Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add mcp/tc2fh/reactome-db-mcp/reactome-dbgit clone --depth 1 https://github.com/tc2fh/reactome-db-mcpGrade A, and why
reactome-db scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"reactome-db": {
"type": "stdio",
"command": "uv",
"args": [
"run",
"--directory",
"/absolute/path/to/reactome-db-mcp",
"reactome-db-mcp"
],
"env": {
"REACTOME_DB_NAME": "reactome_local"
}
}
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 15 lines scan A d795772f5b97
reactome-db is an MCP server published in the GitHub repository tc2fh/reactome-db-mcp (0 stars, last pushed 2mo ago), licensed MIT. Its token cost is not measured: an MCP server costs its tool schemas, not its config file. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other mcp servers, from other repositories
chemdraw-mcp
MCP server that turns molecule names or SMILES into publication-style 2D structure drawings (PNG/SVG via RDKit) — reaction schemes, mechanisms, spectra. Unofficial, not affiliated with Revvity. Runs locally from the chemdraw-mcp Python package.
health-system-profiler
MCP server "health-system-profiler" as configured in ajhcs/healthcare-data-mcp. Launched with hc-mcp health-system-profiler.
IURA EU
MCP server "IURA EU", hosted remotely at mcp.iura.io, as configured in iura-ai/IURA-Plugins.
anvisa_bulario_eletronico-mcp
ANVISA: Bulário Eletrônico, official-source lookup. Platform-hosted, pay per query with prepaid cred. Remote server at api.mcp.ai.
clinical-trials-ai-mcp
MCP server for clinical trials ai. Features search trials, check eligibility, get trial details. From MEOK AI Labs. Runs locally from the clinical-trials-ai-mcp Python package.
math-anchor
MCP server "math-anchor" as configured in tetracoralla/math-anchor. Launched with runtime/math-anchor-runtime/math-anchor-runtime mcp.