Yandex ToolsBLOCK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP servers for Yandex APIs — search, keyword research, webmaster tools, and web analytics for the Russian market.
English | Русский
English
Packages
Quick Start
Yandex Wordstat v2 (keyword research) — Yandex Cloud Search API; uses the same key as Search:
{
"mcpServers": {
"yandex-wordstat": {
"command": "npx",
"args": ["-y", "yandex-wordstat-mcp"],
"env": {
"YANDEX_SEARCH_API_KEY": "your_api_key",
"YANDEX_FOLDER_ID": "your_folder_id"
}
}
}
}Prefer a hosted tool? Use the managed endpoint at unoapi.ru/services/wordstat — no Yandex Cloud credentials to manage.
**Yandex Se
a6ad56709fd2OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add yandex-wordstat-mcp --env YANDEX_CLIENT_SECRET=${YANDEX_CLIENT_SECRET} --env YANDEX_DIRECT_TOKEN=${YANDEX_DIRECT_TOKEN} --env YANDEX_METRIKA_TOKEN=${YANDEX_METRIKA_TOKEN} --env YANDEX_SEARCH_API_KEY=${YANDEX_SEARCH_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"yandex-wordstat-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"YANDEX_CLIENT_SECRET": "${YANDEX_CLIENT_SECRET}",
"YANDEX_DIRECT_TOKEN": "${YANDEX_DIRECT_TOKEN}",
"YANDEX_METRIKA_TOKEN": "${YANDEX_METRIKA_TOKEN}",
"YANDEX_SEARCH_API_KEY": "${YANDEX_SEARCH_API_KEY}"
}
}
}
}Exposed tools (101)
92 read · 8 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add-keywords | write | |
create-adgroup | write | |
create-campaign | write | |
create-text-ad | write | |
delete-adgroup | destructive | |
dynamics | read | |
get-audience-interests | read | |
get-balance | read | |
get-bounce-by-devices-organic | read | |
get-bounce-comparison-search-engines | read | |
get-bounce-device-search-engine | read | |
get-broken-internal-links | read | |
get-broken-internal-links-history | read | |
get-campaign | read | |
get-conversions-by-devices | read | |
get-conversions-by-landing-pages | read | |
get-conversions-by-regions | read | |
get-conversions-by-search-engine | read | |
get-conversions-by-search-phrases | read | |
get-conversions-device-region | read | |
get-counter | read | |
get-counters | read | |
get-critical-pages | read | |
get-demographics-organic | read | |
get-devices | read | |
get-diagnostics | read | |
get-entry-exit-paths | read | |
get-exit-pages-by-devices | read | |
get-exit-pages-by-section | read | |
get-external-links | read | |
get-external-links-history | read | |
get-feed-regions | read | |
get-feed-status | read | |
get-feeds | read | |
get-geography | read | |
get-goals | read | |
get-high-bounce-pages-organic | read | |
get-host | read | |
get-important-url-history | read | |
get-important-urls | read | |
get-indexing-history | read | |
get-indexing-samples | read | |
get-insearch-history | read | |
get-insearch-samples | read | |
get-new-vs-returning-organic | read | |
get-organic-activity-by-day-of-week | read | |
get-organic-activity-by-hour | read | |
get-organic-browsers | read | |
get-organic-seasonality | read | |
get-organic-traffic-dynamics | read | |
get-page-depth-by-sections | read | |
get-popular-pages | read | |
get-popular-queries | read | |
get-problematic-os | read | |
get-quality-referral-traffic | read | |
get-query-analytics | read | |
get-query-history | read | |
get-recrawl-queue | read | |
get-recrawl-quota | read | |
get-recrawl-task | read | |
get-referral-conversions | read | |
get-referral-donors-behavior | read | |
get-referral-full-urls | read | |
get-region-children | read | |
get-region-ids | read | |
get-regions | read | |
get-regions-tree | read | |
get-report | read | |
get-screen-resolutions | read | |
get-search-events-history | read | |
get-search-events-samples | read | |
get-search-phrases | read | |
get-single-query-history | read | |
get-sitemap | read | |
get-sitemaps | read | |
get-social-landing-pages | read | |
get-social-networks-quality | read | |
get-social-networks-traffic | read | |
get-sqi-history | read | |
get-summary | read | |
get-top-exit-pages-organic | read | |
get-traffic-sources | read | |
get-traffic-summary | read | |
get-user | read | |
get-user-sitemap | read | |
get-user-sitemaps | read | |
get-visit-frequency-organic | read | |
list-adgroups | read | |
list-ads | read | |
list-campaigns | read | |
list-hosts | read | |
list-keywords | read | |
manage-ad | read | |
manage-campaign | read | |
regions | read | |
search | read | |
set-bids | write | |
set-negative-keywords | write | |
submit-recrawl | write | |
top-requests | read | |
update-campaign | write |
Trust audit
BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
exec(`${start} "${url}"`);exec(`${start} "${url}"`);exec(`${start} "${url}"`);console.log(token);
console.log(token);
console.log(token);
delete-adgroup
const baseUrl = `http://127.0.0.1:${httpServer.address().port}/v4`;@biomejs/biome
@modelcontextprotocol/sdk, zod
@modelcontextprotocol/sdk, zod
@modelcontextprotocol/sdk, zod
@modelcontextprotocol/sdk, zod
Gates applied: no_behavioural_pass.
a6ad56709fd2full audit observations/trust-audit/mcp-server/altrr2__yandex-tools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a6ad56709fd2 | BLOCK | F | 59 | first audit |
Questions
What tools does Yandex Tools expose?
101 in total: 92 read-only, 8 that write, and 1 that can delete or overwrite (delete-adgroup). Every one is listed on this page with its risk.
Is Yandex Tools safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (59/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Yandex Tools need?
It reads YANDEX_CLIENT_SECRET, YANDEX_DIRECT_TOKEN, YANDEX_METRIKA_TOKEN, YANDEX_SEARCH_API_KEY, YANDEX_WEBMASTER_TOKEN and YANDEX_WORDSTAT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Yandex Tools run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as yandex-wordstat-mcp at 2.0.1.
How current is this page?
The grade is for one exact copy of the source (a6ad56709fd2), read on 2026-10-08. The repository is watched and re-audited when it changes.