Atlas / MCP servers / jinzcdev / LeetCode

LeetCodeBLOCK

mcp/jinzcdev/leetcode-1

An MCP server enabling automated access to LeetCode's problems, solutions, and public data with optional authentication for user-specific features, supporting leetcode.com & leetcode.cn sites.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
19 15r · 4w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
153
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@jinzcdev/leetcode-mcp-server) [](README_zh-CN.md) [](https://www.npmjs.com/package/@jinzcdev/leetcode-mcp-server) [](./LICENSE) [](https://glama.ai/mcp/servers/jinzcdev/leetcode-mcp-server) [](https://github.com/jinzcdev/leetcode-mcp-server)

The LeetCode MCP Server is a Model Context Protocol (MCP) server that provides seamless integration with LeetCode APIs, enabling advanced automation and intelligent interaction with LeetCode's programming problems, contests, solutions, and user data.

Features

  • 🌐 Multi-site Support: Support both leetcode.com (Global) and leetcode.cn (China) platforms
  • 🔌 Dual Transport Modes: Run as a stdio process (default) or as a Streamable HTTP server for web-based integrations
  • 📊 Problem Data Retrieval: Obtain detailed problem descriptions, constraints, examples, official editorials, and user-submitted solutions
  • 👤 User Data Access: Retrieve user profiles, submission history, and contest performance
  • 🔒 Private Data Access: Create and query user notes, track problem-solving progress, and analyze submission details (AC/WA analysis)
  • 🔍 Advanced Search Capabilities: Filter problems by tags, difficulty levels, categories, and keywords
  • 📅 Daily Challenge Access: Easily access daily challenge problems

Prerequisites

  1. Node.js (v20.x or above)
  2. (Optional) LeetCode
Read from source at commit 844afb8654caOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add leetcode-mcp-server -- npx -y @jinzcdev/[email protected]
claude-desktop
{
  "mcpServers": {
    "leetcode-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@jinzcdev/[email protected]"
      ]
    }
  }
}
03

Exposed tools (19)

15 read · 4 write · 0 destructive.

ToolRiskDescription
create_notewriteCreates a new personal note for a problem (write operation, requires auth, CN only). Supports markdown content. Returns { success, note } as JSON. Use update_note to modify an existing note by noteId.
get_all_submissionsreadRetrieves paginated submission history for the authenticated user on LeetCode Global (read-only, requires auth). Optionally filter by problem slug. Use get_recent_submissions/get_recent_ac_submissions to view any user
get_daily_challengereadRetrieves today
get_notereadRetrieves personal notes for a specific problem by questionId (read-only, requires auth, CN only). Use search_notes to find notes across problems by keyword when you don
get_problemreadRetrieves a single LeetCode problem by titleSlug (read-only, no auth). Returns description, examples, constraints, and metadata as JSON. Use search_problems to find problems by keyword/tag/difficulty; use get_daily_challenge for today
get_problem_progressreadRetrieves the authenticated user
get_problem_solutionreadRetrieves full content of a community solution article (read-only, no auth). Requires topicId from list_problem_solutions. Returns article text, author, and metadata as JSON. Use list_problem_solutions first to discover solutions and obtain topicId.
get_problem_submission_reportread
get_recent_ac_submissionsreadRetrieves a user
get_recent_submissionsreadRetrieves a user
get_user_contest_rankingreadRetrieves a user
get_user_profilereadRetrieves any user
get_user_statusreadChecks the authenticated user
list_problem_solutionsreadLists community solution articles for a problem (read-only, no auth). Returns metadata only (topicId)—not full content. Use get_problem_solution with the returned topicId to read the full article. Do not call this when you already have a topicId and need the solution text.
run_codewrite
search_notesreadSearches the authenticated user
search_problemsreadSearches LeetCode problems by category, tags, difficulty, and keywords (read-only, no auth). Supports pagination via limit/offset. Returns matching problem list as JSON. Use get_problem when you already know the titleSlug; use this to browse or discover problems.
submit_solutionwrite
update_notewriteUpdates an existing personal note by noteId (write operation, requires auth, CN only). Use create_note for new notes; use get_note or search_notes first to find the noteId.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:14
- 🌐 **Multi-site Support**: Support both leetcode.com (Global) and leetcode.cn (China) platforms
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:16
- 📊 **Problem Data Retrieval**: Obtain detailed problem descriptions, constraints, examples, official editorials, and user-submitted solutions
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:18
- 🔒 **Private Data Access**: Create and query user notes, track problem-solving progress, and analyze submission details (AC/WA analysis)
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README_zh-CN.md:16
- 📊 **题目数据获取**:获取详细的题目描述、约束条件、示例、官方题解和用户提交的解答
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/resources/problem-resources.ts:9
} from "../../common/constants.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/resources/problem-resources.ts:10
import { LeetCodeBaseService } from "../../leetcode/leetcode-base-service.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/resources/resource-registry.ts:2
import { RegistryBase } from "../../common/registry-base.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/resources/resource-registry.ts:3
import { LeetCodeBaseService } from "../../leetcode/leetcode-base-service.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/resources/solution-resources.ts:5
import { LeetCodeBaseService } from "../../leetcode/leetcode-base-service.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:144
"url": "http://127.0.0.1:3000/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_zh-CN.md:144
"url": "http://127.0.0.1:3000/mcp"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, leetcode-query, minimist, pino, ts-node, zod, @eslint/js, @types/minimist
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 844afb8654cafull audit observations/trust-audit/mcp-server/jinzcdev__leetcode-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07844afb8654caBLOCKD69first audit
06

Questions

What is the LeetCode MCP server?

An MCP server enabling automated access to LeetCode's problems, solutions, and public data with optional authentication for user-specific features, supporting leetcode.com & leetcode.cn sites.

What tools does LeetCode expose?

19 in total: 15 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is LeetCode safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does LeetCode need?

No credential environment variables were found in its source, so it appears to need none.

How does LeetCode run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @jinzcdev/leetcode-mcp-server at 1.4.0.

How current is this page?

The grade is for one exact copy of the source (844afb8654ca), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement