Unofficial MCP server that connects OpenEvidence to AI agents via the user's authenticated browser session
OpenEvidence MCP demonstrates good tool definition quality with comprehensive descriptions and proper input schemas. All 5 tools are explicitly registered with descriptions, input schemas, and clear annotations. Tool names follow the verb_noun pattern (oe_auth_status, oe_history_list, oe_article_get, oe_article_wait, oe_ask). Descriptions are detailed and contextually rich (140-350 chars each), explaining WHAT the tool does, WHEN to use it, and important caveats (e.g., privacy warnings about include_raw parameter, side-effect documentation for oe_ask). All parameters have type definitions and descriptions. However, some parameters lack enum constraints where they could be more restrictive (e.g., article_type in oe_ask accepts free-form string; poll_interval_ms lacks min/max bounds in schema despite being described as 300-10000). Output schemas are not explicitly documented in the tool registration, descriptions refer to returned fields but structured return types are not visible in the schema definitions. Error handling is implicit rather than explicit; no error messages or recovery guidance are visible in the tool definitions themselves. The server includes a helpful registered prompt ('openevidence_research_workflow') that guides usage, which partially compensates for missing error guidance at the tool level.
Fetch an OpenEvidence article by article_id. Use after history lookup or oe_ask returns an article ID. Inputs: article_id UUID, optional include_raw=false. Returns normalized status, question, and answer fields by default. include_raw=true may expose private thread context and must be used only with explicit user intent. Requires authenticated session. No side effects.
Wait for an existing OpenEvidence article_id to finish, then return normalized fields. Use after oe_ask with wait_for_completion=false, especially for long research questions that may exceed MCP host timeouts. Inputs: article_id UUID, optional timeout_sec, poll_interval_ms, and include_raw=false. include_raw=true may expose private thread context and must be used only with explicit user intent. Requires authenticated session. No side effects.
Create an OpenEvidence research question, not medical advice or patient-specific diagnosis. For long questions, prefer wait_for_completion=false and then call oe_article_wait with the returned article_id. Use original_article_id only for true follow-up continuity; omit it for fresh questions. Returns privacy-reduced created article data and optionally normalized completed fields. Side effect: creates a question/article in the user's OpenEvidence account through the local browser profile.
Check whether the saved OpenEvidence browser session is authenticated. Use before history/article/ask tools when auth state is unknown. Returns authenticated=true/false and basic account metadata when available. Requires the local browser profile created by npm run login:session. No side effects. Can fail if the profile is missing, expired, or network access fails.
Output schemas not documented in tool registration. Descriptions mention returned fields (e.g., 'Returns privacy-reduced list', 'Returns normalized status, question, and answer fields') but no structured output schema is visible in the tool definitions. LLMs cannot plan downstream operations without knowing exact response structure.
Parameters lack sufficient constraints in schema. poll_interval_ms is described as '300-10000' but schema does not specify minimum/maximum. article_type in oe_ask is free-form string; should be enum with valid article types. timeout_sec bounds (5-900, 5-600) are documented in descriptions but not in schema constraints.
No explicit error handling or recovery guidance in tool definitions. Descriptions mention failure modes ('Can fail if the profile is missing, expired, or network access fails') but do not provide actionable recovery steps or error classifications. No indication of which errors are retryable vs fatal.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 45 | - | v1 |
List prior OpenEvidence articles from the authenticated account. Use only when the user asks to inspect prior OpenEvidence work or needs an article_id. Inputs: limit, offset, optional search, optional include_raw=false. Returns a privacy-reduced list by default; include_raw=true may expose private prior questions and must be used only with explicit user intent. Requires authenticated session. No side effects.
Tool annotations present (readOnlyHint, idempotentHint on oe_auth_status) but incomplete across all tools. oe_ask declares a WRITE risk and has side effects (creates article in user account) but lacks destructiveHint annotation. Read-only tools should have readOnlyHint and idempotentHint consistently applied.
Privacy-sensitive parameter (include_raw) behavior documented in descriptions but no schema validation or default enforcement visible. LLMs could overlook the privacy implications if relying solely on parameter defaults rather than explicit security gates.
Parameter dependencies not formally declared. oe_ask's original_article_id only applies when wait_for_completion is true or when doing follow-up; this relationship is mentioned in descriptions but not formalized. oe_ask's wait_for_completion=false requires subsequent oe_article_wait call, this multi-step workflow is implied but not structurally enforced.