Korean Law MCP (pragato-throwaway/korean-law-mcp-unclean) is an MCP server listed on the M8ven Trust Index. It scores 60 out of 100, grade C. It declares 10 tools. No publisher has claimed this listing.

C
Caution
60/100

Korean Law MCP

MCP server providing comprehensive Korean legal data access (laws, precedents, regulations, ordinances) with citation verification, temporal comparison, impact graphs, and legal research workflows.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Sandbox Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

pragato-throwaway

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

⏳ This MCP is queued for scoring. Check back in a few minutes.
// key findings
⚠️
Known vulnerabilities in dependencies: 5 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: KOREAN_LAW_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies5 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@xmldom/xmldom@0.9.8GHSA-2v35-w6hq-6mfw

xmldom: Uncontrolled recursion in XML serialization leads to DoS

high@xmldom/xmldom@0.9.8GHSA-f6ww-3ggp-fr8h

xmldom has XML injection through unvalidated DocumentType serialization

high@xmldom/xmldom@0.9.8GHSA-j759-j44w-7fr8

xmldom has XML node injection through unvalidated comment serialization

high@xmldom/xmldom@0.9.8GHSA-wh4c-j3r5-mjhp

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

high@xmldom/xmldom@0.9.8GHSA-x6wf-f3px-wcqx

xmldom has XML node injection through unvalidated processing instruction serialization

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configACCESS_LOG
configCORS_ORIGIN
configFALLBACK_RATE_LIMIT_RPM
🔐 secretKOREAN_LAW_API_KEY
configLAW_API_PROTOCOL폐쇄망/인증서 문제 환경을 위해 =http 옵션 추가(기본 https). 판례 재검색 키워드 후보 생성 개선으로 매칭률 향상. (외부 PR #41/#42)
configLAW_EXTERNAL_HTTPS_PROXYsetx http://proxy-host:8080 /M
configLAW_EXTERNAL_TLS_REJECT_UNAUTHORIZEDsetx 0 /M
configLAW_OC"": "honggildong"
configLAW_REFERER
configLAW_RESPONSE_TYPE
configLAW_USER_AGENTfetch-with-retry.ts에 일반 브라우저 UA 기본 헤더 주입 — 호출자 코드 변경 0, 한 줄 패치로 모든 도구 복구. 환경변수로 override 가능
configMCP_BODY_LIMIT
configMCP_MAX_BATCH_CALLSv4.7.0 보안·운영 패치 동봉: JSON-RPC 배치의 tools/call을 개수만큼 rate limit·폴백 쿼터에 계수(배치 증폭 차단, 요청당 상한 20 — ) + graceful shutdown idle 연결 정리(clean exit) + get_article_history lawName 정확매칭 우선(가나다순 오매칭 방지)
configNO_COLOR
configRATE_LIMIT_RPM
configTRUST_PROXY보안 High 2건 — fetch-with-retry.ts 타임아웃/네트워크 에러에 API 키 포함 URL이 로그로 유출되던 문제 → maskSensitiveUrl()로 OC= 마스킹. trust proxy true → 환경변수(기본 1), X-Forwarded-For 스푸핑 rate limit 우회 차단
// quality suggestions

Shell command execution

32 child_process calls — runs shell commands

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Production dependencies are patched

0 critical, 5 high severity in production deps — @xmldom/xmldom@0.9.8 (high), @xmldom/xmldom@0.9.8 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/pragato-throwaway/korean-law-mcp-unclean?variant=verified)](https://m8ven.ai/mcp/pragato-throwaway/korean-law-mcp-unclean)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 3e86381dd0cc5f34497f978571a38143c340c821
code hash: 55e736fcd0380330f8495fa3ff075d5b404e37baf295379d107876df85820282
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client