Atlas / MCP servers / isnow890 / Naver Search

Naver SearchCAUTION

mcp/isnow890/naver-search

MCP server for Naver Search API integration. Provides comprehensive search capabilities across Naver services (web, news, blog, shopping, etc) and data trend analysis tools via DataLab API.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
18 18r · 0w · 0d
Transport
stdio
License
MIT
Stars
88
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@isnow890/naver-search-mcp) [](https://opensource.org/licenses/MIT)

네이버 검색 API 및 DataLab(데이터랩) API 연동을 위한 Model Context Protocol(MCP) 서버입니다. 웹, 뉴스, 블로그, 쇼핑인사이트, 검색어 트렌드 분석 및 자연어 쇼핑 카테고리 검색을 지원합니다.

  • English Documentation (README-en.md)

빠른 설정 (Quick Start)

Claude Desktop, Cursor, Claude Code, Cline 등 사용하시는 MCP 클라이언트 설정 파일(claude_desktop_config.json, mcp.json 등)의 mcpServers에 아래 설정을 추가하세요.

안내: Kakao PlayMCP 연동 서비스는 지원이 종료되었습니다. 로컬 환경에서 직접 API 키를 설정하여 이용해 주세요.

1. NAVER API HUB (권장 / 신규 발급)

네이버 클라우드 플랫폼(NCP)의 NAVER API HUB 키를 사용하는 경우:

{
"mcpServers": {
"naver-search": {
"command": "npx",
"args": ["-y", "@isnow890/naver-search-mcp"],
"env": {
"NCP_APIGW_API_KEY_ID": "your_client_id",
"NCP_APIGW_API_KEY": "your_client_secret"
}
}
}
}

2. 네이버 개발자센터 (기존 발급자 전용)

기존 네이버 개발자센터(openapi.naver.com) 키를 사용하는 경우 (2027-06-30까지 지원):

{
"mcpServers": {
"naver-search": {
"command": "npx",
"args": ["-y", "@isnow890/naver-search-mcp"],
"env": {
"NAVER_CLIENT_ID": "your_client_id",
"NAVER_CLIENT_SECRET": "your_client_secret"
}
}
}
}

API 키 발급 안내

사용하시는 환경변수 쌍에 따라 호출 플랫폼이 자동으로 결정됩니다. (둘 중 한 쌍만 설정하세요)

Read from source at commit 579a3cc4f227OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add naver-search-mcp --env NAVER_CLIENT_SECRET=${NAVER_CLIENT_SECRET} --env NCP_APIGW_API_KEY=${NCP_APIGW_API_KEY} --env NCP_APIGW_API_KEY_ID=${NCP_APIGW_API_KEY_ID} -- npx -y @isnow890/[email protected]
claude-desktop
{
  "mcpServers": {
    "naver-search-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@isnow890/[email protected]"
      ],
      "env": {
        "NAVER_CLIENT_SECRET": "${NAVER_CLIENT_SECRET}",
        "NCP_APIGW_API_KEY": "${NCP_APIGW_API_KEY}",
        "NCP_APIGW_API_KEY_ID": "${NCP_APIGW_API_KEY_ID}"
      }
    }
  }
}
03

Exposed tools (18)

18 read · 0 write · 0 destructive.

ToolRiskDescription
datalab_searchread
datalab_shopping_by_ageread
datalab_shopping_by_deviceread
datalab_shopping_by_genderread
datalab_shopping_categoryread
datalab_shopping_keyword_by_ageread
datalab_shopping_keyword_by_deviceread
datalab_shopping_keyword_by_genderread
datalab_shopping_keywordsread
find_categoryread
search_blogread
search_cafearticleread
search_encycread
search_imageread
search_kinread
search_localread
search_newsread
search_webkrread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (5)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/clients/naver-api-endpoints.ts:32
legacy: { id: "X-Naver-Client-Id", secret: "X-Naver-Client-Secret" },
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/naver-api-endpoints.test.js:62
secret: "X-Naver-Client-Secret",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/naver-search-client.test.js:82
() => client.get("http://127.0.0.1:1/nope", {}),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/naver-search-client.test.js:98
const pending = client.get("http://127.0.0.1:1/nope", {});
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, zod, zod-to-json-schema, sharp, dotenv, @types/node, shx, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 579a3cc4f227full audit observations/trust-audit/mcp-server/isnow890__naver-search.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07579a3cc4f227CAUTIONB89first audit
06

Questions

What is the Naver Search MCP server?

MCP server for Naver Search API integration. Provides comprehensive search capabilities across Naver services (web, news, blog, shopping, etc) and data trend analysis tools via DataLab API.

What tools does Naver Search expose?

18 in total: 18 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Naver Search safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Naver Search need?

It reads NAVER_CLIENT_SECRET, NCP_APIGW_API_KEY and NCP_APIGW_API_KEY_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Naver Search run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @isnow890/naver-search-mcp at 1.0.52.

How current is this page?

The grade is for one exact copy of the source (579a3cc4f227), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement