Opendart (RealYoungk) MCP Server

opendart-mcp PyPI v0.1.0

Published by realyoungk — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.

OpenDART (DART 전자공시시스템) MCP Server - 금융감독원 공시정보 API

Trust grade
A
93/100
Last scanned get badge →
Trust
A · 93/100
Adoption risk for you: the threat score, then adjusted down for blast radius, publisher verification and how much the scan could see. Deterministic; every point is auditable.
Capability
High
Blast radius if it went rogue — what the server’s tools could reach. Independent of trust.
Coverage
Source
How much the scan could actually inspect. Shallow coverage is stated, never hidden.
Share this Trust Score
𝕏 Share LinkedIn Reddit
A Why this grade threat 100 − adoption risk = 93/100

The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.

1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:

The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.

2. Client adoption risk — 100 − 7 = 93. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:

PointsAdoption-risk factor
−6 capability blast radius (high) — client exposure if the model is manipulated
−1 publisher verification (public source) — no provenance, but the source is public and inspectable

Capability observations and info notes are shown under Findings but never scored. Open any row's finding below for the file, line and evidence behind a deduction.

Findings 2

high Tool "get_unregistered_exec_compensation" exposes command/code executionMTC-CAP-001

Tool "get_unregistered_exec_compensation" appears to run shell commands or evaluate code (keyword "exec" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.

Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.

Location: tool get_unregistered_exec_compensation

low Mutating tool "get_unregistered_exec_compensation" declares no destructiveHintMTC-CAP-005

Tool "get_unregistered_exec_compensation" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.

Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.

Location: tool get_unregistered_exec_compensation

Tools 83

Each tool and what it can reach — statically extracted from the published source.

  • get_unregistered_exec_compensationruns code / shell
  • get_asset_transfer_putbackno sensitive capability
  • get_audit_service_contractno sensitive capability
  • get_auditor_opinionno sensitive capability
  • get_bond_with_warrant_decisionno sensitive capability
  • get_business_acquisition_decisionno sensitive capability
  • get_business_suspensionno sensitive capability
  • get_business_transfer_decisionno sensitive capability
  • get_capital_reductionno sensitive capability
  • get_commercial_paper_balanceno sensitive capability
Show 73 more tools ↓
  • get_company_infono sensitive capability
  • get_compensation_by_typeno sensitive capability
  • get_contingent_bond_decisionno sensitive capability
  • get_contingent_capital_balanceno sensitive capability
  • get_convertible_bond_decisionno sensitive capability
  • get_corp_codeno sensitive capability
  • get_corporate_bond_balanceno sensitive capability
  • get_creditor_management_startno sensitive capability
  • get_creditor_management_stopno sensitive capability
  • get_debt_securities_issuedno sensitive capability
  • get_debt_securities_regno sensitive capability
  • get_default_occurrenceno sensitive capability
  • get_depositary_receipts_regno sensitive capability
  • get_dissolution_eventno sensitive capability
  • get_dividend_infono sensitive capability
  • get_division_decisionno sensitive capability
  • get_division_merger_decisionno sensitive capability
  • get_division_regno sensitive capability
  • get_documentno sensitive capability
  • get_employee_statusno sensitive capability
  • get_equity_securities_regno sensitive capability
  • get_exchangeable_bond_decisionno sensitive capability
  • get_executive_statusno sensitive capability
  • get_executive_stockholdingno sensitive capability
  • get_free_capital_increaseno sensitive capability
  • get_full_financial_statementno sensitive capability
  • get_individual_compensationno sensitive capability
  • get_investment_in_othersno sensitive capability
  • get_largest_shareholderno sensitive capability
  • get_largest_shareholder_changeno sensitive capability
  • get_lawsuit_filingno sensitive capability
  • get_major_stockholdingno sensitive capability
  • get_merger_decisionno sensitive capability
  • get_merger_regno sensitive capability
  • get_minority_shareholderno sensitive capability
  • get_mixed_capital_increaseno sensitive capability
  • get_multi_company_accountsno sensitive capability
  • get_multi_financial_indexno sensitive capability
  • get_new_capital_securities_balanceno sensitive capability
  • get_non_audit_service_contractno sensitive capability
  • get_other_corp_stock_acquisition_decisionno sensitive capability
  • get_other_corp_stock_transfer_decisionno sensitive capability
  • get_outside_director_statusno sensitive capability
  • get_overseas_delistingno sensitive capability
  • get_overseas_delisting_decisionno sensitive capability
  • get_overseas_listingno sensitive capability
  • get_overseas_listing_decisionno sensitive capability
  • get_paid_capital_increaseno sensitive capability
  • get_private_placement_fund_usageno sensitive capability
  • get_public_offering_fund_usageno sensitive capability
  • get_rehabilitation_filingno sensitive capability
  • get_short_term_bond_balanceno sensitive capability
  • get_single_company_accountsno sensitive capability
  • get_single_financial_indexno sensitive capability
  • get_stock_bond_acquisition_decisionno sensitive capability
  • get_stock_bond_transfer_decisionno sensitive capability
  • get_stock_exchange_regno sensitive capability
  • get_stock_exchange_transfer_decisionno sensitive capability
  • get_stock_issuance_statusno sensitive capability
  • get_tangible_asset_acquisition_decisionno sensitive capability
  • get_tangible_asset_transfer_decisionno sensitive capability
  • get_top5_compensationno sensitive capability
  • get_total_compensationno sensitive capability
  • get_total_compensation_approvalno sensitive capability
  • get_total_shares_statusno sensitive capability
  • get_treasury_stock_acquisition_decisionno sensitive capability
  • get_treasury_stock_disposal_decisionno sensitive capability
  • get_treasury_stock_statusno sensitive capability
  • get_treasury_trust_contract_decisionno sensitive capability
  • get_treasury_trust_termination_decisionno sensitive capability
  • get_xbrl_documentno sensitive capability
  • get_xbrl_taxonomyno sensitive capability
  • search_disclosureno sensitive capability

What this scan could not see

Versions 1

Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.

VersionScoreFindingsEngineScanned
v0.1.0 latest A 93/100 2 1.13.0 2026-08-25

Embed this score

Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.

MCP Trust Score: A · 93/100
Markdown (GitHub README)
[![MCP Trust Score](https://mcptrustchecker.com/registry/opendart-mcp-2/badge.svg)](https://mcptrustchecker.com/registry/opendart-mcp-2)
HTML
<a href="https://mcptrustchecker.com/registry/opendart-mcp-2"><img src="https://mcptrustchecker.com/registry/opendart-mcp-2/badge.svg" alt="MCP Trust Score" height="20"></a>
Prefer shields.io styling? Point it at https://mcptrustchecker.com/registry/opendart-mcp-2/badge.json via https://img.shields.io/endpoint?url=…

Verify this score yourself

The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.

npx mcptrustchecker scan opendart-mcp --online --registry pypi

Use the free API → How scoring works

Other implementations of Opendart 2

Independent packages implementing the same tool, scanned with the same engine. Compare all 3 side by side →

More in Finance & Commerce