Atlas / MCP servers / xevos117 / Zotero Assistant

Zotero AssistantSAFE

mcp/xevos117/zotero-assistant

MCP server that exposes Zotero library operations as tools for Claude. Supports searching, browsing collections, adding items by DOI, importing PDFs with fulltext indexing, open access PDF discovery via Unpaywall, and injecting Zotero citation field codes into .docx documents.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
11 6r · 3w · 2d
Transport
stdio
License
NOASSERTION
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Note: This is an unofficial community project and is not affiliated with, endorsed by, or supported by the Zotero team or the Corporation for Digital Scholarship. "Zotero" is a registered trademark of the Corporation for Digital Scholarship.

A Model Context Protocol server for Zotero integration. It gives any LLM full access to your Zotero library: search, organize, add papers by DOI, import PDFs, read full-text content, and inject live citations into Word documents.

Originally based on mcp-zotero by Abhishek Kalia. This project has since been extensively rewritten with a new architecture, 15 tools (up from 5), citation injection, PDF management, and Claude skill support.

How it works

The server is designed to be usable by any LLM without external documentation. On connection, it sends workflow instructions via the MCP instructions field, and each tool description includes cross-references and usage guidance. An LLM that has never seen this server before can discover the full workflow — from adding papers to producing a cited Word document — directly from the tool listing.

For advanced use cases (PDF upload policy, citation style guidance, source transparency), a Claude skill is included for Claude.ai Projects. But the skill is optional: the MCP server is fully self-documenting.

Local vs Remote LLMs

LLMs with filesystem access can use all tools directly, including inject_citations which reads and writes .docx files on disk.

LLMs without filesystem access — including Claude Desktop, which connects to MCP but cannot generate files locally — can use the included Claude skill (`skills/zotero-skill-mcp-i

Read from source at commit 761a952b7ec6OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-zotero --env ZOTERO_API_KEY=${ZOTERO_API_KEY} -- npx -y @xevos117/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-zotero": {
      "command": "npx",
      "args": [
        "-y",
        "@xevos117/[email protected]"
      ],
      "env": {
        "ZOTERO_API_KEY": "${ZOTERO_API_KEY}"
      }
    }
  }
}
03

Exposed tools (11)

6 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_linked_url_attachmentwriteAttach a linked URL to an existing Zotero item, or create a standalone linked-URL attachment. Use this to link external PDFs, web pages, or other resources to items already in your library. If parent_item is provided, the attachment is added as a child; otherwise it is standalone.
create_collectionwriteCreate a new collection (folder) in your Zotero library. Optionally nest it under a parent collection. Returns the new collection key and name. Use the key with add_items_by_doi to organize imported papers.
delete_collectiondestructiveDelete a collection (folder) from your Zotero library. Items inside the collection are NOT deleted — they remain in your library. Requires UNSAFE_OPERATIONS environment variable set to
delete_itemsdestructiveDelete one or more items from your Zotero library permanently (moves to trash). Accepts up to 50 item keys per call. Requires UNSAFE_OPERATIONS environment variable set to
find_and_attach_pdfsreadFor each Zotero item, check Unpaywall for open access PDFs and attach them. Items must have a DOI. Uses the same source as Zotero Desktop
get_collection_itemsreadGet all items in a specific Zotero collection. Returns item keys, titles, authors, and dates. Use the collectionKey from get_collections. Use the returned item keys with get_items_details, get_item_fulltext, or inject_citations.
get_collectionsreadList all collections (folders) in your Zotero library. Returns collection keys, names, and parent relationships. Use collection keys with get_collection_items or as parent_collection in create_collection. Trashed collections are excluded by default.
get_item_fulltextreadGet the full text content of a Zotero item
get_user_idreadReturns the Zotero user ID configured in the server environment. Needed by the standalone inject-citations skill script (inject.js) to generate Zotero field code URIs. Not needed when using the inject_citations MCP tool, which reads the userId internally.
import_pdf_to_zoterowriteDownload a PDF from a URL and upload it to Zotero storage as an imported_url attachment. Unlike linked URL attachments, imported files are stored in Zotero
search_libraryreadSearch your Zotero library or list items sorted by a field. When
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_collection, delete_items
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/utils/pdf-uploader.ts:164
const md5 = createHash("md5").update(buffer).digest("hex");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, fast-xml-parser, jszip, unpdf, zod, zotero-api-client, @types/node
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:5
A Model Context Protocol server for Zotero integration. It gives any LLM full access to your Zotero library: search, organize, add papers by DOI, import PDFs, read full-text content, and inject live c
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:72
| `all` | **Allowed** | **Allowed** | Full access — items and collections can be deleted |

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 761a952b7ec6full audit observations/trust-audit/mcp-server/xevos117__zotero-assistant.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08761a952b7ec6SAFEB89first audit
06

Questions

What is the Zotero Assistant MCP server?

MCP server that exposes Zotero library operations as tools for Claude. Supports searching, browsing collections, adding items by DOI, importing PDFs with fulltext indexing, open access PDF discovery via Unpaywall, and injecting Zotero citation field codes into .docx documents.

What tools does Zotero Assistant expose?

11 in total: 6 read-only, 3 that write, and 2 that can delete or overwrite (delete_collection, delete_items). Every one is listed on this page with its risk.

Is Zotero Assistant safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Zotero Assistant need?

It reads ZOTERO_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Zotero Assistant run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @xevos117/mcp-zotero at 1.0.9.

How current is this page?

The grade is for one exact copy of the source (761a952b7ec6), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement