Plugins / AI & summaries

Zoty Bridge

by eric-tramel · github.com/eric-tramel/zoty

Lightweight Zotero MCP server for AI agents

View source
Downloads a .xpi file (0.00 MB). In Zotero, open Tools → Plugins and install it from the file.
StarsPeople who starred the repository on GitHub: a rough measure of interest.
15
DownloadsAll-time downloads of its release files from GitHub. Installs from elsewhere aren't counted.
104
ContributorsPeople who have committed code to the repository.
2
LicenceThe licence the code is published under, as GitHub reports it.
MIT
C
Atlas gradeNot recommended
because any website you visit can make it act through its local server: it doesn't check where requests come from, and 1 more finding
Applies to v0.3.0, released 16 May 2026Code checked · tested installed in Zotero 9.0.6 on 27 Sep 2026
Doesn't work with the current Zotero (10)Works with Zotero 7, 8, 9.
What we found in the codeSets the gradeThe worst finding in these three areas sets the grade.
Code transparencyReadable code, uploaded by the project's automated GitHub buildThe release file was uploaded by the project's automated GitHub build. We haven't yet rebuilt it from the source to compare.LowLow concern: normal for plugins that do this job. Listed so you know.
Updates
Updates come from this project's GitHub repositoryThe update address offers this version
Where your data goesNo web requests foundLowLow concern: normal for plugins that do this job. Listed so you know.
No further detail for this area yet.
Powerful capabilitiesAny website you visit can make it act through its local server: it doesn't check where requests come from, and 2 moreHighHigh concern: a serious problem. One high finding makes the grade C.
Any website you visit can make it act through its local server: it doesn't check where requests come fromhighHigh concern: a serious problem.Runs code web pages send ithighHigh concern: a serious problem.Runs code it assembles while runninglowLow concern.
Where we found it
Any website you visit can make it act through its local server: it d…bootstrap.js · line 88

A website can make it run code the site sends

var fn = new Function("Zotero", "return (async () => { " + code + " })();");
Runs code web pages send itbootstrap.js · line 88
var fn = new Function("Zotero", "return (async () => { " + code + " })();");
Before you installShown, not gradedFacts to help you decide. They don't change the grade.
Works withZotero 7, 8, 9 · not 10, 11 betaDoesn't work with the current Zotero (10)MediumMedium concern: worth reading before you install. One medium finding makes the grade B.
Zotero 7 ✓ worksZotero 8 ✓ worksZotero 9 ✓ worksZotero 10 ✗ doesn't workZotero 11 beta ✗ doesn't work
What you'll needZotero 7, 8, 9Detected automatically from its code
No further detail for this area yet.
MaintenanceActive · last release 16 May 20262 contributors
No further detail for this area yet.
LanguagesDocumentation in EnglishInterface language not declared
No further detail for this area yet.
We report what we found in the code. Open any area for the evidence.How we gradeReport a problem

What it does

Description coming soon. We haven't written a summary yet. The line above is the developer's own description; the developer's README is linked above.

What you'll need

Detected automatically
  • Zotero 7, 8, 9Not working with Zotero 10

Where your data goes

We found: no web requests found.

Forks and alternatives

No forks listed.

Plugins for the same job
  • Add Items from TextAI & summaries · Import & metadataA+Recommended, tested in Zotero
  • MkteroReading & PDFs · Citing & writing · AI & summariesA+Recommended, tested in Zotero
  • Zotero 阅读模式沉浸式双语Reading & PDFs · Translation · AI & summariesA+Recommended, tested in Zotero
  • Zotero 标题翻译Reading & PDFs · Translation · Organising & tags · AI & summariesA+Recommended, tested in Zotero

The developer's response

The developer hasn't responded. Developers can reply here, and their reply sits next to our findings.I'm the developer
Install Zoty Bridge
CNot recommended
We don't recommend itAny website you visit can make it act through its local server: it doesn't check where requests come from, and 1 more finding.
Read what we found