Atlas / MCP servers / lis186 / Taiwan Holiday

Taiwan HolidaySAFE

mcp/lis186/taiwan-holiday

一個基於 Model Context Protocol (MCP) 的台灣假期查詢伺服器,為 AI 工具提供準確的台灣國定假日資訊。

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 6r · 2w · 0d
Transport
stdio
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://nodejs.org/) [](https://badge.fury.io/js/taiwan-holiday-mcp) [](https://opensource.org/licenses/MIT) [](https://cursor.com/install-mcp?name=taiwan-holiday&config=eyJjb21tYW5kIjoibnB4IHRhaXdhbi1ob2xpZGF5LW1jcCJ9)

一個基於 Model Context Protocol (MCP) 的台灣假期查詢伺服器,提供準確的台灣國定假日和補班日資訊。

✨ 特色功能

  • 🇹🇼 準確的台灣假期資料:基於 TaiwanCalendar 提供的政府公告假期資訊
  • 🚀 即時查詢:支援單日查詢、範圍查詢和統計查詢
  • 📅 多種日期格式:支援 YYYY-MM-DD 和 YYYYMMDD 格式
  • 🔄 智慧快取:自動快取資料,提升查詢效能
  • 🛠️ MCP 標準:完全相容 Model Context Protocol 規範
  • 🎯 AI 友善:專為 Claude Desktop、Cursor 等 AI 工具設計
  • 📊 豐富統計:提供假期統計和分析功能
  • 🌐 跨平台:支援 Windows、macOS 和 Linux

🚀 快速開始

NPX 直接使用(推薦)

最簡單的使用方式,無需安裝:

npx taiwan-holiday-mcp

本地安裝

npm install -g taiwan-holiday-mcp
taiwan-holiday-mcp

開發環境安裝

git clone https://github.com/lis186/taiwan-holiday-mcp.git
cd taiwan-holiday-mcp
npm install
npm run build
npm start

🔧 客戶端設定

Claude Desktop 設定

在 Claude Desktop 的設定檔中新增:

{
"mcpServers": {
"taiwan-holiday": {
"command": "npx",
"args": ["taiwan-holiday-mcp"]
}
}
}

設定檔位置:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json

Cursor 設定

點擊以下按鈕直接安裝。

[](https://cursor.com/install-mcp?name=taiwan-holiday&config=eyJjb21tYW5kIjoibnB4IHRhaXdhbi1ob2xpZGF5LW1jcCJ9)

Windsurf 設定

在專案的 .cursorrules 或設定檔中新增:

{
"mcp": {
"servers": {
"taiwan-holiday": {
"command": "npx",
"args": ["taiwan-holiday-mcp"]
}
Read from source at commit 93817587a811OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add taiwan-holiday-mcp -- npx -y [email protected]
03

Exposed tools (8)

6 read · 2 write · 0 destructive.

ToolRiskDescription
check_holidayread檢查指定日期是否為台灣假期
get_holiday_statsread獲取指定年份或年月的台灣假期統計資訊
get_holidays_in_rangeread獲取指定日期範圍內的所有台灣假期
快速健康檢查read快速系統健康狀態檢查
指定年份的假期統計write任一年份的假期統計(${getQueryableYearRange().start} 起;實際可用年份見 taiwan-holidays://years)
指定年份的台灣假期write任一年份的完整假期資料(${getQueryableYearRange().start} 起;實際可用年份見 taiwan-holidays://years)
支援的年份列表read列出所有支援查詢的年份範圍
系統健康狀態read即時系統健康狀態和診斷資訊
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.cursorindexingignore
.cursorindexingignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmessage
.gitmessage
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/build-and-package.test.ts:5
import { getCurrentYearInTaipei } from '../../src/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/task-6-1-integration.test.ts:13
import { TaiwanHolidayMcpServer } from '../../src/server';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/holiday-service-integration.test.ts:7
import { HolidayService, HolidayServiceError } from '../../src/holiday-service.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/holiday-service-integration.test.ts:8
import { Holiday, HolidayStats, ErrorType, getQueryableYearRange } from '../../src/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/circuit-breaker.test.ts:10
} from '../../src/utils/circuit-breaker.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/jest, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, jest, nock
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 93817587a811full audit observations/trust-audit/mcp-server/lis186__taiwan-holiday.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0993817587a811SAFEB89first audit
06

Questions

What is the Taiwan Holiday MCP server?

一個基於 Model Context Protocol (MCP) 的台灣假期查詢伺服器,為 AI 工具提供準確的台灣國定假日資訊。

What tools does Taiwan Holiday expose?

8 in total: 6 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Taiwan Holiday safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Taiwan Holiday need?

No credential environment variables were found in its source, so it appears to need none.

How does Taiwan Holiday run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as taiwan-holiday-mcp at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (93817587a811), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement