MedicalSAFE
An MCP server that provides comprehensive medical information by querying multiple authoritative medical APIs including FDA, WHO, PubMed, Google Scholar, and RxNorm
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Bring trusted medical data directly into your AI workflow. A local server for private, free access to FDA, WHO, PubMed, RxNorm, Semantic Scholar, and Google Scholar. No API keys. No data leaks.
An MCP (Model Context Protocol) server that brings authoritative medical information into AI coding environments like Cursor and Claude Desktop.
[](https://archestra.ai/mcp-catalog/jamesanz__medical-mcp)
Why Use Medical MCP?
- 🔒 Your Data Never Leaves – Runs 100% locally; no tracking, no logs, no cloud
- 🆓 No API Keys – Works out of the box, zero configuration
- 🏥 Authoritative Sources – FDA, TGA, Health Canada, EMA, DailyMed, WHO, PubMed, RxNorm, ClinicalTrials.gov
- ⚡ Easy Setup – One-click install in Cursor or simple manual setup
- 🔬 Comprehensive – Drug info, health stats, medical literature, clinical guidelines, pediatric sources
- 🛡️ Resilient – Circuit breakers, retry with backoff, rate limiting, and automatic fallbacks
- 📊 Evidence-Graded – Results tagged with study type and evidence level (Meta-Analysis → Case Report). Tags are automatic labels from the title and abstract, not independently checked grades.
- 🏥 Health Monitoring – Built-in health check tool to diagnose source availability
What's New in v2.0
- Resilience Layer – Circuit breakers per source, retry with exponential backoff + jitter, per-source token bucket rate limiters
- Monid web search – Scholar, AAP, and PMC HTML go through Monid TinyFish (Tavily-style search/fetch). Semantic Scholar is the no-key fallback
- Evidence Grading – PubMed and multi-database results tagged with study type (
7c8c15b1c1f8OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add medical-mcp --env MONID_API_KEY=${MONID_API_KEY} --env NCBI_API_KEY=${NCBI_API_KEY} --env TINYFISH_API_KEY=${TINYFISH_API_KEY} --env TYPESAFE_API_KEY=${TYPESAFE_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"medical-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MONID_API_KEY": "${MONID_API_KEY}",
"NCBI_API_KEY": "${NCBI_API_KEY}",
"TINYFISH_API_KEY": "${TINYFISH_API_KEY}",
"TYPESAFE_API_KEY": "${TYPESAFE_API_KEY}"
}
}
}
}Exposed tools (17)
17 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get-article-details | read | Get detailed information about a specific medical article by PMID. Full text is attached only when the PMC record |
get-cache-stats | read | Get cache statistics including hit rate, total entries, and memory usage |
get-health-statistics | read | Get health statistics and indicators from WHO Global Health Observatory |
health-check | read | Check the health and availability of all upstream data sources (FDA, TGA, Health Canada, EMA, PubMed, WHO, RxNorm, ClinicalTrials, Semantic Scholar, TinyFish). Reports build string, latency, circuit breaker states, and cache health. |
list-sources | read | List medical data sources and which MCP tools reach them. Includes registry adapters and dedicated-tool sources (WHO, PubMed, RxNorm, Scholar). Not limited to the search-drugs regulator fanout. |
rank-search-hits | read | Reorder already-fetched literature hits for a clinical question. Retrieval ranking only — never diagnoses, doses, or advises. |
search-clinical-guidelines | read | Search for clinical guidelines and practice recommendations from medical organizations |
search-clinical-trials | read | Search ClinicalTrials.gov for trials by condition, intervention, or drug |
search-drug-nomenclature | read | Search for drug information using RxNorm (standardized drug nomenclature) |
search-drug-safety | read | Search pharmacovigilance data: FDA FAERS adverse events, recalls, and drug shortages |
search-drugs | read | Search national drug regulators (FDA, DailyMed, TGA, Health Canada, EMA). Defaults to US, AU, CA, and EU. Pass countries: [ |
search-google-scholar | read | Search for academic research articles using Google Scholar |
search-medical-journals | read | Search specific medical journals (NEJM, JAMA, Lancet, BMJ, Nature Medicine) for high-quality research |
search-medical-literature | read | Search for medical research articles in PubMed. Optional question/rerank reorders hits for the question (retrieval only — not diagnosis or advice). |
search-pediatric-drugs | read | Search for drugs with pediatric labeling and dosing information from FDA database |
search-pediatric-guidelines | read | Search AAP pediatric guidelines. Policy statements and clinical reports come from PubMed (Pediatrics / AAP corporate author). Bright Futures and publications.aap.org web hits are kept only if the URL is on an AAP host with a real article path. |
search-pediatric-literature | read | Search for research articles in major pediatric journals (Pediatrics, JAMA Pediatrics, etc.). Optional question/rerank reorders hits for the question (retrieval only — not diagnosis or advice). |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
import type { EvidenceTag } from "../../utils/evidence-grading.js";import { CLINICALTRIALS_API_BASE, USER_AGENT } from "../../constants.js";import { logger } from "../../logger.js";import { resilientCall } from "../../resilience/index.js";} from "../../validation/schemas.js";
lnbc1pjhhsqepp5mjgwnvg0z53shm22hfe9us289lnaqkwv8rn2s0rtekg5vvj56xnqdqqcqzzsxqyz5vqsp5gu6vh9hyp94c7t3tkpqrp2r059t4vrw7ps78a4n0a2u52678c7yq9qyyssq7zcferywka50wcy75skjfrdrk930cuyx24rg55cwfuzxs49rc9c53mpz
@modelcontextprotocol/sdk, cors, express, superagent, zod, @types/cors, @types/express, @types/jest
Gates applied: no_behavioural_pass.
7c8c15b1c1f8full audit observations/trust-audit/mcp-server/jamesanz__medical.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 7c8c15b1c1f8 | SAFE | B | 89 | first audit |
Questions
What is the Medical MCP server?
An MCP server that provides comprehensive medical information by querying multiple authoritative medical APIs including FDA, WHO, PubMed, Google Scholar, and RxNorm
What tools does Medical expose?
17 in total: 17 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Medical safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Medical need?
It reads MONID_API_KEY, NCBI_API_KEY, TINYFISH_API_KEY and TYPESAFE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Medical run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as medical-mcp at 2.1.0.
How current is this page?
The grade is for one exact copy of the source (7c8c15b1c1f8), read on 2026-10-07. The repository is watched and re-audited when it changes.