ZotSeekBLOCK
AI semantic search for Zotero, with a built-in MCP server for AI agents (Claude Code, Codex). Find papers by meaning. 100% local and private.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Find similar papers by meaning, not just keywords. 100% local, no data leaves your machine. Now with a built-in MCP server for AI agents.
Status: ✅ Stable release · Zotero 8, 9 & 10 · Transformers.js running locally New: 🤖 MCP server built in — Claude Code, Codex, and any MCP client can search your library and cite papers with links that open straight to the matched PDF page. Fully local, read-only, opt-in. Set it up in one line → New from the same author: 🔎 **citefact** — audit your manuscript against your Zotero library: citations exist, quotes are verbatim, claims are supported.
Features
- 🔒 100% Local - No data sent to cloud, works completely offline
- 🧠 True Semantic Search - Find papers by meaning, not just keywords
- 🤖 AI Agent Access (MCP) - Let Claude Code and other MCP clients search your library, fully local and opt-in (docs)
- 🔍 Find Similar Documents - Right-click any paper → discover related research
- 📖 Search from PDF Selection - Select text while reading → right-click → find documents about that concept
- 🔎 Natural Language Search - Search with queries like "machine learning in healthcare"
- 🔀 Multi-Query Search - Combine up to 4 queries with AND/OR logic to find topic intersections
- 📝 Your Notes, Searched Too - Optionally index the text of notes attached to an item, so what you wrote is findable alongside the paper itself; off by default, and existing items are back-filled on demand
- 🕘 Recent Searches - The search window remembers your last 10 queries, so you can go back to a phrasing that worked; clear the list from the dropdown at any time
- 🔗 Hybrid Search - Combines AI and keyword search, with the keyword half reading PDF text and note content, not
51c2ed268e21OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add zotseek -- npx -y [email protected]
{
"mcpServers": {
"zotseek": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
find_similar | read | Find papers similar to a known library item, using its stored |
index_status | read | Report ZotSeek index status: number of indexed papers, total chunks, |
search | read | Semantic search over the user |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
function Ec(a){return Sd(b=>{a().then(b)})}function Lb(a){a>>>=0;return Ec(async()=>{var b=await W(a);return X(b)})}var Xd=[];function Mb(a,b,c,d){c>>>=0;d>>>=0;a=Xd[a>>>0];b=W(b>>>0);return a(null,b,assertTrue(!isAllowedHfPath('evil/exfiltrator'), 'should reject non-registry hfPath');<html:input type="text" id="zotseek-server-url" placeholder="http://127.0.0.1:1234" style="width: 220px;" />
baseUrl?: string; // e.g. 'http://127.0.0.1:1234' (loopback enforced at request time)
const resp = await fetch(`http://127.0.0.1:${port}/zotseek/mcp`, {import { handleMcpRequest } from '../../server/mcp-endpoint';import { handleSearchRequest, handleStatsRequest } from '../../server/rest-endpoints';import { handleOpenRequest, parseOpenParams, buildZoteroUri } from '../../server/open-endpoint';import { registerEndpoints, isRegistered, unregisterEndpoints } from '../../server/server-manager';import { searchEngine } from '../../core/search-engine';2. In Zotero, go to **Settings → ZotSeek → Local inference server** and enter the server URL, e.g. `http://127.0.0.1:1234`.
2. In **Settings → ZotSeek → Local inference server**, enter `http://127.0.0.1:11434`.
const binary = atob(data);
@huggingface/transformers, zotero-plugin-toolkit, @types/node, archiver, bumpp, esbuild, typescript
content/wasm/ort-wasm-simd-threaded.jsep.wasm
# Add to ~/.zshrc or ~/.bashrc
Gates applied: no_behavioural_pass, no_license.
51c2ed268e21full audit observations/trust-audit/mcp-server/introfini__zotseek.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 51c2ed268e21 | BLOCK | D | 69 | first audit |
Questions
What is the ZotSeek MCP server?
AI semantic search for Zotero, with a built-in MCP server for AI agents (Claude Code, Codex). Find papers by meaning. 100% local and private.
What tools does ZotSeek expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ZotSeek safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does ZotSeek need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (51c2ed268e21), read on 2026-10-06. The repository is watched and re-audited when it changes.