Atlas / MCP servers / openags / paper-search-mcp

paper-search-mcpBLOCK

mcp/openags/paper-search-mcp

MCP, CLI, Skills for searching and downloading academic papers from multiple sources like arXiv, PubMed, bioRxiv, etc.

Verdict
BLOCK
Grade
D
Trust score
68 /100
Exposed tools
73 72r · 0w · 1d
Transport
sse · stdio · streamable-http
License
MIT
Stars
2,730
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for searching and downloading academic papers from multiple sources. The project follows a free-first strategy: prioritize open and public data sources, support optional API keys when they improve stability or coverage, and keep source-specific connectors extensible for advanced users.

[](https://smithery.ai/server/@openags/paper-search-mcp)

Table of Contents

  • Overview
  • Project Principles
  • MCP Authorization Compatibility
  • Features
  • Source Strategy
  • Sci-Hub Notice
  • Installation
  • Claude Code (Skill)
  • Method 1 — Smithery
  • Method 2 — uvx
  • Method 3 — uv
  • Method 4 — pip
  • Method 5 — npx
  • Method 6 — Docker
  • Method 7 — Clone & run from source
  • DeepSeek Harness (DSH)
  • Environment Variables
  • Contributing
  • Demo
  • Star History
  • License
  • TODO

Overview

paper-search-mcp is a Python-based tool for searching and downloading academic papers from various platforms. It provides tools for searching papers, downloading PDFs, and extracting text, making it ideal for r

Read from source at commit da06f58b26d5OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add paper-search-mcp-dsh --env IEEE_API_KEY=${IEEE_API_KEY} --env PAPER_SEARCH_MCP_IEEE_API_KEY=${PAPER_SEARCH_MCP_IEEE_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "paper-search-mcp-dsh": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "IEEE_API_KEY": "${IEEE_API_KEY}",
        "PAPER_SEARCH_MCP_IEEE_API_KEY": "${PAPER_SEARCH_MCP_IEEE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (73)

72 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
clear_search_cachedestructiveDelete all cached search results at the configured local cache path.
download_acmreadDownload a PDF from ACM Digital Library. dl.acm.org sits behind a
download_arxivreadDownload PDF of an arXiv paper.
download_basereadDownload PDF for a paper from BASE.
download_biorxivreadDownload PDF of a bioRxiv paper.
download_citeseerxreadDownload PDF for a paper from CiteSeerX.
download_crossrefreadAttempt to download PDF of a CrossRef paper.
download_dblpreadDownload PDF for a paper from dblp.
download_doajreadDownload PDF for a paper from DOAJ.
download_halreadDownload PDF for a paper from HAL.
download_iacrreadDownload PDF of an IACR ePrint paper.
download_ieeereadIEEE metadata-only connector: direct PDF download is not implemented.
download_medrxivreadDownload PDF of a medRxiv paper.
download_openairereadDownload PDF for a paper from OpenAIRE.
download_openalexreadDownload PDF for a paper from OpenAlex.
download_openreviewreadDownload a public OpenReview PDF by note ID or official forum URL.
download_pubmedreadAttempt to download PDF of a PubMed paper.
download_scihubreadDownload paper PDF via Sci-Hub (optional fallback connector).
download_semanticreadDownload PDF of a Semantic Scholar paper.
download_ssrnreadDownload PDF for a paper from SSRN.
download_with_fallbackreadTry source-native download, OA repositories, Unpaywall, then optional Sci-Hub.
download_zenodoreadDownload PDF for a paper from Zenodo.
get_citing_papersreadGet one hop of papers citing a DOI or OpenAlex work ID (never a title).
get_crossref_paper_by_doireadGet a specific paper from CrossRef by its DOI.
get_referenced_papersreadGet one hop of papers referenced by a DOI or OpenAlex work ID.
get_search_cache_statusreadShow opt-in local search cache settings and entry count, never query contents.
read_acm_paperreadDownload and read an ACM Digital Library paper.
read_arxiv_paperreadRead and extract text content from an arXiv paper PDF.
read_base_paperreadRead and extract text content from a BASE paper.
read_biorxiv_paperreadRead and extract text content from a bioRxiv paper PDF.
read_citeseerx_paperreadRead and extract text content from a CiteSeerX paper.
read_crossref_paperreadAttempt to read and extract text content from a CrossRef paper.
read_dblp_paperreadAttempt to read and extract text content from a dblp paper.
read_doaj_paperreadRead and extract text content from a DOAJ paper.
read_hal_paperreadRead and extract text content from a HAL paper.
read_iacr_paperreadRead and extract text content from an IACR ePrint paper PDF.
read_ieee_paperreadIEEE metadata-only connector: direct full-text reading is not implemented.
read_medrxiv_paperreadRead and extract text content from a medRxiv paper PDF.
read_openaire_paperreadAttempt to read and extract text content from an OpenAIRE paper.
read_openalex_paperreadAttempt to read and extract text content from an OpenAlex paper.
read_openreview_paperreadDownload, validate and read an anonymously accessible OpenReview PDF.
read_pubmed_paperreadRead and extract text content from a PubMed paper.
read_scopus_paperreadRetrieve Scopus abstract metadata, with explicit ScienceDirect opt-in.
read_semantic_paperreadRead and extract text content from a Semantic Scholar paper.
read_ssrn_paperreadRead paper content from SSRN.
read_zenodo_paperreadRead and extract text content from a Zenodo paper.
search_acmreadSearch ACM Digital Library for papers.
search_arxivreadSearch academic papers from arXiv.
search_basereadSearch academic papers from BASE (Bielefeld Academic Search Engine).
search_biorxivreadSearch academic papers from bioRxiv.
search_citeseerxreadSearch academic papers from CiteSeerX digital library.
search_corereadSearch academic papers from CORE.
search_crossrefreadSearch academic papers from CrossRef database.
search_dblpreadSearch academic papers from dblp computer science bibliography.
search_doajreadSearch academic papers from DOAJ (Directory of Open Access Journals).
search_europepmcreadSearch academic papers from Europe PMC.
search_google_scholarreadSearch academic papers from Google Scholar.
search_halreadSearch academic papers from HAL open archive.
search_iacrreadSearch academic papers from IACR ePrint Archive.
search_ieeereadSearch IEEE Xplore for papers. Requires PAPER_SEARCH_MCP_IEEE_API_KEY (or IEEE_API_KEY).
search_medrxivreadSearch academic papers from medRxiv.
search_openairereadSearch academic papers from OpenAIRE European Open Access infrastructure.
search_openalexreadSearch academic papers from OpenAlex.
search_openreviewreadSearch public OpenReview API v2 papers anonymously (0..1000 results).
search_papersreadUnified top-level search across all configured academic platforms.
search_pmcreadSearch academic papers from PubMed Central (PMC).
search_pubmedreadSearch academic papers from PubMed.
search_scopusreadExplicit Scopus metadata search, never part of
search_semanticreadSearch academic papers from Semantic Scholar.
search_ssrnreadSearch SSRN-indexed metadata through OpenAlex.
search_unpaywallreadLookup a DOI via Unpaywall and return OA metadata.
search_wosreadExplicit Web of Science Starter metadata search; never part of
search_zenodoreadSearch academic papers from Zenodo open repository.
04

Trust audit

BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (23)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
dsh/skills/paper-search/SKILL.md:43
- Many public sources work without API keys; optional keys (Semantic Scholar, CORE, Unpaywall email, ...) live in `~/.config/paper-search-mcp/.env` and are loaded by the server automatically.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
paper_search_mcp/search_cache.py:38
locations = (configured,) if configured is not None else ("~/.netrc", "~/_netrc")
Why it matters. touches a credential store
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
paper_search_mcp/academic_platforms/sci_hub.py:55
response = self.session.get(pdf_url, verify=False, timeout=30)
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
paper_search_mcp/academic_platforms/sci_hub.py:87
response = self.session.get(search_url, verify=False, timeout=20)
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_search_cache.py:88
provider.api_key = "private-credential-one"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_search_cache
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
paper_search_mcp/academic_platforms/sci_hub.py:151
pdf_hash = hashlib.md5(response.content).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
paper_search_mcp/academic_platforms/sci_hub.py:157
pdf_hash = hashlib.md5(response.content).hexdigest()[:8]
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/test_feature_integration.py:210
@pytest.mark.parametrize("location", [".netrc", "_netrc", "custom"])
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/test_openreview.py:210
lookup = Mock(side_effect=AssertionError("Must not read .netrc"))
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/test_ssrn_openalex.py:198
lookup = Mock(side_effect=AssertionError("Must not read .netrc"))
Why it matters. touches a credential store
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_google_scholar.py:55
proxy_searcher = GoogleScholarSearcher(proxy_url="http://127.0.0.1:7890")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_google_scholar.py:56
self.assertEqual(proxy_searcher.session.proxies.get("http"), "http://127.0.0.1:7890")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_google_scholar.py:57
self.assertEqual(proxy_searcher.session.proxies.get("https"), "http://127.0.0.1:7890")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_http_auth.py:134
resource = "http://127.0.0.1:8000/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_http_auth.py:137
configure_env(monkeypatch, OAUTH_ISSUER="http://127.0.0.1:9999/")
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/test_openaire.py:26
verify=False,
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:106
| OpenAlex | ✅ | ❌ | ⚠️ info-only | Open API; free API key improves daily limits |
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:393
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:546
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:627
**API keys**: just follow [Environment Variables](#environment-variables-env-file) — the server auto-loads `~/.config/paper-search-mcp/.env`. DSH deliberately scrubs credential-shaped ambient env vars
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/SEARCH_CACHE.md:58
uncredentialed results are safe to share among server callers; credential checks
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
dsh/README.md:29
DSH deliberately scrubs credential-shaped ambient env vars (and all `DSH_*` vars) from spawned children, so shell exports do **not** reach the server. To forward variables explicitly, override the `mc
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-02 · audit v0.4.1 · source sha da06f58b26d5full audit observations/trust-audit/mcp-server/openags__paper-search-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02da06f58b26d5BLOCKD68first audit
06

Questions

What is the paper-search-mcp MCP server?

MCP, CLI, Skills for searching and downloading academic papers from multiple sources like arXiv, PubMed, bioRxiv, etc.

What tools does paper-search-mcp expose?

73 in total: 72 read-only, 0 that write, and 1 that can delete or overwrite (clear_search_cache). Every one is listed on this page with its risk.

Is paper-search-mcp safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (68/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does paper-search-mcp need?

It reads IEEE_API_KEY and PAPER_SEARCH_MCP_IEEE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does paper-search-mcp run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as paper-search-mcp-dsh at 0.1.4.

How current is this page?

The grade is for one exact copy of the source (da06f58b26d5), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement