Atlas / Skills / brycewang-stanford / Mendeley Api

Mendeley ApiBLOCK

skills/brycewang-stanford/mendeley-api

🔬 A curated collection of 23,000+ agent skills for empirical research across 8 social science disciplines. | 精选 23,000+ AI Agent 技能库,覆盖8大社会科学学科的实证研究。CoPaper.AI 20分钟完成一篇可复现的规范实证论文,并支持用户上传 Skills。-- Maintained by CoPaper.AI from Stanford REAP.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
1 documented
License
NOASSERTION
Stars
4,537
01

Overview

🔬 A curated collection of 23,000+ agent skills for empirical research across 8 social science disciplines. | 精选 23,000+ AI Agent 技能库,覆盖8大社会科学学科的实证研究。CoPaper.AI 20分钟完成一篇可复现的规范实证论文,并支持用户上传 Skills。-- Maintained by CoPaper.AI from Stanford REAP.

Read from source at commit e1ba289846fdOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: mendeley-api
description: "Manage references and search Mendeley's catalog via REST API"
metadata:
  openclaw:
    emoji: "📚"
    category: "writing"
    subcategory: "citation"
    keywords: ["mendeley", "reference manager", "bibliography", "catalog search", "research library", "citations"]
    source: "wentor-research-plugins"
---

# Mendeley REST API

## Overview

Mendeley provides a reference management platform with a REST API for programmatic access to personal libraries, group collections, and the Mendeley Catalog — a crowdsourced database of 200M+ academic documents. The API supports OAuth 2.0 authentication, CRUD operations on documents/folders/annotations, and catalog search with rich metadata. Free tier available with registration.

## Authentication

Mendeley uses OAuth 2.0 with client credentials or authorization code flow.

```bash
# 1. Register app at https://dev.elsevier.com/
# 2. Get access token via client credentials (for catalog search)
curl -X POST "https://api.mendeley.com/oauth/token" \
  -d "grant_type=client_credentials" \
  -d "scope=all" \
  -d "client_id=$MENDELEY_CLIENT_ID" \
  -d "client_secret=$MENDELEY_CLIENT_SECRET"

# Response: { "access_token": "...", "expires_in": 3600, "token_type": "bearer" }
```

## API Endpoints

### Base URL

```
https://api.mendeley.com
```

### Catalog Search

Search across Mendeley's 200M+ document database:

```bash
# Search by title/keywords
curl -H "Authorization: Bearer $TOKEN" \
  "https://api.mendeley.com/catalog?query=deep+learning+NLP&limit=20"

# Search by DOI
curl -H "Authorization: Bearer $TOKEN" \
  "https://api.mendeley.com/catalog?doi=10.1038/nature14539"

# Search by title
curl -H "Authorization: Bearer $TOKEN" \
  "https://api.mendeley.com/catalog?title=attention+is+all+you+need"
```

### User Library

```bash
# List documents in personal library
curl -H "Authorization: Bearer $TOKEN" \
  "https://api.mendeley.com/documents?limit=50&sort=created&order=desc"

# Get document details
curl -H "Authorization: Bearer $TOKEN" \
  "https://api.mendeley.com/documents/{doc_id}"

# Add document to library
curl -X POST -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/vnd.mendeley-document.1+json" \
  -d '{"title":"My Paper","type":"journal","year":2025,"authors":[{"first_name":"A","last_name":"B"}]}' \
  "https://api.mendeley.com/documents"
```

### Folders and Groups

```bash
# List folders
curl -H "Authorization: Bearer $TOKEN" \
  "https://api.mendeley.com/folders"

# List group documents
curl -H "Authorization: Bearer $TOKEN" \
  "https://api.mendeley.com/documents?group_id={group_id}"
```

### Annotations

```bash
# Get annotations for a document
curl -H "Authorization: Bearer $TOKEN" \
  "https://api.mendeley.com/annotations?document_id={doc_id}"
```

## Query Parameters

| Parameter | Description | Example |
|-----------|-------------|---------|
| `query` | Free-text search | `query=transformer+model` |
| `doi` | DOI lookup | `doi=10.1234/example` |
| `title` | Title search | `title=BERT` |
| `author` | Author filter | `author=LeCun` |
| `min_year` | From year | `min_year=2020` |
| `max_year` | To year | `max_year=2026` |
| `limit` | Results per page (max 500) | `limit=50` |
| `sort` | Sort field | `created`, `title`, `year` |
| `order` | Sort direction | `asc` or `desc` |
| `view` | Response detail | `bib` (bibliographic), `stats` (reader counts) |

## Catalog Response

```json
{
  "id": "abc123-...",
  "title": "Attention Is All You Need",
  "type": "conference_proceedings",
  "year": 2017,
  "authors": [
    {"first_name": "Ashish", "last_name": "Vaswani"}
  ],
  "source": "NeurIPS",
  "identifiers": {
    "doi": "10.5555/3295222.3295349",
    "arxiv": "1706.03762"
  },
  "keywords": ["attention mechanism", "transformer"],
  "abstract": "The dominant sequence transduction models...",
  "reader_count": 15432,
  "link": "https://www.mendeley.com/catalogue/..."
}
```

## Python Usage

```python
import os
import requests

CLIENT_ID = os.environ["MENDELEY_CLIENT_ID"]
CLIENT_SECRET = os.environ["MENDELEY_CLIENT_SECRET"]
TOKEN_URL = "https://api.mendeley.com/oauth/token"
BASE_URL = "https://api.mendeley.com"


def get_token() -> str:
    """Obtain access token via client credentials."""
    resp = requests.post(TOKEN_URL, data={
        "grant_type": "client_credentials",
        "scope": "all",
        "client_id": CLIENT_ID,
        "client_secret": CLIENT_SECRET,
    })
    resp.raise_for_status()
    return resp.json()["access_token"]


def search_catalog(query: str, limit: int = 20,
                   min_year: int = None) -> list:
    """Search the Mendeley catalog."""
    token = get_token()
    params = {"query": query, "limit": limit, "view": "bib"}
    if min_year:
        params["min_year"] = min_year

    resp = requests.get(
        f"{BASE_URL}/catalog",
        headers={"Authorization": f"Bearer {token}"},
        params=params,
    )
    resp.raise_for_status()

    results = []
    for doc in resp.json():
        results.append({
            "title": doc.get("title"),
            "authors": [f"{a['first_name']} {a['last_name']}"
                        for a in doc.get("authors", [])],
            "year": doc.get("year"),
            "source": doc.get("source"),
            "doi": doc.get("identifiers", {}).get("doi"),
            "readers": doc.get("reader_count", 0),
        })
    return results


def lookup_by_doi(doi: str) -> dict:
    """Look up a single document by DOI."""
    token = get_token()
    resp = requests.get(
        f"{BASE_URL}/catalog",
        headers={"Authorization": f"Bearer {token}"},
        params={"doi": doi, "view": "bib"},
    )
    resp.raise_for_status()
    items = resp.json()
    return items[0] if items else {}


# Example
papers = search_catalog("federated learning privacy", min_year=2023)
for p in papers:
    print(f"[{p['year']}] {p['title']} — readers: {p['readers']}")
```

## Reader Statistics

Mendeley tracks how many users have save
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:26
curl -X POST "https://api.mendeley.com/oauth/token" \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SKILL.md:25
# 2. Get access token via client credentials (for catalog search)
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SKILL.md:150
"""Obtain access token via client credentials."""
Why it matters. asks the agent to read credentials

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-08 · audit v0.4.1 · source sha e1ba289846fdfull audit observations/trust-audit/skill/brycewang-stanford__mendeley-api.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-08e1ba289846fdBLOCKD69first audit
06

Questions

What does the Mendeley Api skill do?

🔬 A curated collection of 23,000+ agent skills for empirical research across 8 social science disciplines. | 精选 23,000+ AI Agent 技能库,覆盖8大社会科学学科的实证研究。CoPaper.AI 20分钟完成一篇可复现的规范实证论文,并支持用户上传 Skills。-- Maintained by CoPaper.AI from Stanford REAP.

Is Mendeley Api safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can Mendeley Api access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Mendeley Api work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (e1ba289846fd), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement