@oscardvs/zoteus

MCPattesté
v1.8.0io.github.oscardvsMITMis à jour il y a 1 jnpmGitHub

The everything Zotero MCP server — Web API v3 + local API, safe writes, citations, search.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
2kTéléch./sem.
il y a 1 jDernière mise à jour
Lit ces identifiants
  • ZOTERO_API_KEYClé d’APIfacultatif

    Zotero API key (writes/sync/groups; optional for local-only reads).

Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquet
Auteurio.github.oscardvs
LicenceMIT
Version1.8.0
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
Listé dans l’index Forge+10/10
Identité vérifiée · build attesté+20/20
Signature de publication Ed25519+0/5
Incluse automatiquement quand l’éditeur exécute `forge publish`
Vérification de domaine+0/5
Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
Correspondance de mainteneur npm+0/5
Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
Analyse CVE · propre+30/30
Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine
Provenance✓ Vérifié par Sigstore · bb414df
Dépendances✓ 60 résolues+ · aucune vulnérable
Surface d’outils30 outils · 1 privilégiés
Analyse de sécurité✓ Proprev1.9.0 · aujourd’huiQuelle est l’efficacité de cette analyse ?
PROMPTtool:zotero_schemaImperative addressed to the AI model
ÉvaluationsAucune
Indexé20 août 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

30 outils · 1 privilégiés
Extrait statiquement du paquet publiév1.9.0 · 2h ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

zotero_annotateAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_attach_fileAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_attachmentAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_bibliographyProduce a formatted bibliography for items already in a Zotero library, rendered server-side by Zotero in a CSL style. Provide `item_keys` and optionally `style` (name or CSL id; Zotero default is chicago-note-bibliography), `locale`, and `linkwrap`. Returns XHTML. Note: this endpoint is item-only…

Produce a formatted bibliography for items already in a Zotero library, rendered server-side by Zotero in a CSL style. Provide `item_keys` and optionally `style` (name or CSL id; Zotero default is chicago-note-bibliography), `locale`, and `linkwrap`. Returns XHTML. Note: this endpoint is item-only…

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_create_itemsAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_delete_itemsprivilégiéAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_exportAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_format_bibliographyAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_fulltextAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_get_fulltextAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_get_itemAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_groupsList the group libraries the current API key can access, with each group's id, name, type, item count, and edit permissions. Use a returned group id with the `library_id`/`library_type:"group"` parameters of other tools to operate on that group library. Requires a cloud API key.

List the group libraries the current API key can access, with each group's id, name, type, item count, and edit permissions. Use a returned group id with the `library_id`/`library_type:"group"` parameters of other tools to operate on that group library. Requires a cloud API key.

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_importAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_indexAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_list_collectionsList collections in a Zotero library (key, name, parent collection key, item count). Read-only — available even in read-only mode (unlike zotero_manage_collections, which also writes). Use the keys to scope zotero_search_items (collectionKey) or zotero_tag_audit (scope.collection_keys).

List collections in a Zotero library (key, name, parent collection key, item count). Read-only — available even in read-only mode (unlike zotero_manage_collections, which also writes). Use the keys to scope zotero_search_items (collectionKey) or zotero_tag_audit (scope.collection_keys).

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_list_tagsList tags in a Zotero library with their usage count and whether each was auto-applied by Zotero. Optional `q` substring filter and `limit`. Read-only — available even when the connector runs in read-only mode (unlike zotero_manage_tags, which also writes). For taxonomy hygiene use zotero_tag_audit.

List tags in a Zotero library with their usage count and whether each was auto-applied by Zotero. Optional `q` substring filter and `limit`. Read-only — available even when the connector runs in read-only mode (unlike zotero_manage_tags, which also writes). For taxonomy hygiene use zotero_tag_audit.

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_manage_collectionsAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_manage_tagsList tags, or add/remove tags on items. Set `action` to "list" (returns library tags; supports `q` substring filter), "add" (add `tags` to each of `item_keys`), or "remove" (remove `tags` from each of `item_keys`). Tags are stored on the parent item's tag array, so add/remove edits the items (cloud…

List tags, or add/remove tags on items. Set `action` to "list" (returns library tags; supports `q` substring filter), "add" (add `tags` to each of `item_keys`), or "remove" (remove `tags` from each of `item_keys`). Tags are stored on the parent item's tag array, so add/remove edits the items (cloud…

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_saved_searchesList, create, or delete saved-search DEFINITIONS. NOTE: the Zotero cloud Web API stores saved searches but does NOT execute them — to get the items a saved search matches, run an equivalent zotero_search_items query (or use the desktop local API when available). Set `action` to "list" (all saved se…

List, create, or delete saved-search DEFINITIONS. NOTE: the Zotero cloud Web API stores saved searches but does NOT execute them — to get the items a saved search matches, run an equivalent zotero_search_items query (or use the desktop local API when available). Set `action` to "list" (all saved se…

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_schemaReturn the Zotero data model so you never hardcode item shapes. With no arguments, returns the schema version and the list of all item type names. With `item_type`, returns the valid fields and creator types for that type (the "primary" creator type is listed first). Use this to validate an item be…

Return the Zotero data model so you never hardcode item shapes. With no arguments, returns the schema version and the list of all item type names. With `item_type`, returns the valid fields and creator types for that type (the "primary" creator type is listed first). Use this to validate an item be…

NOTEImperative addressed to the AI modelReturn the Zotero data model so you never hardcode item shapes. With no argume…

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_scholarAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_search_itemsAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

search_toolsDiscover the available Zotero tools by keyword — useful for progressive disclosure when you do not want to load every tool definition up front (the code-execution-with-MCP pattern). Pass an optional `query` (matched against tool names, titles, and descriptions) and `detail` ("names" or "description…

Discover the available Zotero tools by keyword — useful for progressive disclosure when you do not want to load every tool definition up front (the code-execution-with-MCP pattern). Pass an optional `query` (matched against tool names, titles, and descriptions) and `detail` ("names" or "description…

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_semantic_searchAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_stylesAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_syncReturn what changed in a library since a given version, for efficient incremental sync. Provide `since` (a library version; 0 = everything). Returns, per object type (items/collections/searches/tags), the map of keys→version that changed after `since`, plus the deletion log (keys removed since `sin…

Return what changed in a library since a given version, for efficient incremental sync. Provide `since` (a library version; 0 = everything). Returns, per object type (items/collections/searches/tags), the map of keys→version that changed after `since`, plus the deletion log (keys removed since `sin…

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_tag_auditAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_trash_itemsMove items to the trash (the safe, REVERSIBLE default) or restore them. This sets the `deleted` flag (1=trash, 0=restore) — it is NOT a permanent delete, so trashed items can be recovered here or in the Zotero app. Use this instead of zotero_delete_items unless you truly need irreversible removal.…

Move items to the trash (the safe, REVERSIBLE default) or restore them. This sets the `deleted` flag (1=trash, 0=restore) — it is NOT a permanent delete, so trashed items can be recovered here or in the Zotero app. Use this instead of zotero_delete_items unless you truly need irreversible removal.…

Aucun schéma d’entrée n’a été publié pour cet outil.

zotero_update_itemAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

zotero_whoamiResolve the current Zotero identity (userID, username, display name) and per-library access scopes from the configured API key, and report which library backends are available (cloud Web API and/or the desktop local API). Call this first to discover the userID — never ask the user to type a numeric…

Resolve the current Zotero identity (userID, username, display name) and per-library access scopes from the configured API key, and report which library backends are available (cloud Web API and/or the desktop local API). Call this first to discover the userID — never ask the user to type a numeric…

Aucun schéma d’entrée n’a été publié pour cet outil.

11 outils sur 30 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

The everything Zotero MCP server — Web API v3 + local API, safe writes, citations, search.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-08-29 — résolution observée, et non une déclaration de l'éditeur.

60 paquets résolus · 6 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.

36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)

Déclarées mais non résolues

42 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.

+30 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.