Overleaf Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Overleaf Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP (Model Context Protocol) server that lets LLM agents (Claude Code, etc.) read and update Overleaf LaTeX papers via git.
overleaf_mcp.py — FastAPI server exposing read_paper and update_and_push_paper tools over HTTPmain.py — stdio bridge that translates JSON-RPC (MCP protocol) to HTTP calls; this is what MCP clients connect topdflatex (for LaTeX compilation)git git clone https://git.overleaf.com/<your-project-id> ~/path/to/your-paper cp .env.example .env
# Edit .env and set REPO_DIR to the absolute path of your local clone pip install -e .python overleaf_mcp.pyThe server starts on http://localhost:8000 and exposes:
GET /mcp/tools — list available toolsPOST /mcp/execute — execute a toolGET /health — health checkThe bridge (main.py) speaks JSON-RPC over stdio, the standard MCP transport. Point your MCP client to it.
Claude Code (via `claude.json`):
{
"mcpServers": {
"overleaf": {
"command": "python",
"args": ["/path/to/overleaf_mcp/main.py"]
}
}
}Or run the bridge directly for testing:
python main.py| Tool | Description | Parameters |
|---|---|---|
read_paper | Reads the current content of main.tex | None |
update_and_push_paper | Writes new main.tex, compiles with pdflatex, commits, and pushes to Overleaf | latex_content (required), commit_message (optional) |
read_bibliography | Reads a .bib file from the repo | bib_file (optional, default: references.bib) |
update_and_push_bibliography | Writes new .bib content, compiles, commits, and pushes | bib_content (required), bib_file (optional), commit_message (optional) |
See mcp_sample.json for a sample request payload.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.