DaisoBLOCK
다이소를 MCP로! 뿐만 아니라 한국 로컬 리테일과 영화관 조회를 MCP, CLI, Codex Skill로 가능하게 해줍니다.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mcptoplist.com/server/glama%2Fhmmhmmhm%2Fdaiso-mcp)
다이소(제품/매장/재고), 상품 가격 비교, 주변 음식점/카페, 주유소/유가, 개발자 요청 제출, 롯데마트(매장/상품), GS25(매장/상품/재고), 세븐일레븐(상품/매장/재고/인기검색어/카탈로그), CU(매장/재고), 이마트24(매장/상품/재고), 올리브영(매장/재고), 메가박스(지점/영화/시간표/좌석), 롯데시네마(지점/영화/좌석), CGV(극장/영화/시간표), 디트릭스(독립·예술영화관/상영작/잔여 좌석) 조회 기능을 MCP, CLI, Codex Skill로 AI에 연결합니다.
디트릭스의 지원 범위와 CLI 예시는 독립·예술영화관 조회 가이드를 참고하세요.
MCP: https://mcp.aka.page · CLI: npx daiso · Skill: clawhub install daiso-cli
ClawHub: clawhub.ai/hmmhmmhm/daiso-cli
한국 로컬 리테일, 생활 정보, 영화관 조회를 MCP, CLI, Codex Skill로 연결하는 도구입니다. 사용자는 별도 API 키를 준비하지 않고 바로 사용할 수 있습니다.
지원 서비스
분류 서비스 조회 기능
장소 네이버 지역 검색 음식점, 카페, 디저트, 주변 장소
교통 오피넷 전국 평균 유가, 최저가 주유소, 위치 기반 주유소, 주유소 상세정보
비교 다이소, GS25, 세븐일레븐, 이마트24 같은 상품의 판매처별 가격 후보 비교
운영 Supabase MCP 오류, 개선 요청, 신규 기능 요청 저장
리테일 다이소, 올리브영, 롯데마트 상품, 매장, 재고
편의점 GS25, 세븐일레븐, CU, 이마트24 상품, 매장, 재고, 인기검색어, 카탈로그
영화관 CGV, 메가박스, 롯데시네마 극장, 영화, 시간표, 잔여 좌석
[](https://opensource.org/licenses/MIT) [](https://workers.c
077e59e70b7bOBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add daiso --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env CLOUDFLARE_GLOBAL_API_KEY=${CLOUDFLARE_GLOBAL_API_KEY} --env DTRYX_RELAY_TOKEN=${DTRYX_RELAY_TOKEN} --env GOOGLE_MAPS_API_KEY=${GOOGLE_MAPS_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"daiso": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
"CLOUDFLARE_GLOBAL_API_KEY": "${CLOUDFLARE_GLOBAL_API_KEY}",
"DTRYX_RELAY_TOKEN": "${DTRYX_RELAY_TOKEN}",
"GOOGLE_MAPS_API_KEY": "${GOOGLE_MAPS_API_KEY}"
}
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
decompile_function | read | |
list_functions | read | |
list_strings | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
gs25-b2c-native-payload-hook.ts
gs25-b2c-native-payload-capture.sh
gs25-msg-api-payload-extract.ts
gs25-pgl-meta-export-payload-bins.ts
gs25-pgl-meta-payload-stability.ts
# Dtryx 복구 조사 — 2026-09-21
GHIDRA_URL="http://127.0.0.1:8080/list_functions"
new Request(`http://127.0.0.1:${port}${req.url}`, {.prettierignore
.prettierrc.json
CLAUDE.md
GEMINI.md
sha1: crypto.createHash('sha1').update(chunk).digest('hex').slice(0, 12),} from '../../src/api/healthCheckDefinitions.js';
const openapiModule = await import('../../dist/pages/openapi.js');import { DEFAULT_MCP_URL } from '../../src/cli/constants.js';import { DTRYX_API } from '../../src/services/dtryx/api.js';import { OLIVEYOUNG_API } from '../../src/services/oliveyoung/api.js';{"hostname":"oy-relay.aka.page","path":"^/v1/dtryx/.*$","service":"http://127.0.0.1:4320"}- `mitmweb` 실행 후 브라우저 UI(기본 `http://127.0.0.1:8081`)에서 캡처 로그를 확인할 수 있습니다.
- `OY_RELAY_URL`: 운영자가 관리하는 릴레이의 기본 HTTPS 주소. 개발 시 `http://127.0.0.1:4319` 허용.
### 
return base64.b64decode(s.encode("ascii"))const binary = atob(value);
Gates applied: no_behavioural_pass.
077e59e70b7bfull audit observations/trust-audit/mcp-server/hmmhmmhm__daiso.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 077e59e70b7b | BLOCK | D | 69 | first audit |
Questions
What is the Daiso MCP server?
다이소를 MCP로! 뿐만 아니라 한국 로컬 리테일과 영화관 조회를 MCP, CLI, Codex Skill로 가능하게 해줍니다.
What tools does Daiso expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Daiso safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Daiso need?
It reads CLOUDFLARE_API_TOKEN, CLOUDFLARE_GLOBAL_API_KEY, DTRYX_RELAY_TOKEN, GOOGLE_MAPS_API_KEY, OY_RELAY_TOKEN and ZYTE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Daiso run?
It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as daiso at 1.2.8.
How current is this page?
The grade is for one exact copy of the source (077e59e70b7b), read on 2026-10-03. The repository is watched and re-audited when it changes.