Plugins / Import & metadata

Zotero Resource Search MCP

by X-T-E-R · github.com/X-T-E-R/zotero-resource-search-mcp

Zotero plugin providing MCP-based academic and web resource search across multiple platforms with direct Zotero integration

View source
Downloads a .xpi file (0.6 MB). In Zotero, open Tools → Plugins and install it from the file.
StarsPeople who starred the repository on GitHub: a rough measure of interest.
0
DownloadsAll-time downloads of its release files from GitHub. Installs from elsewhere aren't counted.
11
ContributorsPeople who have committed code to the repository.
1
LicenceThe licence the code is published under, as GitHub reports it.
MIT
C
Atlas gradeNot recommended
because any website you visit can make it act through its local server: it doesn't check where requests come from, and 1 more finding
Applies to v0.2.4, released 15 Apr 2026Code checked · tested installed in Zotero 10.0.3 on 27 Sep 2026
What we found in the codeSets the gradeThe worst finding in these three areas sets the grade.
Code transparencyReadable code, uploaded by the project's automated GitHub buildThe release file was uploaded by the project's automated GitHub build. We haven't yet rebuilt it from the source to compare.LowLow concern: normal for plugins that do this job. Listed so you know.
Updates
Updates come from this project's GitHub repositoryThe update address offers this version
Where your data goesOnly contacts services we could identify8 addresses in 5 groups.LowLow concern: normal for plugins that do this job. Listed so you know.
AI services (1)
api.x.ai
Scholarly services (2)
api.crossref.orgnamed in its codeThe address is in its code, but we didn't trace a request to it. It may be a link or unused.doi.orgnamed in its codeThe address is in its code, but we didn't trace a request to it. It may be a link or unused.
Apps you connect (3)
api.exa.aiapi.firecrawl.devapi.tavily.com
Zotero (1)
Zotero lookup services
On your computer (1)
127.0.0.1named in its codeThe address is in its code, but we didn't trace a request to it. It may be a link or unused.
Where we found it
api.x.aicontent/scripts/zotero-resource-search.js · line 7062
base_url: configProvider.getString("web.xai.baseUrl", "https://api.x.ai/v1"),
api.exa.aicontent/scripts/zotero-resource-search.js · line 7056
base_url: configProvider.getString("web.exa.baseUrl", "https://api.exa.ai"),
api.firecrawl.devcontent/scripts/zotero-resource-search.js · line 7050
base_url: configProvider.getString("web.firecrawl.baseUrl", "https://api.firecrawl.dev"),
Powerful capabilitiesAny website you visit can make it act through its local server: it doesn't check where requests come from, and 9 moreHighHigh concern: a serious problem. One high finding makes the grade C.
Any website you visit can make it act through its local server: it doesn't check where requests come fromhighHigh concern: a serious problem.Downloads and runs codehighHigh concern: a serious problem.A zotero:// link (a web page can open one) can make it install add-ons without asking you (from zotero-plugin-toolkit)mediumMedium concern: worth reading before you install.A zotero:// link can make it run code if you approve a prompt (from zotero-plugin-toolkit)mediumMedium concern: worth reading before you install.Changes settings in other programs or on your computerlowLow concern.Uses the clipboardlowLow concern.Stores API keys or passwordslowLow concern.Runs code it assembles while runninglowLow concern.Works with files on your computerlowLow concern.Uses Zotero's password managerlowLow concern.
Where we found it
Any website you visit can make it act through its local server: it d…content/scripts/zotero-resource-search.js · line 5024

A website can make it change your library

item.addToCollection(col.id);
Downloads and runs codecontent/scripts/zotero-resource-search.js · line 9669
const r = await fetch(entry.downloadUrl, { cache: "no-store" });
A zotero:// link (a web page can open one) can make it install add-o…content/scripts/zotero-resource-search.js · line 129

zotero://plugin

Services.io.getProtocolHandler("zotero").wrappedJSObject._extensions["zotero://plugin"] = pluginBridgeExtension;
A zotero:// link can make it run code if you approve a promptcontent/scripts/zotero-resource-search.js · line 85

zotero://ztoolkit-debug

Services.io.getProtocolHandler("zotero").wrappedJSObject._extensions["zotero://ztoolkit-debug"] = debugBridgeExtension;
Before you installShown, not gradedFacts to help you decide. They don't change the grade.
Works withZotero 7, 8, 9, 10, 11 betaUpdates automatically
Zotero 7 ✓ worksZotero 8 ✓ worksZotero 9 ✓ worksZotero 10 ✓ worksZotero 11 beta ✓ works
What you'll needNothing extra detectedDetected automatically from its code
No further detail for this area yet.
MaintenanceActive · last release 15 Apr 20261 contributor
No further detail for this area yet.
LanguagesDocumentation in EnglishInterface: English and Chinese
No further detail for this area yet.
We report what we found in the code. Open any area for the evidence.How we gradeReport a problem

What it does

Description coming soon. We haven't written a summary yet. The line above is the developer's own description; the developer's README is linked above.

What you'll need

Detected automatically

We haven't detected any setup requirements. That isn't the same as none: check the developer's README.

Where your data goes

We found: only contacts services we could identify. 8 addresses in 5 groups.

AI services (1)
api.x.ai
Scholarly services (2)
api.crossref.orgnamed in its codedoi.orgnamed in its code
Apps you connect (3)
api.exa.aiapi.firecrawl.devapi.tavily.com
Zotero (1)
Zotero lookup services
On your computer (1)
127.0.0.1named in its code
Evidence · file and line
api.x.aicontent/scripts/zotero-resource-search.js · line 7062
base_url: configProvider.getString("web.xai.baseUrl", "https://api.x.ai/v1"),
api.exa.aicontent/scripts/zotero-resource-search.js · line 7056
base_url: configProvider.getString("web.exa.baseUrl", "https://api.exa.ai"),
api.firecrawl.devcontent/scripts/zotero-resource-search.js · line 7050
base_url: configProvider.getString("web.firecrawl.baseUrl", "https://api.firecrawl.dev"),

Forks and alternatives

No forks listed.

Plugins for the same job
  • Google Scholar Citation CountCiting & writing · Import & metadataA+Recommended, tested in Zotero
  • DOI FixImport & metadataA+Recommended, tested in Zotero
  • Add Items from TextAI & summaries · Import & metadataA+Recommended, tested in Zotero
  • MkteroReading & PDFs · Citing & writing · AI & summariesA+Recommended, tested in Zotero

The developer's response

The developer hasn't responded. Developers can reply here, and their reply sits next to our findings.I'm the developer
Install Zotero Resource Search MCP
CNot recommended
We don't recommend itAny website you visit can make it act through its local server: it doesn't check where requests come from, and 1 more finding.
Read what we found