PubmedBLOCK
Search PubMed/Europe PMC, fetch articles and full text (PMC/EPMC/Unpaywall), citations, MeSH terms via MCP. STDIO or Streamable HTTP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
@cyanheads/pubmed-mcp-server Search PubMed/Europe PMC, fetch articles and full text (PMC/EPMC/Unpaywall), citations, MeSH terms via MCP. STDIO or Streamable HTTP. 11 Tools • 1 Resource • 1 Prompt
[](./CHANGELOG.md) [](./LICENSE) [](https://github.com/users/cyanheads/packages/container/package/pubmed-mcp-server) [](https://modelcontextprotocol.io/) [](https://www.npmjs.com/package/@cyanheads/pubmed-mcp-server) [](https://www.typescriptlang.org/) [](https://bun.sh/)
[](https://github.com/cyanheads/pubmed-mcp-server/releases/latest/download/pubmed-mcp-server.mcpb) [](https://cursor.com/en/install-mcp?name=pubmed-mcp-server&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBjeWFuaGVhZHMvcHVibWVkLW1jcC1zZXJ2ZXIiXX0=) [](https://vscode.dev/redirect?url=vscode:mcp/install?%7B%22name%22%3A%22pubmed-mcp-server%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40cya
61789d23cbbeOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add pubmed-mcp-server -- npx -y @cyanheads/[email protected]
claude mcp add pubmed-mcp-server -- npx -y @cyanheads/[email protected]
Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
database-info | write | PubMed database metadata including field list, last update date, and record count. |
Trust audit
BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
const tsc = await exec([join(ROOT_DIR, 'node_modules', '.bin', 'tsc'), '-p', project], 'tsc');
const alias = await exec(
exec(cmd: string[], options: { cwd: string }): Promise<ShellResult> {':(glob)**/.netrc',
| **Server credential** | The server's own upstream key is missing, or the upstream rejects it (401/403) | `ConfigurationError` — translated in the service, since the automatic status mapping yields `
Prereq: a GitHub PAT with `read:org` + `read:user` scopes stored in Keychain under the service name `mcp-publisher-github-pat`:
2. **No `git stash`, no `git reset --hard`, no `git restore .`, no `git clean -f`, no `git checkout -- .`.** These bypass safety and risk silent data loss. Read-only git (`status`, `diff`, `log`, `sho
'NCBI\'s note on the link, e.g. what an erratum corrected ("Fuβer, Fabian [corrected to Fußer, Fabian]"). Absent unless NCBI supplies one.',.mcpbignore
import { textMessages } from '../../../_helpers.js';} from '../../../services/ncbi/parsing/_book-fixtures.js';
import { PUBLISHED_ERRATUM_XML } from '../../../services/ncbi/parsing/_comments-corrections-fixtures.js';import { textBlocks } from '../../../_helpers.js';import { textBlocks } from '../../../_helpers.js';note: 'Fuβer, Fabian [corrected to Fußer, Fabian]',
'- **ErratumIn:** PLoS One. 2013;8(6). doi:10.1371/annotation/df743c15-c50e-4d00-a24d-510e15f9a73b — Note: Fuβer, Fabian \\[corrected to Fußer, Fabian\\]',
note: 'Fuβer, Fabian [corrected to Fußer, Fabian]',
el('mml:math', [t('ηcrit')]),['a zero-width space (U+200B)', ''],
['a word joiner (U+2060)', ''],
['zero-width non-joiner and joiner (U+200C, U+200D)', ''],
['a byte-order mark (U+FEFF)', ''],
['format characters between spaces', ' \u0085 '],
@cyanheads/mcp-ts-core, defuddle, fast-xml-parser, linkedom, pino-pretty, sanitize-html, unpdf, zod
- [ ] `.codex-plugin/mcp.json` updated — server name key is the unscoped repo name; every user-supplied variable (API key, contact email, instance URL) is listed in `env_vars` so Codex forwards it fro
Gates applied: instruction_override, no_behavioural_pass.
61789d23cbbefull audit observations/trust-audit/mcp-server/cyanheads__pubmed-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 61789d23cbbe | BLOCK | F | 40 | first audit |
Questions
What is the Pubmed MCP server?
Search PubMed/Europe PMC, fetch articles and full text (PMC/EPMC/Unpaywall), citations, MeSH terms via MCP. STDIO or Streamable HTTP.
What tools does Pubmed expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Pubmed safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (40/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Pubmed need?
It reads NCBI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Pubmed run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @cyanheads/pubmed-mcp-server at 2.10.20.
How current is this page?
The grade is for one exact copy of the source (61789d23cbbe), read on 2026-10-07. The repository is watched and re-audited when it changes.