gs-skills — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by cookjohn · MCP Server · ★ 484

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is gs-skills safe to install? View the security audit →

About gs-skills

Google Scholar Skills for Claude Code English | 中文 English Claude Code skills that let Claude interact with Google Scholar through Chrome DevTools MCP. Search papers, track citations, get full-text links, and export to Zotero — all from the Claude Code CLI. Prerequisites Claude Code CLI installed Chrome browser with remote debugging enabled Zotero desktop app (optional, for export) Python 3 (optional, for Zotero push script) Skills |

Quick Facts

Stars484
Forks28
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score68.3063434823286/100
Open Issues1
Last Updated2026-03-13
Created2026-03-04
Platformsbrowser, claude-code, mcp, python
Est. Tokens~28k

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is gs-skills?

gs-skills is Google Scholar skills for Claude Code — search, citation tracking, full-text access, and Zotero export via Chrome DevTools MCP. It is categorized as a MCP Server with 484 GitHub stars.

What programming language is gs-skills written in?

gs-skills is primarily written in Python.

How do I install or use gs-skills?

You can find installation instructions and usage details in the gs-skills GitHub repository at github.com/cookjohn/gs-skills. The project has 484 stars and 28 forks, indicating an active community.

What license does gs-skills use?

gs-skills is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools