medical-mcp
Specialized verticals · tested 2026-08-09 · re-test due 2026-11-09 · by the Hlido desk, not the vendor
In short: A broad, key-free MCP server over FDA, WHO, PubMed and RxNorm that installs in one click β but its privacy promise and its Google Scholar leg do not sit comfortably together.
5 PASS · 2 FAIL of 7 public-surface claims
Quick answer
medical-mcp scores 68/100 (FADING) on Hlido’s independent, hands-on test (reviewed 2026-08-09). FADING (68) for a real and usefully broad tool surface over authoritative sources with a genuinely frictionless install, marked down for a privacy claim the same page contradicts ('100% locally, no cloud' alongside Googl
medical-mcp bundles a wide set of medical lookups behind one locally-run MCP server: FDA drug records, WHO Global Health Observatory statistics, PubMed literature, RxNorm nomenclature, clinical and paediatric guidelines, and a cache-stats tool. It needs no API keys and installs into Cursor with a single deep link, which is a genuinely low-friction path into a domain where most data access normally starts with a registration form. The tool list is specific rather than gestural β search-drugs, get-drug-details, search-drug-nomenclature, get-health-statistics, search-medical-literature, search-pediatric-guidelines and roughly a dozen more β and the data-source table names each upstream provider with a stated update frequency, which is the right shape for a retrieval tool. The tension is in the headline claim. The surface leads with 'π Your Data Never Leaves β Runs 100% locally; no tracking, no logs, no cloud' and 'Localhost-only β Server runs locally, no external access', while the same page lists Google Scholar and multi-database search among the sources. Those are network calls to third parties; the queries plainly do leave the machine even if nothing is stored. 'Localhost-only' is describing where the process binds, not where the traffic goes, and a reader in a clinical setting is the one most likely to read it the other way. Scraping Google Scholar is also the least durable leg here β it has no public API and blocks automated access β so that tool is the first thing likely to break. There is no version, changelog, test evidence or third-party validation on the captured page, and the surface Hlido reached is a Glama directory listing rather than the project's own site.
Why FADING
FADING (68) for a real and usefully broad tool surface over authoritative sources with a genuinely frictionless install, marked down for a privacy claim the same page contradicts ('100% locally, no cloud' alongside Google Scholar and multi-database search, which are outbound third-party calls), a Google Scholar leg with no public API and a history of blocking scrapers, and no version, changelog, accuracy evidence or independent validation anywhere on the captured surface.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — 'Bring trusted medical data directly into your AI workflow'
- PASS Cta present (required) — 'Install in Cursor' deep link plus `npm install -g medical-mcp`
- PASS Pricing or access — Open source, no API keys, no pricing surface
- PASS Docs present (required) — Tool list, install paths, usage examples and data-source table on the listing
- FAIL Claims consistent (required) — '100% locally / no cloud / no external access' contradicted by Google Scholar and multi-database search tools on the same page
- FAIL Third party validation — No benchmark, accuracy evidence or named adopter
What we saw
1 screenshot captured by the Hlido engine during the reviewed run (run-749dd3a73fac5e89-glama-ai). Our own captures β not vendor marketing material.
What it does well
- Wide, specifically-named tool surface β drugs, health statistics, literature, clinical and paediatric guidelines β rather than one vague search tool
- No API keys required; works out of the box
- One-click install into Cursor via deep link, plus documented Claude Desktop JSON config
- Data-source table names each upstream provider and its update frequency
- Runs as a local process, so records are not routed through a vendor's server for storage
What it fails at
- Claims '100% locally, no cloud' and 'no external access' while listing Google Scholar and multi-database search β those queries do leave the machine
- The Google Scholar leg has no public API and actively blocks automated access; it is the most fragile tool on the list
- No version, changelog or release evidence on the captured surface
- No accuracy evaluation, test evidence or third-party validation for medical answers
- Hlido reached a Glama directory listing rather than a project-owned site, so the vendor controls less of what was verified
Red flags
- Privacy framing overstates the guarantee: '100% locally / no cloud / no external access' is presented as absolute on a page that also lists Google Scholar and multi-database search among the sources β outbound third-party queries. Nothing is stored, but queries do leave the machine, and a clinical reader is exactly who would misread it.
Best for
- Developers prototyping medical-data workflows in Cursor or Claude Desktop who want zero setup
- Non-clinical research and educational use where FDA, WHO and PubMed lookups are convenience, not evidence of record
Not recommended for
- Any clinical or patient-facing use β there is no accuracy evidence and the tool makes no such claim
- Environments with strict data-egress rules, where the 'no cloud' framing would be read as a guarantee it does not make
- Teams that need a versioned, supported dependency
Pricing & access
- Pricing findable on the public surfacePASS Open source, no API keys, no pricing surface (tested 2026-08-09)
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-09.
Related agents
Agent relevance
CLI MCP Behavioral-testable
stdio MCP server installed via npm or from source; one-click deep link for Cursor and a documented mcpServers JSON block for Claude Desktop. Roughly eighteen named tools are exposed directly to the agent. Built for agent consumption and nothing else.
Agent-friendly score: 8/10
Score over time
The longitudinal record β every point is the score as published on that date. Raw series.
Evidence
- MCP server exposing FDA, WHO, PubMed, RxNorm, Google Scholar, AAP and paediatric journal tools — source (2026-08-09) verified
- No API keys required; one-click Cursor install deep link plus documented Claude Desktop config — source (2026-08-09) verified
- Data-source table names each provider with a stated update frequency — source (2026-08-09) verified
- Claims '100% locally, no tracking, no logs, no cloud' and 'Localhost-only β no external access' — source (2026-08-09) verified
- Those privacy claims hold for outbound queries β the same page lists Google Scholar and multi-database search as sources — source (2026-08-09)
- Version, changelog, accuracy evaluation or third-party validation — source (2026-08-09)
