Mmcp.market

Is Scholar Feed MCP server safe?

Yes, with the usual care.

B79/100grade B

Safe to use. Minor gaps such as a missing repository or slower maintenance.

What to know before installing
  • highWrite-action tools reachable without authentication

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

1 high1 medium1 low
  • Code scan2 source files scanned20/25
  • Live reliabilityremote reachable in 1246ms20/20
  • Tool poisoning27 tool descriptions checked13/15
  • Auth qualityopen endpoint exposes 6 write-action tools with no auth3/15
  • Maintenancelast push 5 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (3)

  • highWrite-action tools reachable without authenticationauth.open-write
  • mediumeval / new Function usedexec.eval
    build/index.js: …&&(l=this.opts.code.process(l,t));let f=new Function(`${sn.default.self}`,`${sn.default.scope…
  • lowUnusually long tool description (over 2,000 characters)poison.long-description
    tool check_drift: …Answers 'for my problem, is the method I use superseded — and by what?' over a grounded, entity-resolved knowledge base of textual critique receipts + benchmark-dominance edges (no LLM call at query time). Call with a `family` (e.g. 'rag', 'peft', 'kvcache') and a `method` (e.g. 'SnapKV', 'LoRA') to get a verdict: how superseded it is, WHO critiques it (verbatim quotes + the citing paper), WHO beats it on benchmarks (winner, numbers, condition, source paper), and the not-yet-superseded alternatives in the same sub-problem. Omit `method` to get the whole-family map: most-superseded baselines, competition sub-problems, and the live frontier. Method names are matched case- and spacing-insensitively, with did-you-mean suggestions on a miss. Use this when choosing or reviewing a technique for a known problem area, or to check whether a baseline a paper relies on has been beaten. Does not require a Pro API key. Covers ~10 builder-problem families and growing; the `family` parameter lists them, or pass family='list' for the live set. Coverage caveat: evidence is drawn only from arXiv benchmark tables, so 'superseded' means a method was beaten in a published comparison (not that it is dead or unusable), production frameworks (LangChain, LlamaIndex, etc.) appear only as baselines and never as winners, and results are a literature signal rather than a deployment recommendation. GROUNDING — how far to trust an individual receipt: every claim passes a deterministic gate against the source paper's raw LaTeX (a critique must carry a verbatim quote shingle found in the source; a benchmark edge must have every one of its numbers present there), so a fabricated quote or table cell cannot enter the KB. What the gate does NOT verify is ATTRIBUTION: the quote is real but its subject may be class-level or a pronoun ('these methods', 'they') rather than the named method, so tying a receipt to one specific method is sometimes an inference. No end-to-end precision number has been measured on this endpoint — read the verbatim quote and its citing paper before repeating a verdict, and cite the source rather than asserting supersession as fact.…
Overall 79/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Scholar Feed does

  • Ranks Hawk
    SEO competitor intelligence for AI agents: content gaps, backlink opportunities, AI-citation topics.
    C
  • Log10x MCP
    Tools to rank log patterns by volume and cost and to compact, tier down or offload each pattern
    A
  • Tracetify
    Find competitors, trace how they grew, watch what they ship — plus your Search Console.
    A

Scholar Feed reviews, tools and install