# zoteus - Doramagic AI Context Pack

> 定位：安装前体验与判断资产。它帮助宿主 AI 有一个好的开始，但不代表已经安装、执行或验证目标项目。

## 充分原则

- **充分原则，不是压缩原则**：AI Context Pack 应该充分到让宿主 AI 在开工前理解项目价值、能力边界、使用入口、风险和证据来源；它可以分层组织，但不以最短摘要为目标。
- **压缩策略**：只压缩噪声和重复内容，不压缩会影响判断和开工质量的上下文。

## 给宿主 AI 的使用方式

你正在读取 Doramagic 为 zoteus 编译的 AI Context Pack。请把它当作开工前上下文：帮助用户理解适合谁、能做什么、如何开始、哪些必须安装后验证、风险在哪里。不要声称你已经安装、运行或执行了目标项目。

## Claim 消费规则

- **事实来源**：Repo Evidence + Claim/Evidence Graph；Human Wiki 只提供显著性、术语和叙事结构。
- **事实最低状态**：`supported`
- `supported`：可以作为项目事实使用，但回答中必须引用 claim_id 和证据路径。
- `weak`：只能作为低置信度线索，必须要求用户继续核实。
- `inferred`：只能用于风险提示或待确认问题，不能包装成项目事实。
- `unverified`：不得作为事实使用，应明确说证据不足。
- `contradicted`：必须展示冲突来源，不得替用户强行选择一个版本。

## 它最适合谁

- **AI 研究者或研究型 Agent 构建者**：README 明确围绕研究、实验或论文工作流展开。 证据：`README.md` Claim：`clm_0002` supported 0.86
- **正在使用 Claude/Codex/Cursor/Gemini 等宿主 AI 的开发者**：README 或插件配置提到多个宿主 AI。 证据：`README.md` Claim：`clm_0003` supported 0.86

## 它能做什么

- **命令行启动或安装流程**（需要安装后验证）：项目文档中存在可执行命令，真实使用需要在本地或宿主环境中运行这些命令。 证据：`README.md` Claim：`clm_0001` supported 0.86

## 怎么开始

- `npx -y @oscardvs/zoteus` 证据：`README.md` Claim：`clm_0004` supported 0.86, `clm_0005` supported 0.86
- `claude mcp add --transport stdio zoteus -e ZOTERO_API_KEY=xxxxx -- npx -y @oscardvs/zoteus` 证据：`README.md` Claim：`clm_0005` supported 0.86

## 继续前判断卡

- **当前建议**：需要管理员/安全审批
- **为什么**：继续前可能涉及密钥、账号、外部服务或敏感上下文，建议先经过管理员或安全审批。

### 30 秒判断

- **现在怎么做**：需要管理员/安全审批
- **最小安全下一步**：先跑 Prompt Preview；若涉及凭证或企业环境，先审批再试装
- **先别相信**：研究结论、引用和实验结果不能在安装前相信。
- **继续会触碰**：研究判断、命令执行、本地环境或项目文件

### 现在可以相信

- **适合人群线索：AI 研究者或研究型 Agent 构建者**（supported）：有 supported claim 或项目证据支撑，但仍不等于真实安装效果。 证据：`README.md` Claim：`clm_0002` supported 0.86
- **适合人群线索：正在使用 Claude/Codex/Cursor/Gemini 等宿主 AI 的开发者**（supported）：有 supported claim 或项目证据支撑，但仍不等于真实安装效果。 证据：`README.md` Claim：`clm_0003` supported 0.86
- **能力存在：命令行启动或安装流程**（supported）：可以相信项目包含这类能力线索；是否适合你的具体任务仍要试用或安装后验证。 证据：`README.md` Claim：`clm_0001` supported 0.86
- **存在 Quick Start / 安装命令线索**（supported）：可以相信项目文档出现过启动或安装入口；不要因此直接在主力环境运行。 证据：`README.md` Claim：`clm_0004` supported 0.86, `clm_0005` supported 0.86

### 现在还不能相信

- **研究结论、引用和实验结果不能在安装前相信。**（unverified）：研究 Skill 可以组织问题和路径，但不能替代真实资料检索、论文核验和实验复现。
- **是否适合你的具体研究领域不能直接相信。**（unverified）：Skill 覆盖很多研究主题，不代表对你的领域、资料要求和可信度标准足够。
- **真实输出质量不能在安装前相信。**（unverified）：Prompt Preview 只能展示引导方式，不能证明真实项目中的结果质量。
- **宿主 AI 版本兼容性不能在安装前相信。**（unverified）：Claude、Cursor、Codex、Gemini 等宿主加载规则和版本差异必须在真实环境验证。
- **不会污染现有宿主 AI 行为，不能直接相信。**（inferred）：Skill、plugin、AGENTS/CLAUDE/GEMINI 指令可能改变宿主 AI 的默认行为。
- **可安全回滚不能默认相信。**（unverified）：除非项目明确提供卸载和恢复说明，否则必须先在隔离环境验证。
- **真实安装后是否与用户当前宿主 AI 版本兼容？**（unverified）：兼容性只能通过实际宿主环境验证。
- **项目输出质量是否满足用户具体任务？**（unverified）：安装前预览只能展示流程和边界，不能替代真实评测。

### 继续会触碰什么

- **研究判断**：问题拆解、资料路径、实验路径、结论结构和可信度判断。 原因：研究型 Skill 可能让输出看起来更专业，但不能替代真实证据核验。
- **命令执行**：包管理器、网络下载、本地插件目录、项目配置或用户主目录。 原因：运行第一条命令就可能产生环境改动；必须先判断是否值得跑。 证据：`README.md`
- **本地环境或项目文件**：安装结果、插件缓存、项目配置或本地依赖目录。 原因：安装前无法证明写入范围和回滚方式，需要隔离验证。 证据：`README.md`
- **环境变量 / API Key**：项目入口文档明确出现 API key、token、secret 或账号凭证配置。 原因：如果真实安装需要凭证，应先使用测试凭证并经过权限/合规判断。 证据：`README.md`, `docs/configuration.md`, `docs/deployment.md`, `docs/distribution.md` 等
- **宿主 AI 上下文**：AI Context Pack、Prompt Preview、Skill 路由、风险规则和项目事实。 原因：导入上下文会影响宿主 AI 后续判断，必须避免把未验证项包装成事实。

### 最小安全下一步

- **先跑 Prompt Preview**：先验证它能否正确界定研究问题和证据边界，不要先相信研究输出。（适用：任何项目都适用，尤其是输出质量未知时。）
- **只在隔离目录或测试账号试装**：避免安装命令污染主力宿主 AI、真实项目或用户主目录。（适用：存在命令执行、插件配置或本地写入线索时。）
- **不要使用真实生产凭证**：环境变量/API key 一旦进入宿主或工具链，可能产生账号和合规风险。（适用：出现 API、TOKEN、KEY、SECRET 等环境线索时。）
- **安装后只验证一个最小任务**：先验证加载、兼容、输出质量和回滚，再决定是否深用。（适用：准备从试用进入真实工作流时。）

### 退出方式

- **保留安装前状态**：记录原始宿主配置和项目状态，后续才能判断是否可恢复。
- **保留资料和结论核验清单**：如果后续发现引用或实验路径不可靠，可以回到证据边界阶段重新校验。
- **记录安装命令和写入路径**：没有明确卸载说明时，至少要知道哪些目录或配置需要手动清理。
- **准备撤销测试 API key 或 token**：测试凭证泄露或误用时，可以快速止损。
- **如果没有回滚路径，不进入主力环境**：不可回滚是继续前阻断项，不应靠信任或运气继续。

## 哪些只能预览

- 解释项目适合谁和能做什么
- 基于项目文档演示典型对话流程
- 帮助用户判断是否值得安装或继续研究

## 哪些必须安装后验证

- 真实安装 Skill、插件或 CLI
- 执行脚本、修改本地文件或访问外部服务
- 验证真实输出质量、性能和兼容性

## 边界与风险判断卡

- **把安装前预览误认为真实运行**：用户可能高估项目已经完成的配置、权限和兼容性验证。 处理方式：明确区分 prompt_preview_can_do 与 runtime_required。 Claim：`clm_0006` inferred 0.45
- **命令执行会修改本地环境**：安装命令可能写入用户主目录、宿主插件目录或项目配置。 处理方式：先在隔离环境或测试账号中运行。 证据：`README.md` Claim：`clm_0007` supported 0.86
- **待确认**：真实安装后是否与用户当前宿主 AI 版本兼容？。原因：兼容性只能通过实际宿主环境验证。
- **待确认**：项目输出质量是否满足用户具体任务？。原因：安装前预览只能展示流程和边界，不能替代真实评测。
- **待确认**：安装命令是否需要网络、权限或全局写入？。原因：这影响企业环境和个人环境的安装风险。

## 开工前工作上下文

### 加载顺序

- 先读取 how_to_use.host_ai_instruction，建立安装前判断资产的边界。
- 读取 claim_graph_summary，确认事实来自 Claim/Evidence Graph，而不是 Human Wiki 叙事。
- 再读取 intended_users、capabilities 和 quick_start_candidates，判断用户是否匹配。
- 需要执行具体任务时，优先查 role_skill_index，再查 evidence_index。
- 遇到真实安装、文件修改、网络访问、性能或兼容性问题时，转入 risk_card 和 boundaries.runtime_required。

### 任务路由

- **命令行启动或安装流程**：先说明这是安装后验证能力，再给出安装前检查清单。 边界：必须真实安装或运行后验证。 证据：`README.md` Claim：`clm_0001` supported 0.86

### 上下文规模

- 文件总数：144
- 重要文件覆盖：40/144
- 证据索引条目：62
- 角色 / Skill 条目：17

### 证据不足时的处理

- **missing_evidence**：说明证据不足，要求用户提供目标文件、README 段落或安装后验证记录；不要补全事实。
- **out_of_scope_request**：说明该任务超出当前 AI Context Pack 证据范围，并建议用户先查看 Human Manual 或真实安装后验证。
- **runtime_request**：给出安装前检查清单和命令来源，但不要替用户执行命令或声称已执行。
- **source_conflict**：同时展示冲突来源，标记为待核实，不要强行选择一个版本。

## Prompt Recipes

### 适配判断

- 目标：判断这个项目是否适合用户当前任务。
- 预期输出：适配结论、关键理由、证据引用、安装前可预览内容、必须安装后验证内容、下一步建议。

```text
请基于 zoteus 的 AI Context Pack，先问我 3 个必要问题，然后判断它是否适合我的任务。回答必须包含：适合谁、能做什么、不能做什么、是否值得安装、证据来自哪里。所有项目事实必须引用 evidence_refs、source_paths 或 claim_id。
```

### 安装前体验

- 目标：让用户在安装前感受核心工作流，同时避免把预览包装成真实能力或营销承诺。
- 预期输出：一段带边界标签的体验剧本、安装后验证清单和谨慎建议；不含真实运行承诺或强营销表述。

```text
请把 zoteus 当作安装前体验资产，而不是已安装工具或真实运行环境。

请严格输出四段：
1. 先问我 3 个必要问题。
2. 给出一段“体验剧本”：用 [安装前可预览]、[必须安装后验证]、[证据不足] 三种标签展示它可能如何引导工作流。
3. 给出安装后验证清单：列出哪些能力只有真实安装、真实宿主加载、真实项目运行后才能确认。
4. 给出谨慎建议：只能说“值得继续研究/试装”“先补充信息后再判断”或“不建议继续”，不得替项目背书。

硬性边界：
- 不要声称已经安装、运行、执行测试、修改文件或产生真实结果。
- 不要写“自动适配”“确保通过”“完美适配”“强烈建议安装”等承诺性表达。
- 如果描述安装后的工作方式，必须使用“如果安装成功且宿主正确加载 Skill，它可能会……”这种条件句。
- 体验剧本只能写成“示例台词/假设流程”：使用“可能会询问/可能会建议/可能会展示”，不要写“已写入、已生成、已通过、正在运行、正在生成”。
- Prompt Preview 不负责给安装命令；如用户准备试装，只能提示先阅读 Quick Start 和 Risk Card，并在隔离环境验证。
- 所有项目事实必须来自 supported claim、evidence_refs 或 source_paths；inferred/unverified 只能作风险或待确认项。

```

### 角色 / Skill 选择

- 目标：从项目里的角色或 Skill 中挑选最匹配的资产。
- 预期输出：候选角色或 Skill 列表，每项包含适用场景、证据路径、风险边界和是否需要安装后验证。

```text
请读取 role_skill_index，根据我的目标任务推荐 3-5 个最相关的角色或 Skill。每个推荐都要说明适用场景、可能输出、风险边界和 evidence_refs。
```

### 风险预检

- 目标：安装或引入前识别环境、权限、规则冲突和质量风险。
- 预期输出：环境、权限、依赖、许可、宿主冲突、质量风险和未知项的检查清单。

```text
请基于 risk_card、boundaries 和 quick_start_candidates，给我一份安装前风险预检清单。不要替我执行命令，只说明我应该检查什么、为什么检查、失败会有什么影响。
```

### 宿主 AI 开工指令

- 目标：把项目上下文转成一次对话开始前的宿主 AI 指令。
- 预期输出：一段边界明确、证据引用明确、适合复制给宿主 AI 的开工前指令。

```text
请基于 zoteus 的 AI Context Pack，生成一段我可以粘贴给宿主 AI 的开工前指令。这段指令必须遵守 not_runtime=true，不能声称项目已经安装、运行或产生真实结果。
```

## 角色 / Skill 索引

- 共索引 17 个角色 / Skill / 项目文档条目。

- **⚡ Zoteus**（project_doc）：Your Zotero library, inside every AI conversation — with real citations, not hallucinations. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`README.md`
- **Zoteus — code-execution wrappers**（project_doc）：Generated TypeScript wrappers for the Zoteus MCP tools, for use with Anthropic's code execution with MCP https://www.anthropic.com/engineering/code-execution-with-mcp pattern. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`codex/README.md`
- **Architecture**（project_doc）：Zoteus is a single TypeScript Node 20+, ESM package with clean internal layers. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/architecture.md`
- **Configuration**（project_doc）：Zoteus is configured via environment variables see .env.example ../.env.example . 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/configuration.md`
- **Zoteus — Production deployment runbook**（project_doc）：Zoteus — Production deployment runbook 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/deployment.md`
- **Distribution & release runbook maintainers**（project_doc）：Distribution & release runbook maintainers 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/distribution.md`
- **Remote OAuth — using Zoteus as a claude.ai web custom connector**（project_doc）：Remote OAuth — using Zoteus as a claude.ai web custom connector 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/remote-oauth.md`
- **Contributing to Zoteus**（project_doc）：Thanks for your interest in improving Zoteus! Contributions of all kinds are welcome — bug reports, docs, tests, and code. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`CONTRIBUTING.md`
- **Citation pipeline**（project_doc）：M5 adds an account-free where possible import-and-cite pipeline: four tools. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/citations.md`
- **Code execution with MCP**（project_doc）：Zoteus implements the pattern from Anthropic's Code execution with MCP https://www.anthropic.com/engineering/code-execution-with-mcp : instead of loading every tool definition into the model's context and round-tripping large intermediate results, an agent can write code that imports typed wrappers and calls Zotero from a sandbox. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/code-execution.md`
- **Files, full-text, sync, groups & export**（project_doc）：Files, full-text, sync, groups & export 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/files-and-sync.md`
- **Full-text grounding, tag audit, and BBT export M12**（project_doc）：Full-text grounding, tag audit, and BBT export M12 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/grounding.md`
- **Prompts workflows**（project_doc）：Zoteus ships MCP Prompts — user-triggered scholarly workflows that hosts expose as slash commands. They orchestrate the zotero tools for common research tasks. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/prompts.md`
- **Scholarly-context graph**（project_doc）：M7 adds zotero scholar — explore the wider literature around a paper and see what's already in your library. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/scholar.md`
- **Hybrid semantic search**（project_doc）：M6 adds local-first hybrid retrieval: BM25 keyword scoring fused with vector similarity Reciprocal Rank Fusion , with results that cite the matching item and a snippet. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/semantic-search.md`
- **Writing to Zotero safe by design**（project_doc）：Zoteus writes go through the cloud Web API v3 the desktop local API is read-only , and require a ZOTERO API KEY with write access. The hard parts — optimistic concurrency, idempotency, batching, and partial-failure handling — are done for you inside the client. 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`docs/writing.md`
- **Changelog**（project_doc）：All notable changes to Zoteus are documented here. The format is based on Keep a Changelog https://keepachangelog.com/en/1.1.0/ and this project adheres to Semantic Versioning https://semver.org/spec/v2.0.0.html . 激活提示：当用户需要理解项目结构、安装方式或边界时参考。 证据：`CHANGELOG.md`

## 证据索引

- 共索引 62 条证据。

- **⚡ Zoteus**（documentation）：Your Zotero library, inside every AI conversation — with real citations, not hallucinations. 证据：`README.md`
- **Zoteus — code-execution wrappers**（documentation）：Generated TypeScript wrappers for the Zoteus MCP tools, for use with Anthropic's code execution with MCP https://www.anthropic.com/engineering/code-execution-with-mcp pattern. 证据：`codex/README.md`
- **Package**（package_manifest）：{ "name": "@oscardvs/zoteus", "version": "1.0.4", "description": "The everything Zotero MCP server — complete Zotero Web API v3 + desktop local API for Claude and any MCP client.", "keywords": "zotero", "mcp", "model-context-protocol", "mcp-server", "claude", "citations", "bibliography", "reference-manager", "zotero-api" , "type": "module", "license": "MIT", "author": "Oscar Devos", "homepage": "https://github.com/oscardvs/zoteus", "repository": { "type": "git", "url": "git+https://github.com/oscardvs/zoteus.git" }, "bin": { "zoteus": "dist/index.js" }, "main": "dist/index.js", "files": "dist", "README.md", "LICENSE" , "engines": { "node": " =20.19" }, "scripts": { "build": "tsc -p tsconfig… 证据：`package.json`
- **Architecture**（documentation）：Zoteus is a single TypeScript Node 20+, ESM package with clean internal layers. 证据：`docs/architecture.md`
- **Configuration**（documentation）：Zoteus is configured via environment variables see .env.example ../.env.example . 证据：`docs/configuration.md`
- **Zoteus — Production deployment runbook**（documentation）：Zoteus — Production deployment runbook 证据：`docs/deployment.md`
- **Distribution & release runbook maintainers**（documentation）：Distribution & release runbook maintainers 证据：`docs/distribution.md`
- **Remote OAuth — using Zoteus as a claude.ai web custom connector**（documentation）：Remote OAuth — using Zoteus as a claude.ai web custom connector 证据：`docs/remote-oauth.md`
- **Contributing to Zoteus**（documentation）：Thanks for your interest in improving Zoteus! Contributions of all kinds are welcome — bug reports, docs, tests, and code. 证据：`CONTRIBUTING.md`
- **License**（source_file）：Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files the "Software" , to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: 证据：`LICENSE`
- **Citation pipeline**（documentation）：M5 adds an account-free where possible import-and-cite pipeline: four tools. 证据：`docs/citations.md`
- **Code execution with MCP**（documentation）：Zoteus implements the pattern from Anthropic's Code execution with MCP https://www.anthropic.com/engineering/code-execution-with-mcp : instead of loading every tool definition into the model's context and round-tripping large intermediate results, an agent can write code that imports typed wrappers and calls Zotero from a sandbox. 证据：`docs/code-execution.md`
- **Files, full-text, sync, groups & export**（documentation）：Files, full-text, sync, groups & export 证据：`docs/files-and-sync.md`
- **Full-text grounding, tag audit, and BBT export M12**（documentation）：Full-text grounding, tag audit, and BBT export M12 证据：`docs/grounding.md`
- **Prompts workflows**（documentation）：Zoteus ships MCP Prompts — user-triggered scholarly workflows that hosts expose as slash commands. They orchestrate the zotero tools for common research tasks. 证据：`docs/prompts.md`
- **Scholarly-context graph**（documentation）：M7 adds zotero scholar — explore the wider literature around a paper and see what's already in your library. 证据：`docs/scholar.md`
- **Hybrid semantic search**（documentation）：M6 adds local-first hybrid retrieval: BM25 keyword scoring fused with vector similarity Reciprocal Rank Fusion , with results that cite the matching item and a snippet. 证据：`docs/semantic-search.md`
- **Writing to Zotero safe by design**（documentation）：Zoteus writes go through the cloud Web API v3 the desktop local API is read-only , and require a ZOTERO API KEY with write access. The hard parts — optimistic concurrency, idempotency, batching, and partial-failure handling — are done for you inside the client. 证据：`docs/writing.md`
- **Tsconfig**（structured_config）：{ "compilerOptions": { "target": "ES2022", "module": "NodeNext", "moduleResolution": "NodeNext", "lib": "ES2022" , "outDir": "dist", "rootDir": "src", "strict": true, "declaration": true, "sourceMap": true, "esModuleInterop": true, "skipLibCheck": true, "resolveJsonModule": true, "forceConsistentCasingInFileNames": true, "noUncheckedIndexedAccess": true }, "include": "src/ / " , "exclude": "node modules", "dist", "tests" } 证据：`tsconfig.json`
- **Zoteus configuration — copy to .env and fill in. NEVER commit your real .env.**（source_file）：Zoteus configuration — copy to .env and fill in. NEVER commit your real .env. 证据：`.env.example`
- **Index**（source_file）：import { loadConfig } from './config.js'; import { buildServer, createServer, ContextCache } from './server.js'; import { startStdio } from './transports/stdio.js'; import { startHttp } from './transports/http.js'; import { buildOAuth } from './auth/router.js'; import { createLogger } from './lib/logger.js'; import { createMetrics } from './lib/metrics.js'; import { makeReadiness, storeCheck, zoteroPingCheck } from './lib/health.js'; import { installShutdownHandlers } from './lib/lifecycle.js'; import type { Server } from 'node:http'; import { createRequire } from 'node:module'; ⋮---- function flag name: string : string undefined ⋮---- async function main : Promise 证据：`src/index.ts`
- **Createitems**（source_file）：import { callMCPTool } from '../runtime.js'; ⋮---- export function createItems input: Record = 证据：`codex/zotero/createItems.ts`
- **Deleteitems**（source_file）：import { callMCPTool } from '../runtime.js'; ⋮---- export function deleteItems input: Record = 证据：`codex/zotero/deleteItems.ts`
- **Index**（source_file）：import { callMCPTool } from '../runtime.js'; ⋮---- export function index input: Record = 证据：`codex/zotero/index.ts`
- **Searchitems**（source_file）：import { callMCPTool } from '../runtime.js'; ⋮---- export function searchItems input: Record = 证据：`codex/zotero/searchItems.ts`
- **Trashitems**（source_file）：import { callMCPTool } from '../runtime.js'; ⋮---- export function trashItems input: Record = 证据：`codex/zotero/trashItems.ts`
- **Http**（source_file）：import { Semaphore } from '../lib/semaphore.js'; import { ZoteroApiError } from './errors.js'; import type { Logger } from '../lib/logger.js'; ⋮---- export type FetchLike = url: string, init?: RequestInit = Promise ; ⋮---- export interface RateLimitedFetcherOptions { maxConcurrency?: number; fetchImpl?: FetchLike; logger?: Logger; defaultDeadlineMs?: number; } ⋮---- const sleep = ms: number ⋮---- export class RateLimitedFetcher ⋮---- constructor opts: RateLimitedFetcherOptions = ⋮---- async fetch url: string, init?: RequestInit, opts?: { maxRetries?: number; deadlineMs?: number }, : Promise ⋮---- const remaining = ⋮---- private timeoutError deadlineMs: number, rateLimited: boolean : ZoteroA… 证据：`src/api/http.ts`
- **Web Client**（source_file）：import { randomBytes } from 'node:crypto'; import { RateLimitedFetcher } from './http.js'; import { ZoteroApiError, actionableMessage } from './errors.js'; import type { Logger } from '../lib/logger.js'; ⋮---- export interface LibraryRef { type: 'user' 'group'; id: number; } ⋮---- export interface KeyInfo { key?: string; userID: number; username: string; displayName?: string; access: Record ; } ⋮---- export interface ListResult { data: T ; totalResults: number; lastModifiedVersion: number; } ⋮---- export interface WriteResult { successful: Array ; unchanged: string ; failed: Array ; newLibraryVersion: number; } ⋮---- export interface ItemQuery { q?: string; qmode?: 'titleCreatorYear' 'every… 证据：`src/api/web-client.ts`
- **Index**（source_file）：import { z } from 'zod'; import type { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js'; ⋮---- function userMessage text: string ⋮---- export function registerPrompts server: McpServer : void 证据：`src/prompts/index.ts`
- **Index**（source_file）：import type { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js'; import type { ToolContext } from '../registry/registry.js'; ⋮---- export function registerResources server: McpServer, ctx: ToolContext : void 证据：`src/resources/index.ts`
- **Capabilities**（source_file）：import type { ZoteusConfig } from '../config.js'; import type { WebApiClient, KeyInfo } from '../api/web-client.js'; import type { LocalApiClient } from '../api/local-client.js'; import type { Logger } from '../lib/logger.js'; ⋮---- export interface Capabilities { cloud: KeyInfo null; localApi: boolean; } ⋮---- export interface ProbeDeps { web: Pick ; local?: Pick ; logger: Logger; } ⋮---- export async function probeCapabilities config: ZoteusConfig, deps: ProbeDeps, : Promise 证据：`src/router/capabilities.ts`
- **Library Router**（source_file）：import type { ZoteusConfig } from '../config.js'; import type { Capabilities } from './capabilities.js'; import type { WebApiClient, LibraryRef, ItemQuery, ListResult, KeyInfo } from '../api/web-client.js'; import type { LocalApiClient } from '../api/local-client.js'; ⋮---- export interface LibraryRouterOptions { config: ZoteusConfig; capabilities: Capabilities; web: WebApiClient; local?: LocalApiClient; } ⋮---- export interface ReadOpts { library?: LibraryRef; } ⋮---- export class LibraryRouter ⋮---- constructor opts: LibraryRouterOptions ⋮---- whoami : KeyInfo null ⋮---- defaultLibrary : LibraryRef ⋮---- private useLocal library: LibraryRef : boolean ⋮---- async searchItems query: ItemQue… 证据：`src/router/library-router.ts`
- **Create Items**（source_file）：import { z } from 'zod'; import type { ToolDefinition } from '../registry/registry.js'; import { ok, requireCloudLibrary } from '../registry/registry.js'; import { itemsArraySchema } from '../schema/item-payload.js'; 证据：`src/tools/create-items.ts`
- **Delete Items**（source_file）：import { z } from 'zod'; import type { ToolDefinition } from '../registry/registry.js'; import { ok, requireCloudLibrary } from '../registry/registry.js'; 证据：`src/tools/delete-items.ts`
- **Index**（source_file）：import type { ToolDefinition } from '../registry/registry.js'; import whoami from './whoami.js'; import searchItems from './search-items.js'; import getItem from './get-item.js'; import schemaTool from './schema.js'; import createItems from './create-items.js'; import updateItem from './update-item.js'; import trashItems from './trash-items.js'; import deleteItems from './delete-items.js'; import manageCollections from './manage-collections.js'; import manageTags from './manage-tags.js'; import savedSearches from './saved-searches.js'; import groups from './groups.js'; import exportTool from './export.js'; import fulltext from './fulltext.js'; import getFulltext from './get-fulltext.js'; im… 证据：`src/tools/index.ts`
- **Manage Collections**（source_file）：import { z } from 'zod'; import type { ToolContext, ToolDefinition, ToolHandlerResult } from '../registry/registry.js'; import { ok, requireCloudLibrary } from '../registry/registry.js'; import type { LibraryRef } from '../api/web-client.js'; ⋮---- function err text: string : ToolHandlerResult ⋮---- async function fetchCollection ctx: ToolContext, lib: LibraryRef, key: string : Promise 证据：`src/tools/manage-collections.ts`
- **Manage Tags**（source_file）：import { z } from 'zod'; import type { ToolDefinition, ToolHandlerResult } from '../registry/registry.js'; import { ok, requireCloudLibrary } from '../registry/registry.js'; ⋮---- function err text: string : ToolHandlerResult 证据：`src/tools/manage-tags.ts`
- **Search Items**（source_file）：import { z } from 'zod'; import type { ToolDefinition } from '../registry/registry.js'; import { ok } from '../registry/registry.js'; ⋮---- export function creatorSummary creators: Array 证据：`src/tools/search-items.ts`
- **Trash Items**（source_file）：import { z } from 'zod'; import type { ToolDefinition } from '../registry/registry.js'; import { ok, requireCloudLibrary } from '../registry/registry.js'; ⋮---- function versionOf item: any : number undefined 证据：`src/tools/trash-items.ts`
- **Update Item**（source_file）：import { z } from 'zod'; import type { ToolDefinition } from '../registry/registry.js'; import { ok, requireCloudLibrary } from '../registry/registry.js'; import { ZoteroApiError } from '../api/errors.js'; import { itemPatchSchema } from '../schema/item-payload.js'; ⋮---- function versionOf item: any : number undefined ⋮---- function jsonEqual a: unknown, b: unknown : boolean 证据：`src/tools/update-item.ts`
- **Http**（source_file）：import http from 'node:http'; import { randomUUID } from 'node:crypto'; import express from 'express'; import cors from 'cors'; import { rateLimit } from 'express-rate-limit'; import { StreamableHTTPServerTransport } from '@modelcontextprotocol/sdk/server/streamableHttp.js'; import { requireBearerAuth } from '@modelcontextprotocol/sdk/server/auth/middleware/bearerAuth.js'; import type { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js'; import type { AuthInfo } from '@modelcontextprotocol/sdk/server/auth/types.js'; import type { Logger } from '../lib/logger.js'; import { requestLogger } from '../lib/request-logger.js'; import { liveness, type Readiness } from '../lib/health.js'; im… 证据：`src/transports/http.ts`
- **Stdio**（source_file）：import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js'; import type { McpServer } from '@modelcontextprotocol/sdk/server/mcp.js'; ⋮---- export async function startStdio server: McpServer : Promise 证据：`src/transports/stdio.ts`
- **Changelog**（documentation）：All notable changes to Zoteus are documented here. The format is based on Keep a Changelog https://keepachangelog.com/en/1.1.0/ and this project adheres to Semantic Versioning https://semver.org/spec/v2.0.0.html . 证据：`CHANGELOG.md`
- **.Eslintrc**（structured_config）：{ "root": true, "parser": "@typescript-eslint/parser", "parserOptions": { "ecmaVersion": 2022, "sourceType": "module" }, "plugins": "@typescript-eslint" , "extends": "eslint:recommended", "plugin:@typescript-eslint/recommended" , "env": { "node": true, "es2022": true }, "ignorePatterns": "dist", "node modules", "codex" , "rules": { "@typescript-eslint/no-explicit-any": "off", "@typescript-eslint/no-unused-vars": "warn", { "argsIgnorePattern": "^ ", "varsIgnorePattern": "^ ", "ignoreRestSiblings": true } } } 证据：`.eslintrc.json`
- **Manifest**（structured_config）：{ "dxt version": "0.1", "name": "zoteus", "display name": "Zoteus — Zotero MCP", "version": "1.0.1", "description": "The everything Zotero MCP server: search, safe writes, citations, semantic search, and a scholarly-context graph for your Zotero library.", "long description": "Zoteus gives Claude complete, safe access to your Zotero library via the Web API v3 and the desktop local API — items, collections, tags, attachments, full-text, sync, groups, add-by-DOI/ISBN/PMID/arXiv, CSL bibliography formatting, hybrid semantic search, and an OpenAlex/Crossref scholarly graph.", "author": { "name": "Oscar Devos", "url": "https://github.com/oscardvs" }, "license": "MIT", "homepage": "https://github… 证据：`dxt/manifest.json`
- **Glama**（structured_config）：{ "$schema": "https://glama.ai/mcp/schemas/server.json", "maintainers": "oscardvs" } 证据：`glama.json`
- **Server**（structured_config）：{ "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json", "name": "io.github.oscardvs/zoteus", "description": "The everything Zotero MCP server — Web API v3 + local API, safe writes, citations, search.", "version": "1.0.1", "repository": { "url": "https://github.com/oscardvs/zoteus", "source": "github" }, "packages": { "registryType": "npm", "identifier": "@oscardvs/zoteus", "version": "1.0.1", "transport": { "type": "stdio" }, "environmentVariables": { "name": "ZOTERO API KEY", "description": "Zotero API key writes/sync/groups; optional for local-only reads .", "isSecret": true, "isRequired": false }, { "name": "ZOTEUS LOCAL", "description": "Use the Zote… 证据：`server.json`
- **.dockerignore**（source_file）：node modules dist .env .git .github tests docs codex dxt .log .tgz 证据：`.dockerignore`
- **.editorconfig**（source_file）：root = true charset = utf-8 indent style = space indent size = 2 end of line = lf insert final newline = true trim trailing whitespace = true 证据：`.editorconfig`
- **Dependencies**（source_file）：Dependencies node modules/ .pnp. .yarn/ 证据：`.gitignore`
- **.prettierrc**（source_file）：{ "singleQuote": true, "semi": true, "trailingComma": "all", "printWidth": 100 } 证据：`.prettierrc`
- **syntax=docker/dockerfile:1**（source_file）：syntax=docker/dockerfile:1 Multi-stage build for the Zoteus MCP server OAuth 2.1 remote . FROM node:22-bookworm-slim AS build WORKDIR /app COPY package.json package-lock.json ./ RUN npm ci COPY tsconfig.json ./ COPY src ./src RUN npm run build 证据：`Dockerfile`
- **Runtime**（source_file）：type Caller = name: string, input: unknown = Promise ; ⋮---- export function setMCPCaller fn: Caller : void ⋮---- export async function callMCPTool name: string, input: unknown : Promise 证据：`codex/runtime.ts`
- **Public HTTPS origin → Zoteus. Caddy terminates TLS and PRESERVES the Host header**（source_file）：Public HTTPS origin → Zoteus. Caddy terminates TLS and PRESERVES the Host header default reverse proxy behavior , which Zoteus's DNS-rebinding guard requires. {$ZOTEUS DOMAIN} comes from .env e.g. zoteus.example.duckdns.org . For a DuckDNS hostname, use the DNS-01 challenge — build a Caddy image with the duckdns module, or use a custom cert. See docs/deployment.md. {$ZOTEUS DOMAIN} { encode zstd gzip reverse proxy zoteus:3939 } 证据：`deploy/Caddyfile`
- **Docker forwards SIGTERM → Zoteus drains/flushes within stop grace period.**（source_file）：Unit Description=Zoteus MCP server After=network-online.target Wants=network-online.target 证据：`deploy/zoteus.service`
- **Docker Compose**（source_file）：services: zoteus: image: ghcr.io/oscardvs/zoteus:latest restart: unless-stopped mem limit: 900m mem reservation: 256m env file: .env environment: ZOTEUS OAUTH ENABLED: "true" ZOTEUS OAUTH MODE: "${ZOTEUS OAUTH MODE:-passcode}" ZOTEUS OAUTH STORE: "file" ZOTEUS DATA DIR: "/data" ZOTEUS LOG FORMAT: "json" ZOTEUS METRICS ENABLED: "true" PORT: "3939" HOST: "0.0.0.0" volumes: - zoteus-data:/data expose: - "3939" healthcheck: test: "CMD", "node", "-e", "fetch 'http://127.0.0.1:3939/healthz' .then r= process.exit r.ok?0:1 .catch = process.exit 1 " interval: 30s timeout: 5s retries: 3 start period: 10s stop grace period: 30s caddy: image: caddy:2 restart: unless-stopped depends on: zoteus ports: -… 证据：`docker-compose.yml`
- **Alternative deploy target paid . Primary free path is docker-compose + Caddy; see docs/deployment.md.**（source_file）：Alternative deploy target paid . Primary free path is docker-compose + Caddy; see docs/deployment.md. app = "zoteus" primary region = "ams" 证据：`fly.toml`
- **Backup Store**（source_file）：set -euo pipefail DATA DIR="${ZOTEUS DATA DIR:-/data}" DEST="${1:-/var/backups/zoteus}" STAMP="$ date -u +%Y%m%dT%H%M%SZ " mkdir -p "$DEST" ARCHIVE="$DEST/zoteus-$STAMP.tar.gz" tar -czf "$ARCHIVE" -C "$DATA DIR" \ oauth-store.json \ $ cd "$DATA DIR" && ls search-index .json 2 /dev/null true echo "wrote $ARCHIVE" ls -1t "$DEST"/zoteus- .tar.gz tail -n +15 xargs -r rm -f 证据：`scripts/backup-store.sh`
- **Generate Codex**（source_file）：import { join } from 'node:path'; import { generateCodex } from '../src/codex/generate.js'; import { tools } from '../src/tools/index.js'; 证据：`scripts/generate-codex.ts`
- **Config**（source_file）：import { z } from 'zod'; import { defaultDataDir } from './lib/paths.js'; ⋮---- export interface ZoteusConfig { apiKey?: string; libraryId?: number; libraryType: 'user' 'group'; local: 'auto' 'on' 'off'; localPort: number; translationServerUrl: string; embeddings: 'local' 'openai' 'gemini' 'off'; scholarProviders: string ; dataDir: string; contactEmail?: string; allowDelete: boolean; readOnly: boolean; logLevel: 'debug' 'info' 'warn' 'error'; logFormat: 'text' 'json'; allowInsecureHttp: boolean; metricsEnabled: boolean; readyzCheckZotero: boolean; mcpRateLimit: { windowMs: number; max: number }; oauth: { enabled: boolean; publicUrl?: string; passcode?: string; accessTokenTtlSec: number; ref… 证据：`src/config.ts`
- 其余 2 条证据见 `AI_CONTEXT_PACK.json` 或 `EVIDENCE_INDEX.json`。

## 宿主 AI 必须遵守的规则

- **把本资产当作开工前上下文，而不是运行环境。**：AI Context Pack 只包含证据化项目理解，不包含目标项目的可执行状态。 证据：`README.md`, `codex/README.md`, `package.json`
- **回答用户时区分可预览内容与必须安装后才能验证的内容。**：安装前体验的消费者价值来自降低误装和误判，而不是伪装成真实运行。 证据：`README.md`, `codex/README.md`, `package.json`

## 用户开工前应该回答的问题

- 你准备在哪个宿主 AI 或本地环境中使用它？
- 你只是想先体验工作流，还是准备真实安装？
- 你最在意的是安装成本、输出质量、还是和现有规则的冲突？

## 验收标准

- 所有能力声明都能回指到 evidence_refs 中的文件路径。
- AI_CONTEXT_PACK.md 没有把预览包装成真实运行。
- 用户能在 3 分钟内看懂适合谁、能做什么、如何开始和风险边界。

---

## Doramagic Context Augmentation

下面内容用于强化 Repomix/AI Context Pack 主体。Human Manual 只提供阅读骨架；踩坑日志会被转成宿主 AI 必须遵守的工作约束。

## Human Manual 骨架

使用规则：这里只是项目阅读路线和显著性信号，不是事实权威。具体事实仍必须回到 repo evidence / Claim Graph。

宿主 AI 硬性规则：
- 不得把页标题、章节顺序、摘要或 importance 当作项目事实证据。
- 解释 Human Manual 骨架时，必须明确说它只是阅读路线/显著性信号。
- 能力、安装、兼容性、运行状态和风险判断必须引用 repo evidence、source path 或 Claim Graph。

- **项目概述与核心特性**：importance `high`
  - source_paths: README.md, src/index.ts, src/server.ts, package.json
- **系统架构与传输层**：importance `high`
  - source_paths: docs/architecture.md, src/transports/stdio.ts, src/transports/http.ts, src/router/library-router.ts, src/router/capabilities.ts
- **工具、安全写入、搜索与引用**：importance `high`
  - source_paths: src/tools/create-items.ts, src/tools/update-item.ts, src/tools/delete-items.ts, src/tools/trash-items.ts, src/tools/manage-collections.ts
- **部署、配置与已知问题**：importance `high`
  - source_paths: docs/configuration.md, docs/deployment.md, docs/remote-oauth.md, docs/distribution.md, .env.example

## Repo Inspection Evidence / 源码检查证据

- repo_clone_verified: true
- repo_inspection_verified: true
- repo_commit: `d0096b748cc2a76ac20af2756e67e5d11a98a909`
- inspected_files: `Dockerfile`, `README.md`, `docker-compose.yml`, `package.json`, `docs/architecture.md`, `docs/citations.md`, `docs/code-execution.md`, `docs/configuration.md`, `docs/deployment.md`, `docs/distribution.md`, `docs/files-and-sync.md`, `docs/grounding.md`, `docs/prompts.md`, `docs/remote-oauth.md`, `docs/scholar.md`, `docs/semantic-search.md`, `docs/writing.md`, `src/api/attachments.ts`, `src/api/bbt-client.ts`, `src/api/errors.ts`

宿主 AI 硬性规则：
- 没有 repo_clone_verified=true 时，不得声称已经读过源码。
- 没有 repo_inspection_verified=true 时，不得把 README/docs/package 文件判断写成事实。
- 没有 quick_start_verified=true 时，不得声称 Quick Start 已跑通。

## Doramagic Pitfall Constraints / 踩坑约束

这些规则来自 Doramagic 发现、验证或编译过程中的项目专属坑点。宿主 AI 必须把它们当作工作约束，而不是普通说明文字。

### Constraint 1: 可能修改宿主 AI 配置

- Trigger: 项目面向 Claude/Cursor/Codex/Gemini/OpenCode 等宿主，或安装命令涉及用户配置目录。
- Host AI rule: 列出会写入的配置文件、目录和卸载/回滚步骤。
- Why it matters: 安装可能改变本机 AI 工具行为，用户需要知道写入位置和回滚方法。
- Evidence: capability.host_targets | https://github.com/oscardvs/zoteus | host_targets=mcp_host, claude, claude_code, cursor
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 2: 失败模式：configuration: update_item / create_items cannot write array-valued fields (creators, tags, collections) — Z...

- Trigger: Developers should check this configuration risk before relying on the project: update_item / create_items cannot write array-valued fields (creators, tags, collections) — Zotero rejects with "property must be an array"
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: update_item / create_items cannot write array-valued fields (creators, tags, collections) — Zotero rejects with "property must be an array". Context: Observed when using python
- Why it matters: Developers may misconfigure credentials, environment, or host setup: update_item / create_items cannot write array-valued fields (creators, tags, collections) — Zotero rejects with "property must be an array"
- Evidence: failure_mode_cluster:github_issue | https://github.com/oscardvs/zoteus/issues/1 | update_item / create_items cannot write array-valued fields (creators, tags, collections) — Zotero rejects with "property must be an array"
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 3: 能力判断依赖假设

- Trigger: README/documentation is current enough for a first validation pass.
- Host AI rule: 将假设转成下游验证清单。
- Why it matters: 假设不成立时，用户拿不到承诺的能力。
- Evidence: capability.assumptions | https://github.com/oscardvs/zoteus | README/documentation is current enough for a first validation pass.
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 4: 维护活跃度未知

- Trigger: 未记录 last_activity_observed。
- Host AI rule: 补 GitHub 最近 commit、release、issue/PR 响应信号。
- Why it matters: 新项目、停更项目和活跃项目会被混在一起，推荐信任度下降。
- Evidence: evidence.maintainer_signals | https://github.com/oscardvs/zoteus | last_activity_observed missing
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

- Trigger: no_demo
- Evidence: downstream_validation.risk_items | https://github.com/oscardvs/zoteus | no_demo; severity=medium
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 6: 存在评分风险

- Trigger: no_demo
- Why it matters: 风险会影响是否适合普通用户安装。
- Evidence: risks.scoring_risks | https://github.com/oscardvs/zoteus | no_demo; severity=medium
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 7: 来源证据：update_item / create_items cannot write array-valued fields (creators, tags, collections) — Zotero rejects with "proper…

- Trigger: GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：update_item / create_items cannot write array-valued fields (creators, tags, collections) — Zotero rejects with "property must be an array"
- Host AI rule: 来源显示可能已有修复、规避或版本变化，说明书中必须标注适用版本。
- Why it matters: 可能影响授权、密钥配置或安全边界。
- Evidence: community_evidence:github | https://github.com/oscardvs/zoteus/issues/1 | 来源讨论提到 npm 相关条件，需在安装/试用前复核。
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 8: issue/PR 响应质量未知

- Trigger: issue_or_pr_quality=unknown。
- Host AI rule: 抽样最近 issue/PR，判断是否长期无人处理。
- Why it matters: 用户无法判断遇到问题后是否有人维护。
- Evidence: evidence.maintainer_signals | https://github.com/oscardvs/zoteus | issue_or_pr_quality=unknown
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 9: 发布节奏不明确

- Trigger: release_recency=unknown。
- Host AI rule: 确认最近 release/tag 和 README 安装命令是否一致。
- Why it matters: 安装命令和文档可能落后于代码，用户踩坑概率升高。
- Evidence: evidence.maintainer_signals | https://github.com/oscardvs/zoteus | release_recency=unknown
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。

### Constraint 10: 失败模式：maintenance: v1.0.0

- Trigger: Developers should check this maintenance risk before relying on the project: v1.0.0
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: v1.0.0. Context: Source discussion did not expose a precise runtime context.
- Why it matters: Upgrade or migration may change expected behavior: v1.0.0
- Evidence: failure_mode_cluster:github_release | https://github.com/oscardvs/zoteus/releases/tag/v1.0.0 | v1.0.0
- Hard boundary: 不要把这个坑点包装成已解决、已验证或可忽略，除非后续验证证据明确证明它已经关闭。
