Job104 Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Job104 Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server for searching 104 人力銀行 job listings with natural-language filters. Works with any MCP client — Claude, Cursor, Windsurf, Cline, Zed, VS Code, and others.
Disclaimer: This is an unofficial, educational/personal-use tool. It is not affiliated with, endorsed by, or sponsored by 104 Corporation. It calls 104's public web endpoints; please respect 104's Terms of Service and use it at a reasonable, low frequency. No scraped job data is distributed with this project.
104 sits behind Cloudflare bot protection — a plain HTTP request to its JSON API returns 403. This server uses curl_cffi with impersonate="chrome" to match a real browser's TLS fingerprint, so the same public endpoints return their normal JSON. The AI sees clean structured results; the 104 category/area codes are resolved from Chinese names automatically.
Every install path runs the server through uv, so it must be installed first (uvx ships with uv):
curl -LsSf https://astral.sh/uv/install.sh | sh
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
MCP is an open protocol, so any MCP-capable client works — not just Claude. Add this to the client's MCP config (e.g. Cursor's ~/.cursor/mcp.json); the command/args form is what most clients accept:
{ "mcpServers": { "job104": { "command": "uvx", "args": ["job104-mcp@latest"] } } }
claude mcp add job104 -s user -- uvx job104-mcp@latest
Or from a local clone (no PyPI required):
claude mcp add job104 -- uv run --project /absolute/path/to/job104-mcp -m job104_mcp
The .mcpb bundle is a Claude-Desktop-only convenience (other clients use the JSON config above). Download job104-mcp-vX.Y.Z.mcpb from the Releases page and double-click it (or drag it into Claude Desktop → Settings → Extensions).
To build the bundle yourself:
npx @anthropic-ai/mcpb pack . # produces job104-mcp.mcpb
uv run job104-mcp
uv run python -m job104_mcp
search_jobs — search with keyword, area, job category, salary floor, remote,recency, experience, education, sort, paging. Use Chinese names for area/jobcat (e.g. ["台北市大安區"], ["軟體工程師"]); they resolve to 104 codes automatically. Each result carries a detail_id.
get_job_detail — full posting for a detail_id from search_jobs.lookup_code — resolve a job-category or area name to its 104 code.The bundled jobcat.json / area.json come from 104's public category tool. Regenerate:
uv run python scripts/fetch_codes.py
uv run pytest # fast unit tests uv run pytest -m live # hits the real 104 site
Releases are automated by .github/workflows/release.yml, triggered when the version in pyproject.toml changes on main. It publishes to PyPI, builds the .mcpb bundle, and attaches it to a GitHub Release.
One-time PyPI setup (uses Trusted Publishing, no API token stored): on <https://pypi.org/manage/account/publishing/> add a pending publisher with project job104-mcp, owner mozzan, repo job104-mcp, workflow release.yml.
To cut a release: bump version in pyproject.toml, commit to main.
MIT — see LICENSE. Provided as-is, without warranty.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.