Atlas / MCP servers / adamzhang1987 / Kingdee K3Cloud

Kingdee K3CloudCAUTION

mcp/adamzhang1987/kingdee-k3cloud-1

金蝶MCP Server(Kingdee K3Cloud MCP):让 Claude、Cursor 等 AI 助手通过自然语言查询和操作金蝶云星空 ERP。

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
15 10r · 4w · 1d
Transport
streamable-http
License
Apache-2.0
Stars
88
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

金蝶MCP 官网 | GitHub | PyPI

[](https://pypi.org/project/kingdee-k3cloud-mcp/) [](https://pypi.org/project/kingdee-k3cloud-mcp/) [](https://pypi.org/project/kingdee-k3cloud-mcp/) [](LICENSE) [](https://github.com/adamzhang1987/kingdee-k3cloud-mcp/actions/workflows/ci.yml)

金蝶MCP Server(Kingdee K3Cloud MCP)面向金蝶云星空 ERP,让 AI 助手(Claude Desktop、Claude Code、Cursor、Windsurf、Cline、Continue、Cherry Studio 等任意支持 MCP 协议的客户端)通过自然语言查询和操作金蝶 ERP 系统。标准 PyPI 包,pip install 或 uvx 均可直接运行,无需绑定特定包管理器。

提示:通过 Openclaw 等支持 MCP 的 Agent 平台接入后,可在其支持的 IM 渠道(如微信、Telegram)中用自然语言查库存、查单据,无需打开金蝶网页端。支持 Skill 机制的 AI Agent(Claude Code、Openclaw 等)还可配合 kingdee-k3cloud-skill 获得更佳体验——Skill 为 Agent 注入金蝶表单字段、常用查询模式和工作流知识,大幅减少试错次数,但并非必需,MCP Server 本身即可独立配合任意 MCP 客户端使用全部工具。
┌─────────────────────┐    ┌─────────────────────┐    ┌──────────────────┐
│  kingdee-k3cloud    │───▶│  kingdee-k3cloud    │───▶│  K3Cloud Web API │
│  -skill             │    │  -mcp               │    │  (金蝶云星空)     │
│  知识库 / 工作流     │    │  执行引擎 / MCP工具  │    │                  │
└─────────────────────┘    └─────────────────────┘    └──────────────────┘
支持 Skill 的 Agent          所有 MCP 客户端通用

MCP Server for Kingdee K3Cloud ERP. Connect AI assistants to your ERP system via the Model Context Protocol.

Read from source at commit a2519e889feeOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add kingdee-k3cloud-mcp --env MCP_API_KEY=${MCP_API_KEY} -- uvx kingdee-k3cloud-mcp
claude-desktop
{
  "mcpServers": {
    "kingdee-k3cloud-mcp": {
      "command": "uvx",
      "args": [
        "kingdee-k3cloud-mcp"
      ],
      "env": {
        "MCP_API_KEY": "${MCP_API_KEY}"
      }
    }
  }
}
03

Exposed tools (15)

10 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
audit_billread审核金蝶云星空单据。
count_billread估算某查询条件下的数据行数(不返回数据内容)。用于大数据量查询前的探测。
delete_billdestructive删除金蝶云星空单据。
execute_operationwrite执行金蝶云星空单据操作(禁用、反禁用等)。
push_billwrite下推金蝶云星空单据(如销售订单下推发货通知单)。
query_billread查询金蝶云星空单据数据(返回二维数组)。
query_bill_allread自动翻页查询直到拉完或达到 max_rows 安全上限。
query_bill_jsonread查询金蝶云星空单据数据(返回JSON格式,字段名作为key)。
query_bill_rangeread按日期自动切片 + 翻页,适合跨月/跨年查询。
query_bill_to_fileread自动翻页并流式写入本地文件,适合大数据量导出(万行以上)。
query_metadataread查询金蝶云星空表单的元数据(字段结构信息)。
save_billwrite保存金蝶云星空单据(新增或更新)。
submit_billwrite提交金蝶云星空单据。
unaudit_billread反审核金蝶云星空单据。
view_billread查看金蝶云星空单条记录的完整详情。
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:16
# MCP_ISSUER_URL=http://127.0.0.1:8000 # 与客户端连接地址一致(默认 http://localhost:8000)
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_bill
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.en.md:354
- **You need a long-running, production-grade AI agent**: `--mode readonly` provides a read-only boundary; credentials are checked at startup so misconfiguration shows up in the startup log rather tha
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/submissions/listings.md:39
• Read-only mode + startup credential check + actionable auth diagnostics
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha a2519e889feefull audit observations/trust-audit/mcp-server/adamzhang1987__kingdee-k3cloud-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a2519e889feeCAUTIONB89first audit
06

Questions

What is the Kingdee K3Cloud MCP server?

金蝶MCP Server(Kingdee K3Cloud MCP):让 Claude、Cursor 等 AI 助手通过自然语言查询和操作金蝶云星空 ERP。

What tools does Kingdee K3Cloud expose?

15 in total: 10 read-only, 4 that write, and 1 that can delete or overwrite (delete_bill). Every one is listed on this page with its risk.

Is Kingdee K3Cloud safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Kingdee K3Cloud need?

It reads MCP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kingdee K3Cloud run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as kingdee-k3cloud-mcp.

How current is this page?

The grade is for one exact copy of the source (a2519e889fee), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement