.
8eba39b78299full audit observations/trust-audit/mcp-server/cookjohn__zotero-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | 8eba39b78299 | CAUTION | B | 86 | first audit |
Questions
What is the Zotero MCP server?
It's a plugin extension in Zotero. Zotero MCP Plugin enables integration between AI assistants and Zotero through MCP. Zotero MCP Plugin 是一个 Zotero 插件,通过 MCP协议实现 AI 助手与 Zotero深度集成。插件支持文献检索、元 数据管理、全文分析和智能问答等功能,让 Claude、ChatGPT 等 AI 工具能够直接访问和操作您的文献库。
What tools does Zotero expose?
32 in total: 22 read-only, 7 that write, and 3 that can delete or overwrite (delete_collection, remove_items_from_collection, write_tag). Every one is listed on this page with its risk.
Is Zotero safe to connect to an agent?
With care. The audit graded it B (86/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Zotero need?
No credential environment variables were found in its source, so it appears to need none.
How does Zotero run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as zotero-mcp-plugin at 1.6.0.
How current is this page?
The grade is for one exact copy of the source (8eba39b78299), read on 2026-09-25. The repository is watched and re-audited when it changes.