Korean JangbuSAFE
한국 스타트업, 1인 법인, 프리랜서, 개인 사업자를 위한 장부 자동 생성 Claude Code 스킬. 카드명세서 PDF·은행 CSV → 재무제표·세무사 전달 CSV 자동 생성. Level 2 민감정보 마스킹 적용.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/Apache-2.0) [](https://discord.gg/hqdGsY7UpH)
한국 스타트업·1인 법인 대표·프리랜서·개인사업자를 위한 장부 자동 생성 Claude Code 스킬 패키지. 카드명세서 PDF·은행 CSV·영수증을 넣으면 표준 거래내역·계정과목 매핑·재무제표·세무사 전달 CSV가 자동 생성됩니다.
한국 도메인 특화 AI 스페시아이에서 만듭니다. 법률·세무·노무·회계·의료 실무에 쓰는 도구를 오픈소스로 공개하고, 완성 제품은 speciai.kr 에서 운영합니다. → 제품 speciai.kr/services · 커뮤니티 디스코드
라이선스: Apache-2.0 버전: 0.2.0 저자: @kimlawtech (SpeciAI)
설계 원칙
- 입력은 넓게 — 엑셀·은행 CSV·카드 내역·영수증 이미지·세금계산서 PDF
- 출력은 단계적 — 세무용(BS·PL) / 경영용(현금흐름·cash burn)
- 계정체계는 매핑 — 내부 계정(유연) ↔ 국세청 표준계정(고정)
- 보안 Level 2 — 민감정보 마스킹 + 룰 우선 분류 + LLM fallback 최소화
스킬 구성
진입점 1개 + 하위 스킬 6개 + MCP 서버 1개.
지원 파일 포맷
HEIC/HEIF(iOS 기본 포맷)는 pip install pillow-heif 추가 설치 필요 (install.sh가 자동 처리).
폴더 일괄 처리: /korean-jangbu-for → [I] 선택 → 폴더 경로 입력 → 혼합된 파일들을 자동 분류·처리.
자동 수집 (BYOK — 사용자 본인 CODEF 키)
사용자가 직접 CODEF developer.codef.io에 무료 가입해 받은 Client ID/Secret
e469a0bb018aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add jangbu-mcp -- uvx jangbu-mcp
{
"mcpServers": {
"jangbu-mcp": {
"command": "uvx",
"args": [
"jangbu-mcp"
]
}
}
}Exposed tools (20)
17 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
apply_classification | write | 분류 결과 저장. source는 rule/llm/user 중 하나. |
classify_with_rules | read | 룰 기반으로 거래를 일괄 분류. 성공 건은 바로 저장. 실패 건 ID 리스트 반환. |
codef_credentials_save | write | CODEF Client ID / Secret / (선택)공개키 저장. 기본 Keychain, 실패 시 ~/.jangbu/credentials.env(권한 0o600). 외부 전송 없음. |
codef_credentials_status | read | CODEF 자동 수집 자격증명 등록 상태 확인. 키는 마스킹되어 프리뷰만 반환. |
codef_fetch_bank | read | CODEF 경유 은행 거래내역 자동 수집. 15개 은행 지원. 간편인증/ID-PW 사용. |
codef_fetch_card | read | CODEF 경유 카드 이용내역 자동 수집. 9개 카드사 지원. |
codef_fetch_hometax | read | CODEF 경유 홈택스 자동 수집 — 소득금액증명·납세증명·사업자등록증명 등. 간편인증 2단계 필요. |
export_djournal | read | 더존·세무사랑 호환 분개 CSV 출력. 세무사 전달용. 국세청 표준계정 + 부가세 간이 분리. 언마스킹 원본 기반, 로컬 파일만. |
export_report | read | BS/PL/현금흐름/cash burn 리포트를 로컬 파일로 생성. 언마스킹된 데이터 사용, 파일은 ~/.jangbu/reports/ 에만 저장. |
get_audit_log | read | 감사 로그 조회. append-only. |
get_transaction_masked | read | 단건 거래 마스킹 뷰 반환. |
ingest_folder | read | 폴더 내 모든 파일을 유형별로 자동 분류해 처리. 이미지(JPG/PNG/HEIC/HEIF/WEBP/TIFF/BMP/GIF)·PDF·엑셀·CSV 일괄. doc_type_hint로 영수증/세금계산서/카드명세서 힌트 지정 가능. |
ingest_raw | read | 엑셀/CSV 파일을 표준 거래내역으로 파싱해 SQLite에 적재. LLM에 원본을 노출하지 않음. |
list_transactions | read | 거래내역 목록을 마스킹된 뷰로 반환. LLM 전달 전용. |
mcp_health | read | MCP 서버 동작·DB·OCR 엔진·파일 포맷 지원 상태를 한 번에 점검. 설치 직후·트러블슈팅 시 사용. |
ocr_analyze | read | OCR 파싱 후 unparsed 패턴 분석 + 가맹점·카드 식별자 alias 제안. Level 2 준수 — 거래 내역 금액·사업자번호 등은 요약에 포함 안함. 결과를 사용자에게 보여주고 동의 시 ocr_apply_alias로 적용. |
ocr_apply_alias | write | 사용자가 승인한 alias 저장 + 기존 거래내역 일괄 갱신. correction_type=counterparty_alias / card_last3_alias / biz_id_alias. |
ocr_document | read | 영수증·세금계산서·통장 스캔·카드명세서(PDF)를 PaddleOCR(로컬)로 처리. 구조화까지 수행. card_statement_scan은 신한카드 포맷 우선 지원. |
ocr_list_corrections | read | 저장된 OCR 보정 alias 목록 조회. |
security_status | read | 보안 레이어 상태 점검 (마스킹·토큰DB·감사로그·파일권한). 사용자 안내용 요약 반환. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
e469a0bb018afull audit observations/trust-audit/mcp-server/kimlawtech__korean-jangbu.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e469a0bb018a | SAFE | B | 89 | first audit |
Questions
What is the Korean Jangbu MCP server?
한국 스타트업, 1인 법인, 프리랜서, 개인 사업자를 위한 장부 자동 생성 Claude Code 스킬. 카드명세서 PDF·은행 CSV → 재무제표·세무사 전달 CSV 자동 생성. Level 2 민감정보 마스킹 적용.
What tools does Korean Jangbu expose?
20 in total: 17 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Korean Jangbu safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Korean Jangbu need?
No credential environment variables were found in its source, so it appears to need none.
How does Korean Jangbu run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as jangbu-mcp.
How current is this page?
The grade is for one exact copy of the source (e469a0bb018a), read on 2026-10-07. The repository is watched and re-audited when it changes.