zotero-mcp-guide
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADS
Full Analysis
- [NO_CODE]: The skill consists exclusively of markdown documentation and setup instructions. It contains no executable scripts, automated commands, or logic that would run on the agent host.
- [EXTERNAL_DOWNLOADS]: The guide directs users to manually clone an external repository from GitHub (https://github.com/54yyyu/zotero-mcp.git) and install dependencies using npm. While the repository is not on a pre-approved trusted list, the skill describes a common and well-known tool in the researcher community.
- [DATA_EXFILTRATION]: No malicious data exfiltration was detected. The guide provides transparent information regarding how data from a local Zotero instance is processed and shared with AI providers for context grounding, highlighting this as a privacy consideration for the user.
Audit Metadata