paper-search-mcpBLOCK
MCP, CLI, Skills for searching and downloading academic papers from multiple sources like arXiv, PubMed, bioRxiv, etc.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for searching and downloading academic papers from multiple sources. The project follows a free-first strategy: prioritize open and public data sources, support optional API keys when they improve stability or coverage, and keep source-specific connectors extensible for advanced users.
[](https://smithery.ai/server/@openags/paper-search-mcp)
Table of Contents
- Overview
- Project Principles
- MCP Authorization Compatibility
- Features
- Source Strategy
- Sci-Hub Notice
- Installation
- Claude Code (Skill)
- Method 1 — Smithery
- Method 2 — uvx
- Method 3 — uv
- Method 4 — pip
- Method 5 — npx
- Method 6 — Docker
- Method 7 — Clone & run from source
- DeepSeek Harness (DSH)
- Environment Variables
- Contributing
- Demo
- Star History
- License
- TODO
Overview
paper-search-mcp is a Python-based tool for searching and downloading academic papers from various platforms. It provides tools for searching papers, downloading PDFs, and extracting text, making it ideal for r
da06f58b26d5OBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add paper-search-mcp-dsh --env IEEE_API_KEY=${IEEE_API_KEY} --env PAPER_SEARCH_MCP_IEEE_API_KEY=${PAPER_SEARCH_MCP_IEEE_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"paper-search-mcp-dsh": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"IEEE_API_KEY": "${IEEE_API_KEY}",
"PAPER_SEARCH_MCP_IEEE_API_KEY": "${PAPER_SEARCH_MCP_IEEE_API_KEY}"
}
}
}
}Exposed tools (73)
72 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
clear_search_cache | destructive | Delete all cached search results at the configured local cache path. |
download_acm | read | Download a PDF from ACM Digital Library. dl.acm.org sits behind a |
download_arxiv | read | Download PDF of an arXiv paper. |
download_base | read | Download PDF for a paper from BASE. |
download_biorxiv | read | Download PDF of a bioRxiv paper. |
download_citeseerx | read | Download PDF for a paper from CiteSeerX. |
download_crossref | read | Attempt to download PDF of a CrossRef paper. |
download_dblp | read | Download PDF for a paper from dblp. |
download_doaj | read | Download PDF for a paper from DOAJ. |
download_hal | read | Download PDF for a paper from HAL. |
download_iacr | read | Download PDF of an IACR ePrint paper. |
download_ieee | read | IEEE metadata-only connector: direct PDF download is not implemented. |
download_medrxiv | read | Download PDF of a medRxiv paper. |
download_openaire | read | Download PDF for a paper from OpenAIRE. |
download_openalex | read | Download PDF for a paper from OpenAlex. |
download_openreview | read | Download a public OpenReview PDF by note ID or official forum URL. |
download_pubmed | read | Attempt to download PDF of a PubMed paper. |
download_scihub | read | Download paper PDF via Sci-Hub (optional fallback connector). |
download_semantic | read | Download PDF of a Semantic Scholar paper. |
download_ssrn | read | Download PDF for a paper from SSRN. |
download_with_fallback | read | Try source-native download, OA repositories, Unpaywall, then optional Sci-Hub. |
download_zenodo | read | Download PDF for a paper from Zenodo. |
get_citing_papers | read | Get one hop of papers citing a DOI or OpenAlex work ID (never a title). |
get_crossref_paper_by_doi | read | Get a specific paper from CrossRef by its DOI. |
get_referenced_papers | read | Get one hop of papers referenced by a DOI or OpenAlex work ID. |
get_search_cache_status | read | Show opt-in local search cache settings and entry count, never query contents. |
read_acm_paper | read | Download and read an ACM Digital Library paper. |
read_arxiv_paper | read | Read and extract text content from an arXiv paper PDF. |
read_base_paper | read | Read and extract text content from a BASE paper. |
read_biorxiv_paper | read | Read and extract text content from a bioRxiv paper PDF. |
read_citeseerx_paper | read | Read and extract text content from a CiteSeerX paper. |
read_crossref_paper | read | Attempt to read and extract text content from a CrossRef paper. |
read_dblp_paper | read | Attempt to read and extract text content from a dblp paper. |
read_doaj_paper | read | Read and extract text content from a DOAJ paper. |
read_hal_paper | read | Read and extract text content from a HAL paper. |
read_iacr_paper | read | Read and extract text content from an IACR ePrint paper PDF. |
read_ieee_paper | read | IEEE metadata-only connector: direct full-text reading is not implemented. |
read_medrxiv_paper | read | Read and extract text content from a medRxiv paper PDF. |
read_openaire_paper | read | Attempt to read and extract text content from an OpenAIRE paper. |
read_openalex_paper | read | Attempt to read and extract text content from an OpenAlex paper. |
read_openreview_paper | read | Download, validate and read an anonymously accessible OpenReview PDF. |
read_pubmed_paper | read | Read and extract text content from a PubMed paper. |
read_scopus_paper | read | Retrieve Scopus abstract metadata, with explicit ScienceDirect opt-in. |
read_semantic_paper | read | Read and extract text content from a Semantic Scholar paper. |
read_ssrn_paper | read | Read paper content from SSRN. |
read_zenodo_paper | read | Read and extract text content from a Zenodo paper. |
search_acm | read | Search ACM Digital Library for papers. |
search_arxiv | read | Search academic papers from arXiv. |
search_base | read | Search academic papers from BASE (Bielefeld Academic Search Engine). |
search_biorxiv | read | Search academic papers from bioRxiv. |
search_citeseerx | read | Search academic papers from CiteSeerX digital library. |
search_core | read | Search academic papers from CORE. |
search_crossref | read | Search academic papers from CrossRef database. |
search_dblp | read | Search academic papers from dblp computer science bibliography. |
search_doaj | read | Search academic papers from DOAJ (Directory of Open Access Journals). |
search_europepmc | read | Search academic papers from Europe PMC. |
search_google_scholar | read | Search academic papers from Google Scholar. |
search_hal | read | Search academic papers from HAL open archive. |
search_iacr | read | Search academic papers from IACR ePrint Archive. |
search_ieee | read | Search IEEE Xplore for papers. Requires PAPER_SEARCH_MCP_IEEE_API_KEY (or IEEE_API_KEY). |
search_medrxiv | read | Search academic papers from medRxiv. |
search_openaire | read | Search academic papers from OpenAIRE European Open Access infrastructure. |
search_openalex | read | Search academic papers from OpenAlex. |
search_openreview | read | Search public OpenReview API v2 papers anonymously (0..1000 results). |
search_papers | read | Unified top-level search across all configured academic platforms. |
search_pmc | read | Search academic papers from PubMed Central (PMC). |
search_pubmed | read | Search academic papers from PubMed. |
search_scopus | read | Explicit Scopus metadata search, never part of |
search_semantic | read | Search academic papers from Semantic Scholar. |
search_ssrn | read | Search SSRN-indexed metadata through OpenAlex. |
search_unpaywall | read | Lookup a DOI via Unpaywall and return OA metadata. |
search_wos | read | Explicit Web of Science Starter metadata search; never part of |
search_zenodo | read | Search academic papers from Zenodo open repository. |
Trust audit
BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (23)
- Many public sources work without API keys; optional keys (Semantic Scholar, CORE, Unpaywall email, ...) live in `~/.config/paper-search-mcp/.env` and are loaded by the server automatically.
locations = (configured,) if configured is not None else ("~/.netrc", "~/_netrc")response = self.session.get(pdf_url, verify=False, timeout=30)
response = self.session.get(search_url, verify=False, timeout=20)
provider.api_key = "private-credential-one"
clear_search_cache
pdf_hash = hashlib.md5(response.content).hexdigest()[:8]
pdf_hash = hashlib.md5(response.content).hexdigest()[:8]
@pytest.mark.parametrize("location", [".netrc", "_netrc", "custom"])lookup = Mock(side_effect=AssertionError("Must not read .netrc"))lookup = Mock(side_effect=AssertionError("Must not read .netrc"))proxy_searcher = GoogleScholarSearcher(proxy_url="http://127.0.0.1:7890")
self.assertEqual(proxy_searcher.session.proxies.get("http"), "http://127.0.0.1:7890")self.assertEqual(proxy_searcher.session.proxies.get("https"), "http://127.0.0.1:7890")resource = "http://127.0.0.1:8000/mcp"
configure_env(monkeypatch, OAUTH_ISSUER="http://127.0.0.1:9999/")
verify=False,
| OpenAlex | ✅ | ❌ | ⚠️ info-only | Open API; free API key improves daily limits |
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
**API keys**: just follow [Environment Variables](#environment-variables-env-file) — the server auto-loads `~/.config/paper-search-mcp/.env`. DSH deliberately scrubs credential-shaped ambient env vars
uncredentialed results are safe to share among server callers; credential checks
DSH deliberately scrubs credential-shaped ambient env vars (and all `DSH_*` vars) from spawned children, so shell exports do **not** reach the server. To forward variables explicitly, override the `mc
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
da06f58b26d5full audit observations/trust-audit/mcp-server/openags__paper-search-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | da06f58b26d5 | BLOCK | D | 68 | first audit |
Questions
What is the paper-search-mcp MCP server?
MCP, CLI, Skills for searching and downloading academic papers from multiple sources like arXiv, PubMed, bioRxiv, etc.
What tools does paper-search-mcp expose?
73 in total: 72 read-only, 0 that write, and 1 that can delete or overwrite (clear_search_cache). Every one is listed on this page with its risk.
Is paper-search-mcp safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (68/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does paper-search-mcp need?
It reads IEEE_API_KEY and PAPER_SEARCH_MCP_IEEE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does paper-search-mcp run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as paper-search-mcp-dsh at 0.1.4.
How current is this page?
The grade is for one exact copy of the source (da06f58b26d5), read on 2026-10-02. The repository is watched and re-audited when it changes.