Atlas / MCP servers / pfldy2850 / Py-MCP-Naver

Py-MCP-NaverSAFE

mcp/pfldy2850/py-mcp-naver

python MCP NAVER

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
14 14r · 0w · 0d
Transport
—
License
MIT
Stars
115
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A server implementation for Naver OpenAPI using the Model Context Protocol (MCP). This project provides tools to interact with various Naver services, such as searching blogs, news, books, and more.

Pre-requisite

To use the Naver MCP server, you need to apply for access to the Naver Open API. You can apply for Open API access at the link below:

https://developers.naver.com/apps/#/register=datalab

Installation

from PyPi (Claude Desktop)

Install it to Claude Desktop with (uv):

uv pip install mcp-naver

uv run python -m mcp-naver.hosts.claude_desktop \
-e NAVER_CLIENT_ID= \
-e NAVER_CLIENT_SECRET=

Install it to Claude Desktop with:

pip install mcp-naver

python -m mcp-naver.hosts.claude_desktop \
-e NAVER_CLIENT_ID= \
-e NAVER_CLIENT_SECRET=

from PyPi (Cursor)

Install it to Cursor with (uv):

uv pip install mcp-naver

uv run python -m mcp-naver.hosts.cursor \
-e NAVER_CLIENT_ID= \
-e NAVER_CLIENT_SECRET=

from source

# Clone the repository
git clone https://github.com/pfldy2850/py-mcp-naver.git

# Navigate into the project directory
cd py-mcp-naver

# Synchronize dependencies
uv sync --dev --all-extras

Run it with:

# Start the server (Using FastMCP CLI)
fastmcp install mcp_naver/server.py -e NAVER_CLIENT_ID= -e NAVER_CLIENT_SECRET=

The tool sets up everything you need to create an MCP server integrated with Naver OpenAPI.

Features

This server provides the following tools for interacting with Naver OpenAPI:

  • Blog Search: Search blog posts on Naver.
  • News Search: Search news articles on Naver.
  • Book Search: Search books and advanced book information.
  • Adult Content Check: Check if a search term is adult content.
  • Encyclopedia Search: Searc
Read from source at commit 80e4ff0f6564OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-naver --env NAVER_CLIENT_SECRET=${NAVER_CLIENT_SECRET} -- uvx mcp-naver
claude-desktop
{
  "mcpServers": {
    "mcp-naver": {
      "command": "uvx",
      "args": [
        "mcp-naver"
      ],
      "env": {
        "NAVER_CLIENT_SECRET": "${NAVER_CLIENT_SECRET}"
      }
    }
  }
}
03

Exposed tools (14)

14 read · 0 write · 0 destructive.

ToolRiskDescription
adult_checkread
fix_spellingread
get_book_advread
search_blogread
search_bookread
search_cafe_articleread
search_docread
search_encycread
search_imageread
search_kinread
search_localread
search_newsread
search_shopread
search_webkrread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 80e4ff0f6564full audit observations/trust-audit/mcp-server/pfldy2850__py-mcp-naver.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0780e4ff0f6564SAFEB89first audit
06

Questions

What is the Py-MCP-Naver MCP server?

python MCP NAVER

What tools does Py-MCP-Naver expose?

14 in total: 14 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Py-MCP-Naver safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Py-MCP-Naver need?

It reads NAVER_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (80e4ff0f6564), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement