For developers / X-T-E-R

Zotero MCP Neo

github.com/X-T-E-R/Zotero-MCP-Neo
Public grade · v2.0.2BUse with care
To reach A
A zotero:// link (a web page can open one) can make it install add-ons without asking youcontent/scripts/zotero-mcp-neo.js · line 9411Services.io.getProtocolHandler("zotero").wrappedJSObject._extensions["zotero://plugin"] = pluginBridgeExtension;Reply
A zotero:// link can make it run code if you approve a promptcontent/scripts/zotero-mcp-neo.js · line 9357Services.io.getProtocolHandler("zotero").wrappedJSObject._extensions["zotero://ztoolkit-debug"] = debugBridgeExtension;Reply
Any website you visit can make it act through its local server: it doesn't check where requests come fromcontent/scripts/zotero-mcp-neo.js · line 5465if (col) item.addToCollection(col.id);Reply
✓Readable code, uploaded by the project's automated GitHub build
✓Only contacts services we could identify
Then A+
Pass the live test in Zotero 10We install it in a fresh Zotero and record what it does. Every plugin at A is tested.
README badgePlugins Atlas grade B[![Plugins Atlas grade](https://zoteroplugins.org/badge/zotero-mcp-neo.svg)](https://zoteroplugins.org/p/zotero-mcp-neo)Updates itself when the grade changes.
Disagree with a finding?Respond on GitHub from an account that maintains the repository. Your response is published next to the card, with our reply.Respond to the card
See the public plugin page