Scholar Sidekick (mlava/scholar-sidekick-mcp) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 7 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.

B
Warning
89/100
5 days ago

Scholar Sidekick

Resolves scholarly identifiers — DOI, PubMed ID, PMCID, ISBN, ISSN, arXiv, ADS bibcode — into clean, formatted citations in any of 10,000+ CSL styles. Returns plain text, HTML, Markdown, RIS, BibTeX, CSL-JSON, or EndNote XML for direct paste or reference manager import.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code VerifiedSandbox Verified⚡ Live Monitored

Monitored 8 days · every push re-verified

Who stands behind it

scholar-sidekick.com (@mlava) · Verified Publisher

Source: Glama

Maintenance & responsiveness
as of 2026-08-20
Issues closed (90d): 0 · 0 open
Releases (90d): 10
Contributor retention: 1/1 stayed · 1 active

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: RAPIDAPI_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 2 credentials: RAPIDAPI_KEY, SCHOLAR_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
Are you the publisher? Confirm or correct these findings.
// environment variables
To run this server yourself, you supply these values.
configRAPIDAPI_HOSTNo RapidAPI host (defaults to scholar-sidekick.p.rapidapi.com)
🔐 secretRAPIDAPI_KEYset (which routes calls through the RapidAPI gateway).
🔐 secretSCHOLAR_API_KEY[scholar-sidekick.com/account](https://scholar-sidekick.com/account) and set .
configSCHOLAR_SIDEKICK_TIMEOUT_MSNo Request timeout in milliseconds (default: 30000)
configSCHOLAR_SIDEKICK_URLNo Override the API base URL (defaults to https://scholar-sidekick.com, or the RapidAPI gateway when RAPIDAPI_KEY is set).
// quality suggestions

Secrets stay with their owner

1 secret/sensitive value flow into network calls (RAPIDAPI_KEY → dynamic)

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/mlava-scholar-sidekick-mcp-1laij3?variant=verified)](https://m8ven.ai/mcp/mlava-scholar-sidekick-mcp-1laij3)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 0b5159a8eeed3ed42b76b4e2d438b5f21107ecb2
code hash: 4c7eb415535e3291935085883dd34c56a9795f95ecb25236b9ac3dd1b0f9164e
verified: 8/23/2026, 4:07:06 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client