korean-law-alio-mcp
npm
v1.0.8
Published by scvcoder — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
국가법령정보센터(법제처) + ALIO 공공기관 규정 통합 MCP 서버 — 35,000건 이상의 법령·공공기관 내부규정을 자연어로 조회·비교·분석
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 7 = 93. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`build/lib/alio/docling-fallback.js:22`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; import fs from "node:fs/promises"; import path from "node:path"; import os from
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server build/lib/alio/docling-fallback.js
In the server's implementation (`build/lib/alio/hwp3-fallback.js:28`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; import fs from "node:fs/promises"; import path from "node:path"; import os from
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server build/lib/alio/hwp3-fallback.js
In the server's implementation (`build/lib/alio/xls-fallback.js:21`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; import fs from "node:fs/promises"; import path from "node:path"; import os from
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server build/lib/alio/xls-fallback.js
In a packaging/dev/install script (shipped, but not the server runtime) (`build/scripts/setup.js:26`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; import { Readable } from "node:stream"; import { pipeline } from "node:stream/pr
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server build/scripts/setup.js
Each tool and what it can reach — statically extracted from the published source.
advanced_alio_searchno sensitive capabilityadvanced_searchno sensitive capabilityanalyze_alio_regulationno sensitive capabilityanalyze_documentno sensitive capabilityanalyze_regulation_delegationno sensitive capabilitychain_action_basisno sensitive capabilitychain_alio_benchmarkno sensitive capabilitychain_amendment_trackno sensitive capabilitychain_dispute_prepno sensitive capabilitychain_document_reviewno sensitive capabilitychain_full_researchno sensitive capabilitychain_law_systemno sensitive capabilitychain_ordinance_compareno sensitive capabilitychain_procedure_detailno sensitive capabilitycompare_admin_rule_old_newno sensitive capabilitycompare_alio_articlesno sensitive capabilitycompare_alio_regulationsno sensitive capabilitycompare_articlesno sensitive capabilitycompare_old_newno sensitive capabilitycompare_regulation_timelineno sensitive capabilityextract_precedent_keywordsno sensitive capabilityfind_regulations_by_upper_lawno sensitive capabilityfind_similar_precedentsno sensitive capabilityfind_similar_regulationsno sensitive capabilityget_acr_decision_textno sensitive capabilityget_acr_special_appeal_textno sensitive capabilityget_admin_appeal_textno sensitive capabilityget_admin_ruleno sensitive capabilityget_alio_annexesno sensitive capabilityget_alio_external_linksno sensitive capabilityget_alio_institution_profileno sensitive capabilityget_alio_regulationno sensitive capabilityget_alio_regulation_historyno sensitive capabilityget_alio_statisticsno sensitive capabilityget_annexesno sensitive capabilityget_appeal_review_decision_textno sensitive capabilityget_article_detailno sensitive capabilityget_article_historyno sensitive capabilityget_article_with_precedentsno sensitive capabilityget_batch_alio_regulationsno sensitive capabilityget_batch_articlesno sensitive capabilityget_constitutional_decision_textno sensitive capabilityget_customs_interpretation_textno sensitive capabilityget_daily_termno sensitive capabilityget_daily_to_legalno sensitive capabilityget_delegated_lawsno sensitive capabilityget_english_law_textno sensitive capabilityget_external_linksno sensitive capabilityget_ftc_decision_textno sensitive capabilityget_historical_lawno sensitive capabilityget_interpretation_textno sensitive capabilityget_law_abbreviationsno sensitive capabilityget_law_historyno sensitive capabilityget_law_statisticsno sensitive capabilityget_law_system_treeno sensitive capabilityget_law_textno sensitive capabilityget_law_treeno sensitive capabilityget_legal_term_detailno sensitive capabilityget_legal_term_kbno sensitive capabilityget_legal_to_dailyno sensitive capabilityget_linked_laws_from_ordinanceno sensitive capabilityget_linked_ordinance_articlesno sensitive capabilityget_linked_ordinancesno sensitive capabilityget_nlrc_decision_textno sensitive capabilityget_ordinanceno sensitive capabilityget_pipc_decision_textno sensitive capabilityget_precedent_textno sensitive capabilityget_public_corp_rule_textno sensitive capabilityget_public_institution_rule_textno sensitive capabilityget_recent_alio_revisionsno sensitive capabilityget_related_lawsno sensitive capabilityget_school_rule_textno sensitive capabilityget_tax_tribunal_decision_textno sensitive capabilityget_term_articlesno sensitive capabilityget_three_tierno sensitive capabilityget_treaty_textno sensitive capabilitylist_alio_regulationsno sensitive capabilityparse_alio_article_linksno sensitive capabilityparse_article_linksno sensitive capabilityparse_jo_codeno sensitive capabilitysearch_acr_decisionsno sensitive capabilitysearch_acr_special_appealsno sensitive capabilitysearch_admin_appealsno sensitive capabilitysearch_admin_ruleno sensitive capabilitysearch_ai_lawno sensitive capabilitysearch_alio_regulation_textno sensitive capabilitysearch_allno sensitive capabilitysearch_appeal_review_decisionsno sensitive capabilitysearch_constitutional_decisionsno sensitive capabilitysearch_customs_interpretationsno sensitive capabilitysearch_english_lawno sensitive capabilitysearch_ftc_decisionsno sensitive capabilitysearch_historical_lawno sensitive capabilitysearch_institutionno sensitive capabilitysearch_interpretationsno sensitive capabilitysearch_lawno sensitive capabilitysearch_legal_termsno sensitive capabilitysearch_nlrc_decisionsno sensitive capabilitysearch_ordinanceno sensitive capabilitysearch_pipc_decisionsno sensitive capabilitysearch_precedentsno sensitive capabilitysearch_public_corp_rulesno sensitive capabilitysearch_public_institution_rulesno sensitive capabilitysearch_school_rulesno sensitive capabilitysearch_tax_tribunal_decisionsno sensitive capabilitysearch_treatiesno sensitive capabilitysuggest_alio_benchmarkno sensitive capabilitysuggest_alio_regulation_namesno sensitive capabilitysuggest_law_namesno sensitive capabilitysummarize_precedentno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.0.8 latest |
A 93/100 | 4 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan korean-law-alio-mcp --online
Free public tax reference data — GST/VAT, income, company and capital-gains tax rules for 50+ countries.
The approval gate for unattended UCP buying agents — a policy/approval MCP proxy in front of a merchant's UCP checkout endpoint.
Autotask PSA MCP server. Generic entity query/get/create/update across the full REST API plus convenience tools for tickets, companies, contacts, projects, tasks and time entries. AI-safe with readonly mode and destructive-action confirmation. stdio + opt
MCP server for B2C Commerce developer experience tools
Search, compare and contact real-world companies through a public MCP business directory.
Norwegian business register (Brønnøysundregistrene) as an MCP server — companies, roles, subunits and annual accounts, with the register's silent traps encoded as guards.