Back to Browse

Pubtator MCP Server

Developer ToolsModerate6.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

PubTator 3 MCP — biomedical entity search, literature search with entity

About

PubTator 3 MCP — biomedical entity search, literature search with entity

Remote endpoints: streamable-http: https://gateway.pipeworx.io/pubtator/mcp

Security Report

6.8
Moderate6.8Moderate Risk

This is a well-structured MCP server for biomedical literature search via PubTator 3 API. The code demonstrates good security practices with proper error handling, input validation, and no authentication-based risks (the API is keyless). The extensive shared HTTP utilities show defensive coding patterns. Minor code quality observations around exception handling breadth do not materially impact security. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed · 4 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

@pipeworx/pubtator

Biomedical literature search by entity, plus the gene–disease–chemical–variant relations PubTator 3 has extracted from ~36M PubMed abstracts and PMC open-access full text — every relation labelled machine-extracted and carrying the sentences it was read from. Sourced from the PubTator 3 API run by NCBI / NLM. Connects gene-level lookups (mygene-info, pubmed) to the literature that mentions them.

Part of Pipeworx — an MCP gateway connecting AI agents to 1715+ live data sources. This is an independent, unofficial integration — not affiliated with, endorsed by, or published by the upstream provider.

Tools

  • pubtator_find_entity(query, concept?, limit?) — resolve a gene, disease, chemical, variant, species or cell-line name to its normalized PubTator id (@GENE_BRCA1 / NCBI Gene 672, @DISEASE_Breast_Neoplasms / MeSH D001943). Answers "what is the id for X so I can query by it".
  • pubtator_search(query, page?) — literature search by free text, by entity ids joined with AND/OR, or by a relation query (relations:treat|@CHEMICAL_Doxorubicin|@DISEASE_Breast_Neoplasms). Each hit carries the matched sentence with its entity mentions decoded (text, entity, normalized ids, matched_query), PMID, PMCID, DOI, journal and date. 10 per page; total_results and total_pages returned.
  • pubtator_relations(entity, type?, target?, limit?, evidence_for?) — the relations PubTator 3 extracted for an entity (which drugs treat a disease, which genes a disease is associated with …), ranked by supporting_publications. The top evidence_for relations (default 3, max 5) carry up to 3 supporting passages each. Accepts a PubTator id or a plain name (resolved via autocomplete; the match is reported in resolved_from).
  • pubtator_relation_evidence(type, entity1, entity2, page?) — every passage supporting one specific relation, 10 per page, with PMIDs. Use it to audit a relation pubtator_relations returned.
  • pubtator_annotations(pmids, full_text?) — entity annotations for up to 20 PMIDs: every mention in title + abstract (or PMC full text when full_text: true), normalized to NCBI Gene / MeSH / dbSNP / Taxonomy with character offsets, plus the relations extracted within each article.

Auth

Keyless.

Data sources

Things the next person would otherwise rediscover:

  • Entity ids are name-based and case-sensitive. The API wants @GENE_BRCA1, @DISEASE_Breast_Neoplasms, @CHEMICAL_Doxorubicin — not @GENE_672 or @DISEASE_MESH_D001943. A search for the database-id form returns HTTP 200 with count: 0 and no error, which is why every entity argument in this pack goes through autocomplete when it does not start with @.
  • Everything is a text-mining prediction. PubTator 3's relations come from a neural relation-extraction model and its annotations from entity recognizers (GNormPlus, TaggerOne, tmVar…). Nothing is human-curated. Each relation and the annotations envelope carry an extraction field saying so; supporting_publications is the model's evidence count, not a curation status.
  • Relation queries ignore entity order. relations:associate|A|B and relations:associate|B|A return the same count. Twelve relation types: associate, cause, compare, cotreat, drug_interact, inhibit, interact, negative_correlate, positive_correlate, prevent, stimulate, treat.
  • text_hl encoding. @<m>GENE_BRCA1</m> @GENE_672 @@@BRCA1@@@-mutated means: id tokens (query matches wrapped in <m>), then the surface mention wrapped in @@@. An id token is @ not followed by @@ — the first cut of the decoder treated @@@BRCA@@@ as an id and merged two mentions into one.
  • Autocomplete concepts. gene, disease, chemical and variant are dense; species and cellline return [] for common names ("mouse", "HeLa"). Drop the concept filter rather than concluding the entity is absent.
  • Full text is large. full=true on a PMC open-access article returns 100+ passages (119 for PMID 31022191) and the document id becomes the PMC number; the PMID is recovered from the first passage's article-id_pmid. Passages are truncated to 1,500 characters with truncated: true.
  • Page size is fixed at 10 by the upstream; there is no size parameter.

Quick Start

Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):

{
  "mcpServers": {
    "pubtator": {
      "url": "https://gateway.pipeworx.io/pubtator/mcp"
    }
  }
}

What this endpoint actually serves

tools/list at https://gateway.pipeworx.io/pubtator/mcp returns the tools in the table above plus the shared Pipeworx meta-tools — ask_pipeworx, discover_tools, search_within, remember/recall and the rest of the gateway-wide set. So the tool count you see is larger than this table: a single-pack endpoint currently lists roughly 30 shared tools alongside the pack's own. The connection's initialize response states its exact scope, and is the authoritative answer for a given day.

This is deliberate, not multiplexing by accident. The meta-tools are what let a scoped connection answer a question this pack does not cover — via ask_pipeworx, which routes across the whole catalog — without you adding a second MCP server. There is currently no way to mount a pack endpoint without them; if the extra schemas cost you more context than the routing is worth, connect to the full gateway once rather than to several pack endpoints.

Or connect to the full Pipeworx gateway to get every pack's tools listed directly, instead of just this one's:

{
  "mcpServers": {
    "pipeworx": {
      "url": "https://gateway.pipeworx.io/mcp"
    }
  }
}

Both URLs reach the same gateway and the same 1715+ data sources. The only difference is which pack's tools are listed directly; ask_pipeworx reaches all of them from either one.

No MCP client? Call it over HTTP

curl -X POST https://gateway.pipeworx.io/v1/tools/pubtator_find_entity \
  -H 'Content-Type: application/json' \
  -d '{"query":"BRCA1","concept":"gene","limit":5}'

No account needed for the first calls. Inspect any tool: GET https://gateway.pipeworx.io/v1/tools/pubtator_find_entity. Find one: POST https://gateway.pipeworx.io/v1/tools/search_packs with {"query":"..."}.

Standalone (no gateway account)

This package also runs as a local stdio MCP server — no Pipeworx account, no gateway round-trip:

{
  "mcpServers": {
    "pubtator": {
      "command": "npx",
      "args": ["-y", "@pipeworx/mcp-pubtator"]
    }
  }
}

Or run it directly to confirm it starts:

npx -y @pipeworx/mcp-pubtator

It speaks MCP over stdin/stdout and answers initialize/tools/list/tools/call for only this pack's tools — none of the shared meta-tools the gateway connection above adds. Same source, same tools, no ask_pipeworx routing.

Using with ask_pipeworx

Instead of calling tools directly, you can ask questions in plain English — this works on the pack endpoint above as well as on the full gateway:

ask_pipeworx({ question: "your question about Pubtator data" })

The gateway picks the right tool and fills the arguments automatically.

More

License

MIT

Reviews

No reviews yet

Be the first to review this server!