Papersflow Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Papersflow Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
papersflow-mcp is PapersFlow's production / GA hosted MCP server for literature search, citation verification, related-paper discovery, and authenticated research workflows across Claude, Codex, Gemini, ChatGPT-style MCP apps, and other MCP clients.
<a href="https://glama.ai/mcp/servers/papersflow-ai/papers-flow"> <img width="380" height="200" src="https://glama.ai/mcp/servers/papersflow-ai/papers-flow/badge" alt="PapersFlow MCP server" /> </a>
https://doxa.papersflow.ai/mcphttps://doxa.papersflow.ai/.well-known/oauth-protected-resourcehttps://doxa.papersflow.ai/.well-known/oauth-authorization-serverhttps://doxa.papersflow.ai/oauth/registersearchfetchverify_citationsearch_literaturefind_related_papersget_citation_graphget_paper_neighborsexpand_citation_graphAuthenticated and paid tools are available through PapersFlow account access and plan entitlements.
This repository also includes a root gemini-extension.json so Gemini CLI can install it as an extension wrapper around the hosted MCP server.
Official Gemini CLI flow supported by the docs:
gemini extensions install https://github.com/papersflow-ai/papersflow-mcpThe extension manifest lives at the repository root and points Gemini CLI at the hosted MCP endpoint using Gemini's remote MCP config shape.
If Gemini shows:
papersflow-mcp (from papersflow-mcp) - Disconnected (OAuth not authenticated)that is expected until OAuth is completed inside Gemini:
/mcp auth papersflow-mcp
/mcp refresh
/mcp listgemini extensions install installs the extension package. It does not complete OAuth during install. The browser opens when Gemini starts the remote MCP auth flow, typically via /mcp auth papersflow-mcp or the first auth-required connection attempt.
Gemini CLI references:
https://geminicli.com/docs/extensions/releasing/https://geminicli.com/docs/extensions/reference/https://geminicli.com/docs/extensions/writing-extensions/Add PapersFlow as a remote MCP server in your Cline MCP settings:
{
"mcpServers": {
"papersflow": {
"url": "https://doxa.papersflow.ai/mcp",
"transportType": "streamable-http"
}
}
}On first use, Cline will open a browser window for OAuth sign-in to your PapersFlow account. Public tools (literature search, citations, paper discovery) work immediately; authenticated tools require a PapersFlow plan.
Supported client paths today:
The setup guide includes both command-style and config-style snippets where supported.
https://papersflow.aihttps://papersflow.ai/privacyhttps://papersflow.ai/termshttps://papersflow.ai/contact[email protected]~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.