Pubmed SearchCAUTION
MCP PubMed Search Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
search pubmed via MCP
Components
Resources
The server implements a simple note storage system with:
- Custom note:// URI scheme for accessing individual notes
- Each note resource has a name, description and text/plain mimetype
Prompts
The server provides a single prompt:
- summarize-notes: Creates summaries of all stored notes
- Optional "style" argument to control detail level (brief/detailed)
- Generates prompt combining all current notes with style preference
Tools
The server implements one tool:
- add-note: Adds a new note to the server
- Takes "name" and "content" as required string arguments
- Updates server state and notifies clients of resource changes
Configuration
[TODO: Add configuration details specific to your implementation]
Quickstart
Install
Claude Desktop
On MacOS: ~/Library/Application\ Support/Claude/claude_desktop_config.json On Windows: %APPDATA%/Claude/claude_desktop_config.json
Development/Unpublished Servers Configuration
"mcpServers": {
"pubmed_search": {
"command": "uv",
"args": [
"--directory",
"/Users/nofuture/Documents/GitHub/pubmed_search",
"run",
"pubmed_search"
]
}
}Published Servers Configuration
"mcpServers": {
"pubmed_search": {
"command": "uvx",
"args": [
"pubmed_search"
]
}
}Development
Building and Publishing
To prepare the package for distribution:
- Sync dependencies and update lockfile:
uv sync
- Build package distributions:
uv build
This will create source and wheel distributions in the dist/ directory.
- Publish to PyPI:
uv publish
Note: You'll need to set PyPI credentials via environment variables or command flags:
- Token:
--tokenorUV_PUBLISH_TOKEN - Or username/password
491381cd6506OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add pubmed-search -- uvx pubmed-search
{
"mcpServers": {
"pubmed-search": {
"command": "uvx",
"args": [
"pubmed-search"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
pubmed_search | read | Search PubMed medical literature database |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
.DS_Store
.DS_Store
.DS_Store
.DS_Store
pubmed_search.log
Gates applied: no_behavioural_pass.
491381cd6506full audit observations/trust-audit/mcp-server/wavelovey__pubmed-search.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 491381cd6506 | CAUTION | B | 89 | first audit |
Questions
What is the Pubmed Search MCP server?
MCP PubMed Search Server
What tools does Pubmed Search expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Pubmed Search safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Pubmed Search need?
No credential environment variables were found in its source, so it appears to need none.
How does Pubmed Search run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as pubmed-search.
How current is this page?
The grade is for one exact copy of the source (491381cd6506), read on 2026-10-08. The repository is watched and re-audited when it changes.