@the-40-thieves/alexandria-mcp

MCPattested
v11.0.0suavecito585MITUpdated todaynpmGitHub

152-source digital library MCP server. Natural language search across academic papers, public domain books, legal records, government archives, and software documentation.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
1GitHub stars
todayLast update
Reads these credentials
  • OPENAI_API_KEYAPI keyoptional

    OpenAI key for routing (library_ask), synthesis (library_answer, library_research), and embeddings (library_ingest). Search and read tools work without it.

  • ALEXANDRIA_API_KEYAPI keyoptional

    API key paired with ALEXANDRIA_BASE_URL. Falls back to OPENAI_API_KEY.

  • CORE_API_KEYAPI keyoptional

    Unlocks the core source (CORE, 57M+ open access papers). Free key from core.ac.uk/services/api.

  • COURTLISTENER_API_KEYAPI keyoptional

    Unlocks the courtlistener source (US federal and state court opinions). Free key from courtlistener.com.

  • GOVINFO_API_KEYAPI keyoptional

    Unlocks govinfo (Congressional Record, Federal Register, US Code); also accepted by congress and regulations. Free key from api.data.gov.

  • GOOGLE_BOOKS_API_KEYAPI keyoptional

    Unlocks the googlebooks source (40M+ books). Free key from the Google Cloud Console (Books API).

  • GITHUB_TOKENAPI keyoptional

    Unlocks githubsearch and githubmcp (GitHub code search); optional for ghsa and openiti. Public-repo read scope is enough.

  • NASA_ADS_API_KEYAPI keyoptional

    Unlocks the nasaads source (NASA Astrophysics Data System). Free key from ui.adsabs.harvard.edu.

  • EUROPEANA_API_KEYAPI keyoptional

    Unlocks the europeana source (50M+ European cultural heritage items). Free key from apis.europeana.eu.

  • SEMANTIC_SCHOLAR_API_KEYAPI keyoptional

    Optional for semanticscholar and library_recommend; raises the rate limit. Free key from semanticscholar.org/product/api.

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorsuavecito585
LicenseMIT
Version11.0.0
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
Listed in Forge index+10/10
Identity verified · attested build+20/20
Ed25519 publish signature+0/5
Included automatically when the publisher runs `forge publish`
Domain verification+0/5
Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+5/5
npm maintainer match+0/5
Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
CVE scan · clean+30/30
Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain
Provenance✓ Sigstore-verified · 22fc267
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface38 tools · none privileged
Security scan✓ Cleanv11.0.0 · todayHow well does this scan work?
EvalsNone
IndexedSep 5, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

38 tools · none privileged
Statically extracted from the published packagev11.0.0 · 1h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

circlCIRCL Vulnerability Lookup: full-text search across CVE, GHSA and other vulnerability feeds, run by Luxembourg's CERT. No API key required.

CIRCL Vulnerability Lookup: full-text search across CVE, GHSA and other vulnerability feeds, run by Luxembourg's CERT. No API key required.

No input schema was published for this tool.

context7mcpContext7 documentation search via its own MCP server (resolve-library-id then query-docs). Works keyless; set CONTEXT7_API_KEY for a higher rate. Additive to the existing context7 REST source. read() cannot target a specific topic (query-docs needs one but read(id) carries no query), so it uses a g…

Context7 documentation search via its own MCP server (resolve-library-id then query-docs). Works keyless; set CONTEXT7_API_KEY for a higher rate. Additive to the existing context7 REST source. read() cannot target a specific topic (query-docs needs one but read(id) carries no query), so it uses a g…

No input schema was published for this tool.

dataciteDataCite: DOI metadata for research datasets and software (Zenodo, Figshare, Dryad, OSF, and more all register here) - one source for the whole data-repository DOI tier. No API key required (3,000 req/5min/IP).

DataCite: DOI metadata for research datasets and software (Zenodo, Figshare, Dryad, OSF, and more all register here) - one source for the whole data-repository DOI tier. No API key required (3,000 req/5min/IP).

No input schema was published for this tool.

dbnomicsDBnomics: an aggregator of macroeconomic and statistical datasets from central banks, statistical agencies, and international organizations worldwide. No API key required.

DBnomics: an aggregator of macroeconomic and statistical datasets from central banks, statistical agencies, and international organizations worldwide. No API key required.

No input schema was published for this tool.

epatriEPA Toxics Release Inventory (TRI): facility search by name, part of EPA's tracking of industrial toxic chemical releases. No API key required.

EPA Toxics Release Inventory (TRI): facility search by name, part of EPA's tracking of industrial toxic chemical releases. No API key required.

No input schema was published for this tool.

euvdEUVD: the European Union Vulnerability Database, ENISA's aggregation of CVE, GHSA and vendor advisories. No API key required.

EUVD: the European Union Vulnerability Database, ENISA's aggregation of CVE, GHSA and vendor advisories. No API key required.

No input schema was published for this tool.

fredFRED: the Federal Reserve Bank of St. Louis's economic data API, hundreds of thousands of US and international time series. Requires free FRED_API_KEY.

FRED: the Federal Reserve Bank of St. Louis's economic data API, hundreds of thousands of US and international time series. Requires free FRED_API_KEY.

No input schema was published for this tool.

ghsaGitHub Security Advisories: advisories curated by GitHub across public repositories and package ecosystems. Works keyless (60 req/h); set GITHUB_TOKEN for a higher rate.

GitHub Security Advisories: advisories curated by GitHub across public repositories and package ecosystems. Works keyless (60 req/h); set GITHUB_TOKEN for a higher rate.

No input schema was published for this tool.

githubmcpGitHub code search via the official Copilot MCP server (search_code, get_file_contents). Requires GITHUB_TOKEN; hidden without it.

GitHub code search via the official Copilot MCP server (search_code, get_file_contents). Requires GITHUB_TOKEN; hidden without it.

No input schema was published for this tool.

githubsearchGitHub code search: full-text search across public repository contents. Requires GITHUB_TOKEN (the /search/code endpoint rejects unauthenticated requests).

GitHub code search: full-text search across public repository contents. Requires GITHUB_TOKEN (the /search/code endpoint rejects unauthenticated requests).

No input schema was published for this tool.

guardianThe Guardian Open Platform: full-text search across Guardian journalism, with article body text. Requires free GUARDIAN_API_KEY.

The Guardian Open Platform: full-text search across Guardian journalism, with article body text. Requires free GUARDIAN_API_KEY.

No input schema was published for this tool.

halHAL (Hyper Articles en Ligne): 4M+ full-text French/EU academic deposits with a Solr search across titles, abstracts, and full text. No API key required.

HAL (Hyper Articles en Ligne): 4M+ full-text French/EU academic deposits with a Solr search across titles, abstracts, and full text. No API key required.

No input schema was published for this tool.

hansardUK Parliament Hansard: full-text search over Commons and Lords debates, with the complete member-by-member record of any one debate. No API key required.

UK Parliament Hansard: full-text search over Commons and Lords debates, with the complete member-by-member record of any one debate. No API key required.

No input schema was published for this tool.

hapiHDX HAPI (Humanitarian Data Exchange, Humanitarian API): conflict-event and coordination data. A country-name query resolves to a conflict-events lookup; other queries search HAPI's location metadata. Requires free HDX_APP_IDENTIFIER (self-serve).

HDX HAPI (Humanitarian Data Exchange, Humanitarian API): conflict-event and coordination data. A country-name query resolves to a conflict-events lookup; other queries search HAPI's location metadata. Requires free HDX_APP_IDENTIFIER (self-serve).

No input schema was published for this tool.

huggingfaceHugging Face Hub paper search via its MCP hf_fs tool (an hf://papers search). Full text is read via the arxiv source (every result id is a bare arXiv id). No API key required.

Hugging Face Hub paper search via its MCP hf_fs tool (an hf://papers search). Full text is read via the arxiv source (every result id is a bare arXiv id). No API key required.

No input schema was published for this tool.

library_list_sourcesNo description published

This tool published no description. Forge does not invent one.

library_health_checkNo description published

This tool published no description. Forge does not invent one.

library_askNo description published

This tool published no description. Forge does not invent one.

library_searchSearch a specific library source by name. Use library_ask instead for natural language queries across multiple sources. Sources marked [full text] support library_read and library_ingest. Sources marked [metadata] return discovery info and external URLs only.

Search a specific library source by name. Use library_ask instead for natural language queries across multiple sources. Sources marked [full text] support library_read and library_ingest. Sources marked [metadata] return discovery info and external URLs only.

No input schema was published for this tool.

library_readFetch text from a library source. Full-text sources return cleaned text (truncated at 200k chars). Metadata sources return item details and an external URL.

Fetch text from a library source. Full-text sources return cleaned text (truncated at 200k chars). Metadata sources return item details and an external URL.

No input schema was published for this tool.

library_indexDry run: fetch text, chunk semantically, score OCR quality. No writes. Full-text sources only.

Dry run: fetch text, chunk semantically, score OCR quality. No writes. Full-text sources only.

No input schema was published for this tool.

library_ingestChunk, embed, and store a text. Idempotent. Full-text sources only. Requires OPENAI_API_KEY + SUPABASE_URL + SUPABASE_SERVICE_ROLE_KEY.

Chunk, embed, and store a text. Idempotent. Full-text sources only. Requires OPENAI_API_KEY + SUPABASE_URL + SUPABASE_SERVICE_ROLE_KEY.

No input schema was published for this tool.

library_recommendGet papers similar to a given paper using Semantic Scholar's recommendation engine. Pass a paperId from a semanticscholar search result. Returns up to 500 similar papers.

Get papers similar to a given paper using Semantic Scholar's recommendation engine. Pass a paperId from a semanticscholar search result. Returns up to 500 similar papers.

No input schema was published for this tool.

library_answerAsk a question in plain English and get a synthesized answer with inline [n] citations, fused across sources with reciprocal rank fusion. Use this instead of library_ask when you want a cited answer rather than raw results. Every factual sentence is cited or dropped; an uncited or all-dropped answe…

Ask a question in plain English and get a synthesized answer with inline [n] citations, fused across sources with reciprocal rank fusion. Use this instead of library_ask when you want a cited answer rather than raw results. Every factual sentence is cited or dropped; an uncited or all-dropped answe…

No input schema was published for this tool.

library_researchNo description published

This tool published no description. Forge does not invent one.

library_citationsNo description published

This tool published no description. Forge does not invent one.

jinaJina AI's live web search and page reader MCP server (search_web, read_url). Works keyless for connecting; set JINA_API_KEY for actual search/read calls (unauthenticated calls return an error result). cluster web, freshness realtime.

Jina AI's live web search and page reader MCP server (search_web, read_url). Works keyless for connecting; set JINA_API_KEY for actual search/read calls (unauthenticated calls return an error result). cluster web, freshness realtime.

No input schema was published for this tool.

jinaarxivJina AI's search_arxiv tool: arXiv preprint search via the same MCP server as jina. Full text is read via the arxiv source when a result carries an arxiv_id. Works keyless for connecting; set JINA_API_KEY for actual search calls.

Jina AI's search_arxiv tool: arXiv preprint search via the same MCP server as jina. Full text is read via the arxiv source when a result carries an arxiv_id. Works keyless for connecting; set JINA_API_KEY for actual search calls.

No input schema was published for this tool.

searchfake search

fake search

No input schema was published for this tool.

readfake read

fake read

No input schema was published for this tool.

mdnmcpMDN Web Docs's own MCP server: web platform reference and guides, with full document text via get-doc. No API key required. Additive to the existing mdn REST source, which it falls back to when the MCP server is unreachable.

MDN Web Docs's own MCP server: web platform reference and guides, with full document text via get-doc. No API key required. Additive to the existing mdn REST source, which it falls back to when the MCP server is unreachable.

No input schema was published for this tool.

nvdNIST NVD: the National Vulnerability Database, CVE records enriched with CVSS scores and CPE matches. Works keyless at a slow pace; set NVD_API_KEY for a faster one.

NIST NVD: the National Vulnerability Database, CVE records enriched with CVSS scores and CPE matches. Works keyless at a slow pace; set NVD_API_KEY for a faster one.

No input schema was published for this tool.

paperswithcodePapers with Code: machine learning papers cross-referenced with their code implementations.

Papers with Code: machine learning papers cross-referenced with their code implementations.

No input schema was published for this tool.

reliefwebReliefWeb: humanitarian reports and situation updates from UN OCHA and partner organizations. Requires a registered RELIEFWEB_APPNAME.

ReliefWeb: humanitarian reports and situation updates from UN OCHA and partner organizations. Requires a registered RELIEFWEB_APPNAME.

No input schema was published for this tool.

rentcastRentCast: US rental and sale market statistics by ZIP code. Requires free-tier RENTCAST_API_KEY (50 requests/month).

RentCast: US rental and sale market statistics by ZIP code. Requires free-tier RENTCAST_API_KEY (50 requests/month).

No input schema was published for this tool.

stackexchangeStack Overflow (via the Stack Exchange API): advanced full-text question search. Works keyless at the shared rate limit; set STACKEXCHANGE_KEY for a dedicated pool.

Stack Overflow (via the Stack Exchange API): advanced full-text question search. Works keyless at the shared rate limit; set STACKEXCHANGE_KEY for a dedicated pool.

No input schema was published for this tool.

twelvedataTwelve Data: stock, ETF, and forex symbol search across global exchanges, with a daily time series read. Requires free TWELVEDATA_API_KEY.

Twelve Data: stock, ETF, and forex symbol search across global exchanges, with a daily time series read. Requires free TWELVEDATA_API_KEY.

No input schema was published for this tool.

ukparliamentUK Parliament Bills API: public legislation before the House of Commons and House of Lords. No API key required.

UK Parliament Bills API: public legislation before the House of Commons and House of Lords. No API key required.

No input schema was published for this tool.

33 of 38 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

152-source digital library MCP server. Natural language search across academic papers, public domain books, legal records, government archives, and software documentation.

Keywords
mcpmodel-context-protocollibraryresearchacademicaillmclaudearxivgutenbergrag
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-09-05 — observed resolution, not a publisher declaration.

60 packages resolved · 16 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

33 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+21 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies, optionalDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.

Topics

Related in rag & embeddings