by JamesANZ
An MCP server that provides comprehensive medical information by querying multiple authoritative medical APIs including FDA, WHO, PubMed, Google Scholar, and RxNorm
# Add to your Claude Code skills
git clone https://github.com/JamesANZ/medical-mcpGuides for using mcp servers skills like medical-mcp.
Last scanned: 6/17/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@babel/core: @babel/core: Arbitrary File Read via sourceMappingURL Comment",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@istanbuljs/load-nyc-config: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jest/core: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jest/expect: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jest/globals: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jest/reporters: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jest/transform: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@modelcontextprotocol/sdk: Anthropic's MCP TypeScript SDK has a ReDoS vulnerability",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "babel-jest: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "babel-plugin-istanbul: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "basic-ftp: Basic FTP has Path Traversal Vulnerability in its downloadToDir()ย method",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser is vulnerable to denial of service when url encoding is used",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "create-jest: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "form-data: form-data uses unsafe random function in form-data for choosing boundary",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "handlebars: Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-circus: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-cli: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-config: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-resolve-dependencies: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-runner: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-runtime: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jest-snapshot: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "js-yaml: js-yaml has prototype pollution in merge (<<)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "socks: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tar-fs: tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ts-jest: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-06-17T09:03:59.699Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how medical-mcp compares with popular alternatives.
medical-mcp is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by JamesANZ. An MCP server that provides comprehensive medical information by querying multiple authoritative medical APIs including FDA, WHO, PubMed, Google Scholar, and RxNorm. It has 112 GitHub stars.
medical-mcp failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/JamesANZ/medical-mcp" and add it to your Claude Code skills directory (see the Installation section above).
medical-mcp is primarily written in TypeScript. It is open-source under JamesANZ on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh medical-mcp against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
โ ๏ธ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Bring trusted medical data directly into your AI workflow. A local server for private, free access to FDA, WHO, PubMed, RxNorm, Semantic Scholar, and Google Scholar. No API keys. No data leaks.
An MCP (Model Context Protocol) server that brings authoritative medical information into AI coding environments like Cursor and Claude Desktop.
NCBI_API_KEY env var boosts PubMed from 3 req/sec to 10 req/sechealth-check pings all upstream sources and reports latency, circuit breaker states, rate limiter status, and cache healthInstall in Cursor (Recommended):
Or install manually:
npm install -g medical-mcp
# Or from source:
git clone https://github.com/JamesANZ/medical-mcp.git
cd medical-mcp && npm install && npm run build
search-drugs โ Search FDA, DailyMed, TGA (Australia), Health Canada, and EMA. Filter with countries (US, AU, CA, EU)get-drug-details โ Get comprehensive US drug info by NDC codesearch-drug-nomenclature โ Standardized drug names via RxNormsearch-drug-safety โ FDA FAERS adverse events, recalls, and shortagesget-health-statistics โ WHO Global Health Observatory data (life expectancy, mortality, disease prevalence)search-medical-literature โ Search 30M+ PubMed articles (with evidence grading)get-article-details โ Detailed article info by PMIDsearch-google-scholar โ Academic papers via Monid TinyFish (research_paper) when MONID_API_KEY is set; otherwise Semantic Scholarsearch-medical-databases โ Multi-database search (PubMed, Scholar, Semantic Scholar, Cochrane, ClinicalTrials.gov, Europe PMC)search-medical-journals โ Top journals (NEJM, JAMA, Lancet, BMJ, Nature Medicine)search-clinical-guidelines โ Practice recommendations from medical organizationssearch-clinical-trials โ ClinicalTrials.gov plus Australia/New Zealand location coveragelist-sources โ Full catalog of registry adapters and dedicated-tool sources (WHO, PubMed, RxNorm, Scholar, Cochrane, AAP), including which MCP tool reaches each. This is not the search-drugs five-regulator fanout.search-pediatric-guidelines โ AAP guidelines and Bright Futures preventive caresearch-pediatric-literature โ Research from major pediatric journalsget-child-health-statistics โ Pediatric health indicators from WHOsearch-pediatric-drugs โ Drugs with pediatric labeling and dosing informationsearch-aap-guidelines โ Comprehensive AAP guideline search (Bright Futures + Policy Statements)health-check โ Ping all upstream sources, report latency/status, circuit breaker states, and cache healthget-cache-stats โ View cache statistics (hit rate, memory usage, entry count)Click the install link above or use:
cursor://anysphere.cursor-deeplink/mcp/install?name=medical-mcp&config=eyJtZWRpY2FsLW1jcCI6eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIm1lZGljYWwtbWNwIl19fQ==
Requirements: Node.js 18+ and npm
git clone https://github.com/JamesANZ/medical-mcp.git
cd medical-mcp
npm install
npm run build
npm start
Add to claude_desktop_config.json:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"medical-mcp": {
"command": "node",
"args": ["/absolute/path/to/medical-mcp/build/index.js"],
"env": {
"NCBI_API_KEY": "your_optional_key_here"
}
}
}
}
Restart Claude Desktop after configuration.
{
"tool": "search-drugs",
"arguments": { "query": "Tylenol", "limit": 5 }
}
Results now include evidence tags:
1. Efficacy of COVID-19 Treatments: A Meta-Analysis
Evidence: [Systematic Review / Meta-Analysis โข Grade I]
Authors: Smith J, Jones K...
2. Randomized Trial of Remdesivir in Adults
Evidence: [Randomized Controlled Trial โข Grade II]
Authors: Chen L, Wang M...
{ "tool": "health-check", "arguments": {} }
Returns:
โ
FDA: healthy (234ms)
โ
PubMed: healthy (156ms)
โ
WHO: healthy (890ms)
โ
RxNorm: healthy (312ms)
โ
ClinicalTrials: healthy (445ms)
โ
SemanticScholar: healthy (189ms)
NCBI API Key: โ
Configured (10 req/sec PubMed)
Every API call flows through a three-layer resilience stack:
Request โ Rate Limiter โ Circuit Breaker โ Retry (with backoff) โ Upstream API
PubMed and multi-database results are automatically classified:
| Grade | Study Type | Examples |
|---|---|---|
| I | Systematic Review / Meta-Analysis | Cochrane reviews, PRISMA studies |
| II | Randomized Controlled Trial | Double-blind placebo-controlled trials |
| III | Cohort / Case-Control Study | Prospective, retrospective, population-based |
| IV | Case Report / Case Series | Clinical case presentations |
| V | Expert Opinion / Editorial | Commentaries, perspectives, narrative reviews |
When MONID_API_KEY is set, Scholar/Cochrane/AAP search and PMC HTML fetch go through Monid TinyFish. Without a key, Scholar falls back to Semantic Scholar's API โ free, well-structured, 100 req/sec, no API key needed.
All upstream API responses are validated against Zod schemas. If a source changes their API response format, the server logs a warning but continues operating with raw data โ no crashes, just alerts.
| Source | Coverage | Update Frequency | Resilience |
|---|---|---|---|
| FDA | US approved drug labels | Real-time | Circuit breaker + retry |
| DailyMed | US structured product labels | Daily | Circuit breaker + retry |
| TGA ARTG | Australian Register of Therapeutic Goods | Real-time | Circuit breaker + retry |
| Health Canada DPD | Canadian marketed/approved drugs | Real-time | Circuit breaker + retry |
| EMA | EU centrally authorised medicines | Twice daily JSON | In-memory cache + retry |
| FDA FAERS / recalls / shortages | US safety signals | Real-time | Circuit breaker + retry |
| WHO | Global hea |