
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@sylphx/pdf-reader-mcp
Advanced tools
Give AI agents eyes for PDFs — structured text, tables, OCR, visual evidence, and page-level citations via MCP. Native Rust engine, local-first, five platforms.
Turn PDFs into structured text, tables, OCR, visual evidence, and page-level citations — locally, with one MCP server.
Plain-text PDF tools make agents guess. PDF Reader MCP gives them evidence.
Most PDF tools dump text. Agents then invent page numbers, miss tables, and cite the wrong cell.
PDF Reader MCP returns an Agent Document Twin: markdown + structure + geometry + provenance your agent can actually trust.
| Without evidence | With PDF Reader MCP |
|---|---|
| “The revenue was about $12M” | “Page 14, Table 3, cell (row 4, col 2) = $12.4M” |
| Lost table structure | Rows, columns, cells, bounding boxes |
| Scanned PDF becomes noise | OCR path with page-linked evidence |
| Hidden text / prompt injection ignored | Trust signals when requested |
npm install -g @sylphx/pdf-reader-mcp
Or pin the current release:
npm install -g @sylphx/pdf-reader-mcp@4.1.1
One native binary is installed for your platform only (not all five).
| Platform | Native package (auto optionalDependency) |
|---|---|
| macOS arm64 | @sylphx/pdf-reader-mcp-darwin-arm64 |
| macOS x64 | @sylphx/pdf-reader-mcp-darwin-x64 |
| Linux x64 | @sylphx/pdf-reader-mcp-linux-x64-gnu |
| Linux arm64 | @sylphx/pdf-reader-mcp-linux-arm64-gnu |
| Windows x64 | @sylphx/pdf-reader-mcp-win32-x64-msvc |
Missing native package → fail closed (no silent engine switch).
Claude Code
claude mcp add pdf-reader -- npx @sylphx/pdf-reader-mcp
Claude Desktop / Cursor / VS Code / any MCP client
{
"mcpServers": {
"pdf-reader": {
"command": "npx",
"args": ["@sylphx/pdf-reader-mcp"]
}
}
}
Dual-era hosts that send server/discover before initialize (e.g. Gemini Antigravity CLI) are supported on stdio — the server answers discovery and keeps the session open for the legacy handshake.
Stdio / HTTP
pdf-reader-mcp
MCP_TRANSPORT=http pdf-reader-mcp
Three tools. One product surface.
| Tool | What agents use it for |
|---|---|
read_pdf | Smart default: markdown, tables, structure, OCR, citations |
search_pdf | Find page + snippet matches before deep reading |
pdf_evidence | Crops, renders, inspect, focused evidence ops |
Minimal call:
{
"sources": [{ "path": "/absolute/path/to/report.pdf" }]
}
Compare full clean installs, not “JS wrapper tarball vs native executable”:
| Metric (measured clean install, linux-x64) | Historical TS 3.0.14 | Sole-Rust 4.1.0 |
|---|---|---|
| Main package on disk | ~403 KB | ~77 KB |
Full node_modules | ~82.3 MiB | ~24.4 MiB (~3.4× smaller) |
| Installed files | 4,101 | 20 (~205× fewer) |
| Production npm dependency graph | PDF.js + MCP TS SDK + more | {} + one platform native |
The native binary is multi-megabyte because it is the PDF intelligence engine (parser, server, rendering/table/OCR routing). That is expected and still yields a cleaner, smaller install than shipping PDF.js + a JS dependency tree.
Details: installed footprint comparison
Controlled same-host linux-x64 dual-mode A/B vs @sylphx/pdf-reader-mcp@3.0.14, using registry-installed 4.1.x natives:
| Mode | What it measures | Result |
|---|---|---|
persistent_warm | long-lived server, repeated identical local read_pdf after warm-up | ≥ ~10× median latency improvement on all 8 required fixture classes |
startup_inclusive | spawn + initialize + one task | large advantage on the same fixtures |
persistent_warm includes a process-local cache for identical local path+options. First request in a process still pays full parse cost.
Also: install footprint is much smaller than TS 3.0.14 on measured linux-x64 (~3.4× less disk, ~205× fewer files), and the 4.1.0 native binary is smaller than 4.0.2 (strip/LTO).
Not a multi-host guarantee. Details: 4.1.0 report · claims policy
Version 4 runs a native Rust engine on supported platforms via a thin Node launcher.
Local-first. Five platforms. One clean install.
Engineering history, recovery pins, and ADRs live under docs/migration.md — not the product pitch.
MIT
If this saves your agents from PDF hallucinations, star the repo and share a demo with your team.
FAQs
Citra — PDF evidence for agents (Sylphx). Local-first structured text, tables, OCR, visual evidence, citations via MCP/CLI/SDK. Package id transitional: @sylphx/pdf-reader-mcp.
The npm package @sylphx/pdf-reader-mcp receives a total of 817 weekly downloads. As such, @sylphx/pdf-reader-mcp popularity was classified as not popular.
We found that @sylphx/pdf-reader-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.