Atlas / MCP servers / lstudlo / Scholar

ScholarSAFE

mcp/lstudlo/scholar-1

ScholarMCP - An academic research MCP server with comprehensive literature search, PDF ingestion, and citation management tools. Integrates with Google Scholar, OpenAlex, Crossref, and Semantic Scholar for automated research workflows.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
10 10r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/scholar-mcp) [](https://github.com/lstudlo/ScholarMCP/actions/workflows/test.yml) [](https://github.com/lstudlo/ScholarMCP/commits/main) [](https://github.com/lstudlo/ScholarMCP/blob/main/LICENSE)

ScholarMCP is an open-source MCP server for academic research. Search Google Scholar, OpenAlex, Crossref, and Semantic Scholar, parse accessible PDFs, and prepare references in your coding agent.

ScholarMCP website and documentation · Installation · Academic paper search guide

Early Development Notice

This project is still in early development, and rough edges or bugs may occur. If you run into a problem, please open an issue and include:

  1. the agent used
  2. screenshots, if applicable
  3. steps to reproduce the issue

ScholarMCP gives your agent tools to:

  • search papers across multiple sources
  • ingest and parse full-text PDFs
  • extract structured paper details
  • suggest citations and build references
  • validate manuscript citations

ScholarMCP is for...

Use this if you want Claude Code, Codex, or any MCP-compatible coding agent to run research tasks directly from chat.

Quick Start

1. Prerequisites

  • Node.js >=20
  • npm (for install/publish)
  • pnpm (for contributors working from source)

2. Install as an npm package (recommended)

npm install -g scholar-mcp

One-off run without global install:

npx -y scholar-mcp --transport=stdio

Install from GitHub Packages (scoped mirror packag

Read from source at commit c0de13c3ed67OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add scholar-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "scholar-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (10)

10 read · 0 write · 0 destructive.

ToolRiskDescription
build_reference_listread
extract_granular_paper_detailsread
get_author_inforead
get_ingestion_statusread
ingest_paper_fulltextread
search_google_scholar_advancedread
search_google_scholar_key_wordsread
search_literature_graphread
suggest_contextual_citationsread
validate_manuscript_citationsread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (4 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/scholar-mcp/src/research/utils.ts:11
const digest = createHash('sha1').update(value).digest('hex').slice(0, 16);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/docs/src/lib/seo.ts:1
import { version } from '../../../../packages/scholar-mcp/package.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/scholar-mcp/src/research/providers/crossref-client.ts:1
import type { AppConfig } from '../../config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/scholar-mcp/src/research/providers/openalex-client.ts:1
import type { AppConfig } from '../../config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/scholar-mcp/src/research/providers/semantic-scholar-client.ts:1
import type { AppConfig } from '../../config.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:77
curl http://127.0.0.1:3000/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:191
2. Connect client to `http://127.0.0.1:3000/mcp`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/docs/src/content/docs/getting-started/quick-start.md:72
curl http://127.0.0.1:3000/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/scholar-mcp/README.md:65
curl http://127.0.0.1:3000/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/scholar-mcp/README.md:134
2. Connect client to `http://127.0.0.1:3000/mcp`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/docs/package.json
@astrojs/sitemap, @tailwindcss/vite, astro, tailwindcss, @astrojs/check, cheerio, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/scholar-mcp/package.json
@citation-js/core, @citation-js/plugin-bibtex, @citation-js/plugin-csl, @citation-js/plugin-doi, @hono/node-server, @modelcontextprotocol/sdk, cheerio, dotenv
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
apps/docs/src/content/docs/index.md:65
The server itself does not require a paid ScholarMCP key. Provider authentication is separate. You can configure OpenAlex and Semantic Scholar API keys, and a contact email for provider requests. Prov
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha c0de13c3ed67full audit observations/trust-audit/mcp-server/lstudlo__scholar-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09c0de13c3ed67SAFEB89first audit
06

Questions

What is the Scholar MCP server?

ScholarMCP - An academic research MCP server with comprehensive literature search, PDF ingestion, and citation management tools. Integrates with Google Scholar, OpenAlex, Crossref, and Semantic Scholar for automated research workflows.

What tools does Scholar expose?

10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Scholar safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Scholar need?

No credential environment variables were found in its source, so it appears to need none.

How does Scholar run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as scholar-mcp at 1.2.0.

How current is this page?

The grade is for one exact copy of the source (c0de13c3ed67), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement