Kingdee K3CloudCAUTION
金蝶MCP Server(Kingdee K3Cloud MCP):让 Claude、Cursor 等 AI 助手通过自然语言查询和操作金蝶云星空 ERP。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
[](https://pypi.org/project/kingdee-k3cloud-mcp/) [](https://pypi.org/project/kingdee-k3cloud-mcp/) [](https://pypi.org/project/kingdee-k3cloud-mcp/) [](LICENSE) [](https://github.com/adamzhang1987/kingdee-k3cloud-mcp/actions/workflows/ci.yml)
金蝶MCP Server(Kingdee K3Cloud MCP)面向金蝶云星空 ERP,让 AI 助手(Claude Desktop、Claude Code、Cursor、Windsurf、Cline、Continue、Cherry Studio 等任意支持 MCP 协议的客户端)通过自然语言查询和操作金蝶 ERP 系统。标准 PyPI 包,pip install 或 uvx 均可直接运行,无需绑定特定包管理器。
提示:通过 Openclaw 等支持 MCP 的 Agent 平台接入后,可在其支持的 IM 渠道(如微信、Telegram)中用自然语言查库存、查单据,无需打开金蝶网页端。支持 Skill 机制的 AI Agent(Claude Code、Openclaw 等)还可配合 kingdee-k3cloud-skill 获得更佳体验——Skill 为 Agent 注入金蝶表单字段、常用查询模式和工作流知识,大幅减少试错次数,但并非必需,MCP Server 本身即可独立配合任意 MCP 客户端使用全部工具。
┌─────────────────────┐ ┌─────────────────────┐ ┌──────────────────┐ │ kingdee-k3cloud │───▶│ kingdee-k3cloud │───▶│ K3Cloud Web API │ │ -skill │ │ -mcp │ │ (金蝶云星空) │ │ 知识库 / 工作流 │ │ 执行引擎 / MCP工具 │ │ │ └─────────────────────┘ └─────────────────────┘ └──────────────────┘ 支持 Skill 的 Agent 所有 MCP 客户端通用
MCP Server for Kingdee K3Cloud ERP. Connect AI assistants to your ERP system via the Model Context Protocol.
a2519e889feeOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add kingdee-k3cloud-mcp --env MCP_API_KEY=${MCP_API_KEY} -- uvx kingdee-k3cloud-mcp{
"mcpServers": {
"kingdee-k3cloud-mcp": {
"command": "uvx",
"args": [
"kingdee-k3cloud-mcp"
],
"env": {
"MCP_API_KEY": "${MCP_API_KEY}"
}
}
}
}Exposed tools (15)
10 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
audit_bill | read | 审核金蝶云星空单据。 |
count_bill | read | 估算某查询条件下的数据行数(不返回数据内容)。用于大数据量查询前的探测。 |
delete_bill | destructive | 删除金蝶云星空单据。 |
execute_operation | write | 执行金蝶云星空单据操作(禁用、反禁用等)。 |
push_bill | write | 下推金蝶云星空单据(如销售订单下推发货通知单)。 |
query_bill | read | 查询金蝶云星空单据数据(返回二维数组)。 |
query_bill_all | read | 自动翻页查询直到拉完或达到 max_rows 安全上限。 |
query_bill_json | read | 查询金蝶云星空单据数据(返回JSON格式,字段名作为key)。 |
query_bill_range | read | 按日期自动切片 + 翻页,适合跨月/跨年查询。 |
query_bill_to_file | read | 自动翻页并流式写入本地文件,适合大数据量导出(万行以上)。 |
query_metadata | read | 查询金蝶云星空表单的元数据(字段结构信息)。 |
save_bill | write | 保存金蝶云星空单据(新增或更新)。 |
submit_bill | write | 提交金蝶云星空单据。 |
unaudit_bill | read | 反审核金蝶云星空单据。 |
view_bill | read | 查看金蝶云星空单条记录的完整详情。 |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
# MCP_ISSUER_URL=http://127.0.0.1:8000 # 与客户端连接地址一致(默认 http://localhost:8000)
delete_bill
.pre-commit-config.yaml
- **You need a long-running, production-grade AI agent**: `--mode readonly` provides a read-only boundary; credentials are checked at startup so misconfiguration shows up in the startup log rather tha
• Read-only mode + startup credential check + actionable auth diagnostics
Gates applied: no_behavioural_pass.
a2519e889feefull audit observations/trust-audit/mcp-server/adamzhang1987__kingdee-k3cloud-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a2519e889fee | CAUTION | B | 89 | first audit |
Questions
What is the Kingdee K3Cloud MCP server?
金蝶MCP Server(Kingdee K3Cloud MCP):让 Claude、Cursor 等 AI 助手通过自然语言查询和操作金蝶云星空 ERP。
What tools does Kingdee K3Cloud expose?
15 in total: 10 read-only, 4 that write, and 1 that can delete or overwrite (delete_bill). Every one is listed on this page with its risk.
Is Kingdee K3Cloud safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Kingdee K3Cloud need?
It reads MCP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Kingdee K3Cloud run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as kingdee-k3cloud-mcp.
How current is this page?
The grade is for one exact copy of the source (a2519e889fee), read on 2026-10-08. The repository is watched and re-audited when it changes.