gbif-mcp (tyson-swetnam/gbif-mcp) is an MCP server listed on the M8ven Trust Index. It scores 54 out of 100, grade D. It declares 58 tools. No publisher has claimed this listing.

D
Caution
54/100

gbif-mcp

Enables AI assistants to query and retrieve biodiversity data from the Global Biodiversity Information Facility (GBIF), including species, occurrences, datasets, and literature.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

tyson-swetnam

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical, 14 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 1 credential: GBIF_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes58 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

gbif_literature_get

Get complete metadata for a scientific publication by its DOI. Returns title, authors, abstract, journal, citation info, and GBIF usage details. Use to get full details about a specific paper that used GBIF data.

gbif_literature_search

Search scientific literature that cites GBIF data. Find peer-reviewed publications, reports, and papers that used GBIF-mediated data. Useful for understanding data impact, finding research examples, and tracking biodiversity research trends.

gbif_maps_get_raster_tile_url

Generate URL for pre-rendered PNG density map tiles. Raster tiles show occurrence density with various color schemes. Fast rendering, ideal for simple map displays. Use for quick visualization without client-side rendering overhead.

gbif_maps_get_tile_url

Generate a URL for occurrence map tiles with customizable styling and filters. Returns tile URLs in standard web Mercator projection (EPSG:3857) for use in web mapping applications, GIS software, or direct visualization.

gbif_maps_get_vector_tile_url

Generate URL for occurrence vector tiles in Mapbox Vector Tile (MVT) format. Vector tiles enable client-side styling, interactivity, and dynamic rendering. Ideal for web mapping libraries like Mapbox GL JS, Leaflet with vector tile plugins, or OpenLayers.

gbif_maps_list_styles

List all available map visualization styles for occurrence tiles. Returns style names, descriptions, and types (density/point/poly). Use to discover visualization options before generating tile URLs with gbif_maps_get_tile_url.

gbif_occurrence_count

Fast endpoint for counting occurrences matching filters without retrieving full records. Useful for statistics, dashboards, and filter validation before running full searches.

gbif_occurrence_counts_by_basis_of_record

Get occurrence counts broken down by basis of record type (observations, specimens, etc.). Returns a breakdown showing how many occurrences of each type match your filters. Essential for understanding dataset composition and data quality. Very fast - use for dashboards and quick statistics.

gbif_occurrence_counts_by_country

Get occurrence counts broken down by country for geographic distribution analysis. Returns counts per country showing global distribution patterns. Essential for understanding species ranges, identifying data gaps by region, and prioritizing conservation efforts. Fast statistics endpoint.

gbif_occurrence_counts_by_dataset

Get occurrence counts broken down by contributing dataset. Identifies which datasets contribute most records for a given query. Essential for data attribution, understanding data sources, finding primary datasets for a taxon/region, and acknowledging data providers. Returns dataset UUIDs with counts

gbif_occurrence_counts_by_publishing_country

Get occurrence counts broken down by the country of the publishing organization. Shows which countries are contributing data, useful for understanding data provider distribution, identifying data collaboration opportunities, and analyzing global participation in GBIF. Different from occurrence count

gbif_occurrence_counts_by_publishing_org

Get occurrence counts broken down by publishing organization UUID. Identifies which institutions are contributing the most data for a query. Essential for data attribution, understanding institutional contributions, acknowledging data providers, and analyzing organizational participation. Returns or

gbif_occurrence_counts_by_taxon

Get occurrence counts broken down by taxon key for taxonomic composition analysis. Returns counts per child taxon showing species-level distribution. Useful for understanding biodiversity patterns, identifying dominant species, and analyzing taxonomic coverage within a higher taxon. Fast statistics

gbif_occurrence_counts_by_year

Get occurrence counts broken down by year for temporal trend analysis. Returns year-by-year counts showing how observations have accumulated over time. Perfect for time series visualization, identifying data collection patterns, and understanding temporal coverage. Fast endpoint for dashboards.

gbif_occurrence_download_status

Check the status and retrieve metadata for an occurrence download request. Returns status, download link when ready, record count, and file size.

gbif_occurrence_download_request

Request an asynchronous download for large occurrence datasets beyond pagination limits (100,000+ records). Returns a download key for checking status. REQUIRES AUTHENTICATION: Set GBIF_USERNAME and GBIF_PASSWORD environment variables.

gbif_occurrence_download_predicate_builder

Helper tool to build a download predicate from simple search parameters. Converts occurrence search filters into the complex predicate format required by the download API.

gbif_occurrence_get

Get complete details for a single occurrence record including verbatim fields, interpretation history, media, and data quality issues.

gbif_occurrence_search

Search GBIF occurrence records (species observations and specimens) with comprehensive filtering by taxonomy, geography, time, data quality, and more. Returns paginated results with optional facets for aggregations.

gbif_occurrence_verbatim

Get the original, unprocessed occurrence record as provided by the publisher, before GBIF interpretation. Includes all original Darwin Core fields with full URIs.

gbif_registry_dataset_document

Get the EML (Ecological Metadata Language) metadata document for a dataset. Returns structured XML metadata including dataset description, contacts, geographic/taxonomic/temporal coverage, methods, and project information. Essential for proper dataset citation, understanding data collection methods,

gbif_registry_dataset_metrics

Get occurrence statistics and quality metrics for a dataset. Returns counts by basis of record, country, year, and data quality indicators. Useful for understanding dataset composition and coverage.

gbif_registry_get_collection

Get complete details for a specific scientific collection from GRSciColl. Returns collection metadata, institutional affiliation, specimen holdings, contacts, and preservation methods. Essential for understanding physical specimen repositories.

gbif_registry_get_dataset

Get complete metadata for a specific GBIF dataset by its UUID. Returns full dataset details including title, description, contacts, endpoints, geographic/taxonomic coverage, and citation information.

gbif_registry_get_installation

Get complete details for a specific IPT or data server installation. Returns technical endpoint information, hosting organization, and datasets served by this installation.

gbif_registry_get_institution

Get complete details for a specific scientific institution from GRSciColl. Returns institutional metadata, collections housed, contacts, addresses, and identifiers. Use to understand institution profiles and their collection holdings.

gbif_registry_get_network

Get complete details for a specific dataset network. Returns network metadata, constituent datasets, contacts, and description. Use to understand collaborative data initiatives and their scope.

gbif_registry_get_node

Get complete details for a GBIF participant node. Returns node metadata, contacts, participation type, country information, and endorsement details. Use to understand national GBIF participation, governance structure, and institutional membership.

gbif_registry_get_organization

Get complete details for a specific data-publishing organization. Returns contacts, addresses, datasets published, endorsement status, and institutional information.

gbif_registry_list_nodes

List GBIF participant nodes (national/organizational participants). Nodes represent countries or organizations that participate in GBIF governance and data sharing. Essential for understanding GBIF network structure, national participation, and institutional membership.

gbif_registry_network_datasets

List all constituent datasets within a specific network. Shows which datasets are part of a collaborative network. Useful for exploring thematic data collections like eBird observations or marine biodiversity networks.

gbif_registry_organization_datasets

List all datasets published by a specific organization. Shows the complete catalog of datasets contributed by an institution. Useful for understanding an organization's data contributions and portfolio.

gbif_registry_search_collections

Search the Global Registry of Scientific Collections (GRSciColl) for natural history collections. Find museum collections, herbaria, tissue collections, and other scientific collections worldwide. Use to discover physical specimen holdings and their metadata.

gbif_registry_search_datasets

Search for datasets in the GBIF registry. Find published datasets by type, keyword, publisher, geographic coverage, and taxonomic scope. Essential for discovering data sources and understanding dataset metadata.

gbif_registry_search_installations

Search for IPT (Integrated Publishing Toolkit) installations in the GBIF network. IPTs are servers that host and publish biodiversity datasets. Use to find technical infrastructure and data hosting platforms.

gbif_registry_search_institutions

Search for scientific institutions in the Global Registry of Scientific Collections (GRSciColl). Find museums, herbaria, universities, and research institutions that house natural history collections worldwide.

gbif_registry_search_networks

Search for dataset networks in GBIF. Networks are collaborative groups that organize related datasets (e.g., eBird, iNaturalist, Ocean Biodiversity Information System). Use to discover thematic data collections and partnerships.

gbif_registry_search_organizations

Search for data-publishing organizations in the GBIF network. Find museums, herbaria, research institutions, and other biodiversity data publishers. Use to discover data providers and understand institutional participation.

gbif_species_children

Get direct taxonomic children of a taxon (e.g., species under a genus, subspecies under a species). Useful for exploring taxonomy hierarchically.

gbif_species_descriptions

Get textual descriptions for a species from various sources. Includes morphological descriptions, habitat information, behavior, and other narrative content.

gbif_species_distributions

Get known geographic distribution records for a species. Includes information about occurrence status, establishment means, and locality details.

gbif_species_media

Get associated multimedia records for a species including images, sounds, and videos. Returns URLs and metadata for media resources from various sources.

gbif_species_metrics

Get quick occurrence statistics for a species without running full searches. Returns total occurrence count, dataset count, country count, and basis of record breakdown. Fast endpoint perfect for species profile pages, dashboards, and quick data availability checks.

gbif_species_parents

Get the complete taxonomic classification path from kingdom down to the specified taxon. Returns the full hierarchy including all parent taxa. Useful for breadcrumb navigation and understanding taxonomic position.

gbif_species_parse_names

Parse and standardize scientific names in batch using GBIF's name parser. Extracts genus, species, authorship, rank, and more from scientific name strings. Essential for data cleaning, quality checking, and standardizing names from spreadsheets or databases. Handles up to 1000 names per request.

gbif_species_related

Get related species including siblings (same parent taxon), variants, and associated taxa. Useful for taxonomic exploration, "see also" functionality, discovering similar species, and understanding taxonomic relationships. Returns species at the same taxonomic level with shared higher classification

gbif_species_search

Search for species in the GBIF taxonomic backbone. Supports filtering by rank, status, habitat, threat level, and more.

gbif_species_get

Get detailed information about a specific species by its GBIF key.

gbif_species_suggest

Get species name suggestions for autocomplete functionality.

gbif_species_match

Fuzzy match a species name against the GBIF backbone taxonomy.

gbif_species_synonyms

Get all synonyms and alternative scientific names for a species. Useful for name resolution and historical name tracking.

gbif_species_vernacular_names

Get vernacular (common) names for a species in multiple languages. Returns preferred names when available.

gbif_validator_get_status

Check the status of an asynchronous Darwin Core Archive validation job. Validation is processed asynchronously, so use this tool to poll for completion and retrieve results. Returns validation status, progress, and results when complete.

gbif_validator_validate_dwca

Validate a Darwin Core Archive (DwC-A) file against GBIF standards. Checks data structure, required fields, data quality, and format compliance. Returns validation report with issues, warnings, and recommendations. Essential before publishing datasets to GBIF.

gbif_validator_validate_tabular

Validate tabular data files (CSV, TSV) against Darwin Core standards before creating archives. Checks column headers, data types, required fields, and format compliance. Useful for data preparation workflows, pre-publication validation, and quality assurance before creating Darwin Core Archives. Ret

gbif_vocabularies_get_concept

Get detailed information about a specific concept within a controlled vocabulary. Returns the concept definition, usage notes, related terms, and examples. Use to understand the precise meaning and usage of specific vocabulary terms.

gbif_vocabularies_get

Get a specific controlled vocabulary with all its concepts and definitions. Returns the complete vocabulary including all valid values, descriptions, and usage notes. Use to understand valid values for specific GBIF fields.

gbif_vocabularies_list

List all controlled vocabularies used in GBIF. Vocabularies define valid values for fields like basisOfRecord, establishmentMeans, occurrenceStatus, etc. Essential for understanding valid filter values and data standardization.

// known CVEs in dependencies2 critical14 high4 medium12 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@1.0.0GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

criticalvitest@1.0.0GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.6.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.6.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configCACHE_CHECK_PERIOD
configCACHE_ENABLED
configCACHE_MAX_SIZE
configCACHE_TTL
configENABLE_AUTH
configENABLE_CACHE
configENABLE_METRICS
configENABLE_VALIDATION
configGBIF_BASE_URL
🔐 secretGBIF_PASSWORD"": "your-password"
configGBIF_RETRY_ATTEMPTS
configGBIF_RETRY_DELAY
configGBIF_TIMEOUT
configGBIF_USERNAME"": "your-username",
configGBIF_USER_AGENTGBIF-MCP-Server/1.0.0
configLOG_FORMAT
configLOG_LEVELdebug # Change log level
configLOG_MASK_SENSITIVE
configRATE_LIMIT_BACKOFF_MULTIPLIER
configRATE_LIMIT_CONCURRENT
configRATE_LIMIT_MAX_BACKOFF
configRATE_LIMIT_MAX_REQUESTS
configRESPONSE_ENABLE_SIZE_LOGGINGtrue # Log size metrics
configRESPONSE_ENABLE_TRUNCATIONtrue # Enable smart truncation
configRESPONSE_MAX_SIZE_KBMaximum Response Size: 250KB (configurable via )
configRESPONSE_WARN_SIZE_KB200 # Warning threshold
configSERVER_DESCRIPTION
configSERVER_NAME
configSERVER_VERSION
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

58/58 tools missing one or more hints — gbif_literature_get (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); gbif_literature_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); gbif_maps_get_raster_tile_url (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +55 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

40/58 tools referenced in tests (69%)

Write tests that reference each tool by name so every tool has at least one test.

Production dependencies are patched

0 critical, 14 high severity in production deps — @modelcontextprotocol/sdk@1.0.0 (high), axios@1.6.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Dev dependencies

2 critical/high in dev-only deps (does not ship to users)

Upgrade dev dependencies when convenient.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/tyson-swetnam/gbif-mcp?variant=verified)](https://m8ven.ai/mcp/tyson-swetnam/gbif-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 5988b3e0a5d232b1fe6bc176ea8fd79c97639f36
code hash: f4a310b7a47dfabfaed5b30f46e5f44f3fefaa6818afa814c5c5a69aa0fcec8c
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client