Nyt Cooking Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Nyt Cooking Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that lets an AI assistant (Claude, etc.) search New York Times Cooking, fetch full recipes, and browse your saved recipe box.
NYT Cooking has no official public API, so this reads the same JSON endpoints the website itself uses. The recipe paywall is enforced client-side, so searching and reading full recipes needs no login at all — only your personal saved recipe box requires a session cookie.
| Tool | Auth needed | Description |
|---|---|---|
search_recipes(query) | no | Search recipes by natural-language query. |
get_recipe(recipe_id) | no | Full recipe: ingredients, steps, time, rating. |
list_saved_recipes(page, per_page) | yes | Your saved recipe box. |
login(nyt_s_cookie, user_id) | — | Store credentials server-side and verify them. |
logout() | — | Delete the stored credentials. |
auth_status() | — | Check whether credentials are configured. |
Requires Python 3.10+. With uv:
git clone https://github.com/bramboe/nyt-cooking-mcp
cd nyt-cooking-mcp
uv run nyt-cooking-mcp # stdio (default)
uv run nyt-cooking-mcp --transport streamable-http --port 3001Or with pipx / pip:
pipx install git+https://github.com/bramboe/nyt-cooking-mcp
nyt-cooking-mcpAdd to your MCP config (claude_desktop_config.json, or via claude mcp add):
{
"mcpServers": {
"nyt-cooking": {
"command": "uv",
"args": ["run", "--directory", "/path/to/nyt-cooking-mcp", "nyt-cooking-mcp"]
}
}
}Then ask: "search NYT Cooking for marry me chicken" or "get NYT recipe 1024503".
list_saved_recipes is the only tool that needs your account. NYT Cooking has no OAuth, so credentials are harvested once from your logged-in browser and persisted server-side (like a session token). Call the `login` tool with:
NYT-S cookie on cooking.nytimes.com(DevTools → Application → Cookies).
regi_id value inside the regi_cookie.login verifies the cookie with a live request and writes it to the credentials file (--credentials-file, default ~/.config/nyt-cooking-mcp/credentials.json). Environment variables NYT_S_COOKIE / NYT_USER_ID override the stored file. The NYT-S cookie is long-lived; when calls start returning auth_required, run login again.
Run it as a systemd service over streamable-HTTP so it is always available:
# /etc/systemd/system/nyt-cooking-mcp.service
[Unit]
Description=NYT Cooking MCP Server
After=network.target
[Service]
User=nyt-cooking
ExecStart=/opt/nyt-cooking-mcp/.venv/bin/nyt-cooking-mcp \
--transport streamable-http --host 0.0.0.0 --port 3001 \
--credentials-file /var/lib/nyt-cooking-mcp/credentials.json
# Permit LAN access while keeping DNS-rebinding protection on (localhost always allowed):
Environment=NYT_MCP_ALLOWED_HOSTS=your.server.ip:*
Restart=on-failure
[Install]
WantedBy=multi-user.targetThe HTTP endpoint is then http://your.server:3001/mcp. Put a reverse proxy (TLS) and an auth token in front before exposing it beyond your trusted network.
For personal use. This is an unofficial tool not affiliated with The New York Times; respect NYT Cooking's Terms of Service and use your own account.
MIT — see LICENSE.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.