Atlas / MCP servers / 7gugu / Whistle

WhistleCAUTION

mcp/7gugu/whistle

A Whistle proxy management tool based on Model Context Protocol that allows AI assistants to directly control local Whistle proxy servers, simplifying network debugging, API testing, and proxy rule configuration through natural language interaction.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
34 34r · 0w · 0d
Transport
streamable-http
License
MIT
Stars
44
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

Project Introduction

Whistle MCP Server is a Whistle proxy management tool based on the Model Context Protocol (MCP), allowing AI assistants to directly operate and control local Whistle proxy servers. Through this tool, AI can help users manage rules, groups, values, monitor network requests, replay and modify requests, etc., without requiring manual operation of the Whistle interface. It greatly simplifies the process of network debugging, API testing, and proxy rule management, enabling users to complete complex network proxy configuration tasks through natural language interaction with AI.

Features

  • Rule Management: Create, update, rename, delete, and enable/disable Whistle rules
  • Group Management: Create, rename, delete groups, and associate operations between rules and groups
  • Value Management: Create, update, rename, and delete values, with support for value group management
  • Proxy Control: Enable/disable proxy, HTTP/HTTPS interception, HTTP/2 protocol, etc.
  • Request Interception: View intercepted network request information, with URL filtering support
  • Request Replay: Support for replaying captured requests with custom request parameters
  • Multi-Rule Mode: Support for enabling/disabling multi-rule mode

Installation

Requirements

Node.js 18.20.0 or newer is required (see engines in package.json). Older versions are not supported.

Installing via Smithery

To install Whistle MCP Server for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @7gugu/whistle-mcp --client claude

Manual Installation

You can install Whistle MCP Server globally via npm:

npm install -g whistle-mcp-tool

Build from source

From the repository root:

npm install
npm run build

The build output entry is `dist/index.js` (the same file used by the `whistle-m

Read from source at commit 827ea67b6e05OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add whistle-mcp-tool -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "whistle-mcp-tool": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (34)

34 read · 0 write · 0 destructive.

ToolRiskDescription
addRuleToGroupread将规则添加到分组
addValueToGroupread将值添加到分组
createGroupread创建新分组
createRuleread创建新规则
createValueread创建新的值
createValuesGroupread创建新的值分组
deleteGroupread删除分组
deleteRuleread删除规则
deleteValueread删除值
deleteValueGroupread删除值分组
disableRuleread禁用规则
enableRuleread启用规则
getAllValuesread获取所有规则的值(注意:数据量可能很大,建议使用 getValueList 获取列表后再通过 getValue 获取具体值)
getCurrentTimestampread获取当前本地时间戳
getInterceptInforead获取URL的拦截信息(请求/响应皆以base64编码)
getRulesread获取所有规则&分组
getValueread根据名称获取单个值的完整信息(包含 data 字段)
getValueListread获取值列表(仅包含 index 和 name,不包含 data 字段,避免数据量过大)
getWhistleStatusread获取whistle服务器的当前状态
removeRuleFromGroupread将规则移出分组
removeValueFromGroupread将值移出分组
renameGroupread重命名分组
renameRuleread重命名规则
renameValueread重命名值
renameValueGroupread重命名值分组
replayRequestread在whistle中重放捕获的请求(本接口请求后不会直接返回结果, 需要使用getInterceptInfo接口获取结果)
setAllRulesStateread控制所有规则的启用状态(启用/禁用)
toggleHttp2read启用或禁用HTTP/2
toggleHttpInterceptionread启用或禁用HTTP拦截
toggleHttpsInterceptionread启用或禁用HTTPS拦截
toggleMultiRuleModeread启用或禁用多规则模式
toggleProxyread启用或禁用whistle代理
updateRuleread更新规则内容
updateValueread更新值内容
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
src/WhistleClient.ts:71
formData.append("key", `w-reactkey-${Math.floor(Math.random() * 1000)}`); // Generate a random key
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
fastmcp, minimist, @types/minimist, @types/node, tsx, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 827ea67b6e05full audit observations/trust-audit/mcp-server/7gugu__whistle.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08827ea67b6e05CAUTIONB89first audit
06

Questions

What is the Whistle MCP server?

A Whistle proxy management tool based on Model Context Protocol that allows AI assistants to directly control local Whistle proxy servers, simplifying network debugging, API testing, and proxy rule configuration through natural language interaction.

What tools does Whistle expose?

34 in total: 34 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Whistle safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Whistle need?

No credential environment variables were found in its source, so it appears to need none.

How does Whistle run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as whistle-mcp-tool at 1.2.0.

How current is this page?

The grade is for one exact copy of the source (827ea67b6e05), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement