Atlas / MCP servers / chrisryugj / Korean DART

Korean DARTSAFE

mcp/chrisryugj/korean-dart

OpenDART 전자공시MCP | 83개 API → 15 MCP 도구. 공시·재무·지분·XBRL + 버핏급 애널리스트 프레임(내부자 시그널·회계 리스크·퀄리티 체크리스트) + HWP/PDF 첨부 마크다운화 | 83 Korean DART disclosure APIs → 15 MCP tools with Buffett-grade analyst frames

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
18 18r · 0w · 0d
Transport
stdio
License
MIT
Stars
110
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

OpenDART 83개 API를 15개 도구로. 공시·재무·지분·XBRL + 버핏급 애널리스트 프레임(내부자 시그널·회계 리스크·퀄리티 체크리스트) + HWP/PDF 첨부 마크다운화를 AI 어시스턴트에서 바로 사용.

[](https://www.npmjs.com/package/korean-dart-mcp) [](https://modelcontextprotocol.io) [](LICENSE)

금융감독원 OpenDART 전자공시 기반 MCP 서버 + CLI. Claude Desktop, Cursor, Windsurf, Claude Code 등에서 바로 사용 가능.

자매 프로젝트: korean-law-mcp (법제처 41 API → 15 도구)

English documentation → README-EN.md

⚡ 30초 설치 — 한 줄로 끝

macOS / Linux / Windows 공용. Node.js 20.19+ 만 깔려있으면 됩니다.

npx -y korean-dart-mcp setup

대화형 마법사가 띄웁니다:

  1. OpenDART 인증키 입력 (없으면 Enter — 나중에 설정 가능, 여기서 무료 발급)
  2. 사용 중인 AI 클라이언트 번호 선택 (Claude Desktop / Cursor / Claude Code / Windsurf / VS Code / Gemini CLI / Zed / Antigravity — 설치된 건 [감지됨] 표시)
  3. 설정 파일 자동 패치 → 클라이언트 재시작

Windows 도 자동으로 cmd /c npx 래핑해줘서 npx not found 이슈 해결됨. 수동 JSON 편집 불필요.

수동 설정을 원하면 아래 설치 및 사용법 섹션 참고.

v0.9 — 무엇이 새로운가

  • `get_xbrl format="markdown_full"` — presentation/calculation linkbase 를 파싱해 전체 계정 + 계층 구조 + 합산 검증. 기존 markdown 의 whitelist 50태그 대비 BS 50+ / IS 15+ / CF 10+ 전부 커버. 금융지주 DX prefix 등 업종별 택소노미 자동 대응. 6MB XBRL → ~30-60KB 마크다운.
  • `search_disclosures` 90일 자동분할 — corp_code 미지정 + 기간 90일 초과 시 자동으로 90일 청크 분할 (OpenDART "전체시장 3개월 제약" 우회). 최대 40 chunks(≈10년).
  • `insider_signal` / `disclosure_anomaly` `summary_text` — 한국어 자동 요약문 필드 추가. LLM 이 원시 테이블 뽑기 전 한 줄로 맥락 파악.
  • 보안 하드닝 (v0.9.1) — ZIP slip / ZIP bomb 방어 공용 헬퍼, HTTPS 뷰어 스크래핑, chunks 상한, presentation 재귀 depth 가드, XBRL 파싱 경고 노출.

💡 주식에 관심 많은 일반인이 쓸 수 있는 5가지

증권사 앱만으론 아쉬운 개미 투자자 기준 킬러 유스케이스. Claude 에게 프롬프트로 그냥 말하면 됨.

1. 내 보유종목 "경영진 눈치게임"

"삼성전자 최근 
Read from source at commit 857b663cfaceOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add korean-dart-mcp --env DART_API_KEY=${DART_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "korean-dart-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DART_API_KEY": "${DART_API_KEY}"
      }
    }
  }
}
03

Exposed tools (18)

18 read · 0 write · 0 destructive.

ToolRiskDescription
buffett_quality_snapshotread버핏 퀄리티 체크리스트. corps 1개 → N년 ROE/부채/CAGR 시계열 + 체크 4종.
dart_rawreadOpenDART 임의 엔드포인트 범용 호출(패스스루). 전용 enum 도구가 없는 엣지/신규 op 를 operation 명 + params 로 직접 호출해 원본 JSON 을 반환.
disclosure_anomalyread회계·거버넌스 이상 징후 스코어: 정정공시 비율, 감사인 교체, 감사의견 비적정, 자본 스트레스.
download_documentread공시서류 원문을 마크다운/원본XML/plain text 로 반환합니다. 기본값 markdown — DART 전용 XML 을 자체 파서로 heading·테이블 보존해 변환.
get_attachmentsread공시 첨부파일(HWP/PDF/DOCX/XLSX)을 목록 조회(mode=list) 하거나 다운받아 마크다운으로 추출(mode=extract).
get_companyread기업의 개황(업종·설립일·대표자·주소·홈페이지·종목코드 등)을 조회합니다.
get_corporate_eventreadDS005 주요사항보고서 36종 이벤트 조회.
get_executive_compensationread임원 보수 6개 섹션을 한 번에 합성 조회: 전체·개인별 5억 이상·상위 5인·미등기·주총 승인금액·유형별.
get_financial_indicatorsreadDS003 주요 재무지표(수익성·안정성·성장성·활동성)를 사전계산값으로 조회.
get_financialsread재무정보 조회 — scope=summary(주요계정, 단일/다중사 자동) 또는 full(전체 재무제표, 단일사).
get_major_holdingsread지분공시 2종 합성 조회: 대량보유(5%룰) + 임원·주요주주 본인 소유.
get_periodic_reportread사업보고서 내 29개 세부 섹션을 report_type enum 으로 단일 도구 호출.
get_securities_filingreadDS006 증권신고서 주요정보 6종을 enum 으로 조회.
get_shareholdersread지배구조 스냅샷: 최대주주·변동·소액주주·주식총수 4개 섹션을 한 번에 합성 조회.
get_xbrlread재무제표 XBRL 조회 — format 선택:
insider_signalread임원·주요주주 거래(DS004 elestock)를 매수·매도 클러스터로 집계.
resolve_corp_coderead회사명 또는 종목코드로 OpenDART corp_code 를 조회합니다.
search_disclosuresreadDART 공시 검색 (3 모드):
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @xmldom/xmldom, better-sqlite3, commander, dotenv, iconv-lite, kordoc, pdfjs-dist
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 857b663cfacefull audit observations/trust-audit/mcp-server/chrisryugj__korean-dart.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07857b663cfaceSAFEB89first audit
06

Questions

What is the Korean DART MCP server?

OpenDART 전자공시MCP | 83개 API → 15 MCP 도구. 공시·재무·지분·XBRL + 버핏급 애널리스트 프레임(내부자 시그널·회계 리스크·퀄리티 체크리스트) + HWP/PDF 첨부 마크다운화 | 83 Korean DART disclosure APIs → 15 MCP tools with Buffett-grade analyst frames

What tools does Korean DART expose?

18 in total: 18 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Korean DART safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Korean DART need?

It reads DART_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Korean DART run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as korean-dart-mcp at 0.10.1.

How current is this page?

The grade is for one exact copy of the source (857b663cface), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement