Atlas / MCP servers / aliyun / Yunxiao DevOps

Yunxiao DevOpsCAUTION

mcp/aliyun/yunxiao-devops

Yunxiao MCP Server provides AI assistants with the ability to interact with the Yunxiao platform. It provides a set of tools that interact with Yunxiao's API, allowing AI assistants to manage Codeup repository, Project, Pipeline, Packages etc.

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
200 116r · 84w · 14d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
175
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

AlibabaCloud Devops MCP Server provides AI assistants with the ability to interact with the Yunxiao platform, enabling them to read work item contents in projects, automatically write code after understanding requirements, and submit code merge requests. Enterprise development teams can use it to assist with code reviews, optimize task management, reduce repetitive operations, and thus focus on more important innovation and product delivery.

Features

alibabacloud-devops-mcp-server provides the following capabilities for AI assistants:

  • organization-management: Organization management tools (organization list, organization details, department information, organizational roles, member information, etc.)
  • code-management: Code repository management tools (repository management, branch management, merge request management, file tree, etc.)
  • project-management: Project management tools (project management, work item management, work item fields, work item comments, time tracking, etc.)
  • pipeline-management: Pipeline management tools (pipeline list, pipeline configuration, resource management, tag management, deployment management, etc.)
  • application-delivery: Application delivery tools (deployment order management, application management, application tags, variable group management, etc.)
  • packages-management: Artifact repository management tools (artifact repositories, artifact lists, etc.)
  • test-management: Test management tools (test case management, test case directories, test plans, test results, etc.)

Usage

Region Edition Support

This tool supports both Yunxiao central station and Region edition deployment modes:

  • Central Station: Uses https://openapi-rdc.aliyuncs.com as the API domain
  • Region Edition: Uses organization-specific domains, such as `https://your-org.devops.a
Read from source at commit c8316cc7a151OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add alibabacloud-devops-mcp-server --env MCP_AUTH_CHECK=${MCP_AUTH_CHECK} --env YUNXIAO_ACCESS_TOKEN=${YUNXIAO_ACCESS_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "alibabacloud-devops-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MCP_AUTH_CHECK": "${MCP_AUTH_CHECK}",
        "YUNXIAO_ACCESS_TOKEN": "${YUNXIAO_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (200)

116 read · 84 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
Kubernetes发布read部署到Kubernetes集群
add_host_list_to_deploy_groupwrite[application delivery] Add host list to deploy group
add_host_list_to_host_groupwrite[application delivery] Add host list to host group
cancel_app_release_stage_executionread[application delivery] 取消发布流程阶段执行
cancel_appstack_change_requestread[application delivery] Cancel a change request
close_appstack_change_requestread[application delivery] Close a change request
compareread[Code Management] Query code to compare content
create_app_orchestrationwrite[application delivery] Create an application orchestration
create_app_tagwrite[application delivery] Create an application tag
create_applicationwrite[application delivery] Create a new application
create_appstack_change_requestwrite[application delivery] Create a change request
create_branchwrite[Code Management] Create a new branch in a Codeup repository
create_change_orderwrite[application delivery] 创建部署单
create_change_requestwrite[Code Management] Create a new change request (merge request). Supports specifying source/target branches, reviewers, associated work items, and optional AI review trigger.
create_commit_commentwrite[Code Management] Create a comment on a commit
create_effort_recordwrite[Project Management] 登记实际工时。云效中实际工时(fieldId 101587)为受控字段,不能通过 update_work_item 的 customFieldValues 修改,必须调用本工具。
create_estimated_effortwrite[Project Management] 登记预计工时。云效中预计工时(fieldId 101586)为受控字段,不能通过 update_work_item 的 customFieldValues 修改,必须调用本工具。
create_filewrite[Code Management] Create a new file in a Codeup repository
create_flow_variable_groupwrite[Pipeline Management] Create an organization-level variable group for Flow (pipeline).
create_global_varwrite[application delivery] Create a global variable group
create_pipeline_from_descriptionwrite[Pipeline Management] Create a pipeline from structured parameters.\n\n
create_pipeline_runwrite[Pipeline Management] Run a pipeline.\n\n
create_repositorywrite[Code Management] Create a new Codeup repository.\n
create_resource_memberwrite[Resource Member Management] Create a resource member
create_sprintwrite[Project Management] Create a new sprint
create_system_release_workflowwrite[application delivery] 创建系统发布流程
create_tagwrite[Tag Management] Create a tag
create_tag_groupwrite[Tag Management] Create a tag group
create_test_plan_testcase_commentwrite[test management] 创建测试计划中测试用例的评论,支持回复(通过parentId)。与用例库中的用例评论不同,这里是测试计划上下文
create_testcasewrite[test management] 创建测试用例
create_testcase_commentwrite[test management] 创建测试用例评论,支持回复(通过parentId)
create_testcase_directorywrite[test management] 创建测试用例目录
create_variable_groupwrite[application delivery] Create a variable group
create_versionwrite[Project Management] Create a new version in a Yunxiao Project. Versions are used to manage release plans and track delivery progress.\n\nUse Cases:\n\nCreate a new release version\nPlan project milestones\nSet version owners and dates
create_work_itemwrite[Project Management] Create a work item. \n描述字段使用提示:\n- description 支持 Markdown / 富文本,需配合 formatType(\
create_work_item_commentwrite[Project Management] Create a comment for a specific work item
create_workitem_relation_recordwrite[Project Management] Relate one work item to another. Use ASSOCIATED for a normal related item without a parent-child hierarchy.
create_workitem_testcase_relationwrite[Project Management] Relate a test case to a work item. Returns the created relation record id.
delete_app_orchestrationdestructive[application delivery] Delete an application orchestration
delete_branchdestructive[Code Management] Delete a branch from a Codeup repository
delete_filedestructive[Code Management] Delete a file from a Codeup repository
delete_flow_variable_groupdestructive[Pipeline Management] Delete a Flow (pipeline) variable group by numeric id.
delete_resource_memberdestructive[Resource Member Management] Delete a resource member
delete_tagdestructive[Tag Management] Delete a tag
delete_tag_groupdestructive[Tag Management] Delete a tag group
delete_testcasedestructive[test management] 删除测试用例
delete_variable_groupdestructive[application delivery] Delete a variable group
delete_versiondestructive[Project Management] Delete a version from a Yunxiao Project.\n\nUse Cases:\n\nRemove obsolete versions\nClean up project versions
delete_work_itemdestructive[Project Management] Delete a work item. This operation is irreversible.
delete_workitem_relation_recorddestructive[Project Management] Delete a relation between two work items without deleting either work item.
delete_workitem_testcase_relationdestructive[Project Management] Remove a test case relation from a work item by relationRecordId (obtained from list_workitem_testcase_relations).
execute_app_release_stagewrite[application delivery] 执行变更请求的发布流程阶段
execute_job_actionwrite[application delivery] 操作环境部署单
execute_pipeline_job_actionwrite[Pipeline Management] Execute a subsequent action of a pipeline job.
execute_pipeline_job_runwrite[Pipeline Management] Manually run a pipeline task. Start a specific job in a pipeline run instance.
execute_system_release_stagewrite[application delivery] 执行系统发布流程阶段
find_task_operation_logread[application delivery] 查询部署任务执行日志,其中通常包含下游部署引擎的调度细节信息
generate_pipeline_yamlread[Pipeline Management] Generate the pipeline YAML without creating the pipeline — a dry run of
get_app_orchestrationread[application delivery] Get an application orchestration
get_app_release_stage_job_logread[application delivery] 查询研发阶段流水线任务运行日志
get_app_release_stage_pipeline_runwrite[application delivery] 获取研发阶段流水线运行实例
get_app_release_workflow_stageread[application delivery] 获取发布流程阶段详情
get_app_variable_groupsread[application delivery] Get variable groups for an application
get_app_variable_groups_revisionread[application delivery] Get the revision of variable groups for an application
get_applicationread[application delivery] Get application details by name
get_appstack_change_request_audit_itemsread[application delivery] Get audit items for a change request
get_artifactread[Packages Management] Get information about a single artifact in a package repository
get_branchread[Code Management] Get information about a branch in a Codeup repository
get_change_orderwrite[application delivery] 读取部署单使用的物料和工单状态
get_change_requestread[Code Management] Get detailed information about a specific change request (merge request) by its local ID.
get_commitwrite[Code Management] Get information about a commit
get_current_organization_inforeadGet information about the current user and organization based on the token. In the absence of an explicitly specified organization ID, this result will take precedence.
get_current_userreadGet information about the current user based on the token. In the absence of an explicitly specified user ID, this result will take precedence.
get_env_variable_groupsread[application delivery] Get variable groups for an environment
get_file_blobsread[Code Management] Get file content from a Codeup repository
get_flow_variable_groupread[Pipeline Management] Get a Flow (pipeline) variable group by numeric id.
get_global_varread[application delivery] Get a global variable group
get_latest_orchestrationread[application delivery] Get the latest orchestration for an environment
get_latest_pipeline_runwrite[Pipeline Management] Get information about the latest pipeline run
get_machine_deploy_logwrite[application delivery] Get machine deployment log
get_organization_department_ancestorsreadGet the ancestors of a department in an organization
get_organization_department_inforeadGet information about a department in an organization
get_organization_member_inforeadGet information about a member in an organization
get_organization_member_info_by_user_idreadGet information about a member in an organization by user ID
get_organization_roleread[Organization Management] Get information about an organization role
get_pipelineread[Pipeline Management] Get details of a specific pipeline in an organization
get_pipeline_job_run_logwrite[Pipeline Management] Get the execution logs of a pipeline job. Retrieve the log content for a specific job in a pipeline run.
get_pipeline_job_step_logread[Pipeline Management] Get the log content for a specific step of a pipeline job. Use GetPipelineJobSteps first to get stepIndex and buildId.
get_pipeline_job_step_log_urlread[Pipeline Management] Get the download URL for a pipeline job step log. Use GetPipelineJobSteps first to get stepIndex and buildId.
get_pipeline_job_stepsread[Pipeline Management] Get the list of steps for a pipeline job. Returns step details including stepIndex and buildId needed for log retrieval.
get_pipeline_runwrite[Pipeline Management] Get details of a specific pipeline run instance
get_projectread[Project Management] Get information about a Yunxiao project
get_repositoryread[Code Management] Get information about a Codeup repository
get_sprintread[Project Management] Get information about a sprint
get_tag_groupread[Tag Management] Get a tag group
get_test_plan_progressread[test management] 获取测试计划用例执行进度统计(通过/失败/延后/待执行)
get_test_result_listread[test management] 获取测试计划中测试用例列表
get_testcaseread[test management] 获取测试用例信息
get_testcase_field_configread[test management] 获取测试用例字段配置
get_user_organizationsreadGet the list of organizations the current user belongs to
get_variable_groupread[application delivery] Get a variable group
get_vm_deploy_machine_logwrite[VM Deploy Order Management] Get VM deploy machine log
get_vm_deploy_orderwrite[VM Deploy Order Management] Get VM deploy order details
get_work_itemread[Project Management] Get information about a work item
get_work_item_typeread[Project Management] Get details of a specific work item type
get_work_item_type_field_configread[Project Management] Get field configuration for a specific work item type
get_work_item_typesread[Project Management] Get the list of work item types for a project
get_work_item_workflowread[Project Management] Get workflow information for a specific work item type
get_workitem_fileread[Project Management] Get file information for a specific work item. Supports both file IDs (long hex for description-embedded images) and attachment IDs (numeric like 62487031). Returns file details including name, size, suffix, and a temporary download URL.
list_all_work_item_typesread[Project Management] List all work item types in an organization
list_app_orchestrationread[application delivery] List application orchestrations
list_app_release_stage_briefsread[application delivery] 查询发布流程阶段摘要列表
list_app_release_stage_metadataread[application delivery] 查询研发阶段执行记录集成变更信息
list_app_release_stage_runsread[application delivery] 查询发布流程阶段执行记录列表
list_app_release_workflow_briefsread[application delivery] 查询应用下所有发布流程摘要
list_app_release_workflowsread[application delivery] 查询应用下所有发布流程
list_application_sourcesread[application delivery] List application sources with pagination
list_applicationsread[application delivery] List applications in an organization with pagination
list_appstack_change_request_executionsread[application delivery] List change request executions
list_appstack_change_request_work_itemsread[application delivery] List work items for a change request
list_appstack_change_requestsread[application delivery] Search change requests in an application with pagination and filtering
list_artifactsread[Packages Management] List artifacts in a package repository with filtering options
list_attached_change_requestsread[application delivery] List change requests attached to a release
list_branchesread[Code Management] List branches in a Codeup repository
list_change_order_job_logswrite[application delivery] 查询环境部署单日志
list_change_order_versionswrite[application delivery] 查看部署单版本列表
list_change_orders_by_originread[application delivery] 根据创建来源查询部署单
list_change_request_commentsread[Code Management] List comments on a change request. Supports filtering by comment type (GLOBAL_COMMENT or INLINE_COMMENT), state (OPENED or DRAFT), resolved status, and file path (for inline comments).
list_change_request_patch_setswrite[Code Management] List patch sets (versions) for a change request. Patch sets represent different versions of the merge request as it evolves.
list_change_requestsread[Code Management] List change requests with multi-condition filtering, pagination and sorting. Supports filtering by repository, author, reviewer, state (opened/merged/closed), search keywords, and creation time range.
list_commitsread[Code Management] List commits in a Codeup repository
list_current_user_effort_recordsread[Project Management] 获取用户的实际工时明细,结束时间和开始时间的间隔不能大于6个月
list_effort_recordsread[Project Management] 获取实际工时明细
list_estimated_effortsread[Project Management] 获取预计工时明细
list_filesread[Code Management] List file tree from a Codeup repository
list_flow_variable_groupsread[Pipeline Management] List organization-level Flow (pipeline) variable groups with pagination.
list_global_varsread[application delivery] List global variable groups
list_organization_departmentsreadGet the list of departments in an organization
list_organization_membersreadlist user members in an organization
list_organization_rolesread[Organization Management] List organization roles
list_package_repositoriesread[Packages Management] List package repositories in an organization with filtering options
list_pipeline_job_historysread[Pipeline Management] Get the execution history of a pipeline task. Retrieve all execution records for a specific task in a pipeline.
list_pipeline_jobs_by_categoryread[Pipeline Management] Get pipeline execution tasks by category. Currently only supports DEPLOY category.
list_pipeline_runswrite[Pipeline Management] Get a list of pipeline run instances with filtering options
list_pipelinesread[Pipeline Management] Get a list of pipelines in an organization with filtering options
list_program_versionswrite[Project Management] List versions for a Yunxiao Program (Project Set). Versions are used to manage release plans and track delivery progress.\n\nUse Cases:\n\nList all versions in a program\nFilter versions by status (TODO, DOING, ARCHIVED)\nSearch versions by name
list_repositoriesread[Code Management] Get the CodeUp Repository List.\n
list_resource_membersread[Resource Member Management] Get a list of resource members
list_service_connectionsread[Service Connection Management] List service connections in an organization with filtering options
list_sprintsread[Project Management] List sprints in a project
list_system_release_workflowsread[application delivery] 查询系统下所有发布流程
list_tag_groupsread[Tag Management] Get a list of tag groups
list_test_plan_result_directoriesread[test management] 获取测试计划结果目录列表,按用例库分组返回目录树及每个目录下的用例数量
list_test_plan_testcase_commentsread[test management] 获取测试计划中测试用例的评论列表(与用例库中的用例评论不同,这里是测试计划上下文)
list_test_plansread[test management] 获取测试计划列表,支持分页及按项目、迭代、状态、名称筛选
list_test_repo_tagsread[test management] 获取测试用例库标签列表,支持分页与按名称关键词过滤
list_test_reposread[test management] 获取用例库列表,支持分页与按名称模糊筛选
list_testcase_commentsread[test management] 获取测试用例评论列表
list_testcase_directoriesread[test management] 获取测试用例目录列表
list_versionsread[Project Management] List versions for a Yunxiao Project or Program. Versions are used to manage release plans and track delivery progress.\n\nUse Cases:\n\nList all versions in a project\nFilter versions by status (TODO, DOING, ARCHIVED)\nSearch versions by name
list_work_item_commentsread[Project Management] List comments for a specific work item
list_work_item_relation_work_item_typesread[Project Management] List work item types that can be related to a specific work item
list_work_item_typesread[Project Management] List work item types in a project space
list_workitem_activitiesread[Project Management] List activity history for a specific work item. Returns changes including field updates, status transitions, association changes, and attachment changes, with operator and timestamp details.
list_workitem_attachmentsread[Project Management] List attachments for a specific work item. Returns attachment information including file name, size, suffix, download URL, and creator/modifier details.
list_workitem_relation_recordsread[Project Management] List relation records of the requested relation type for a work item.
list_workitem_testcase_relationsread[Project Management] List test cases related to a work item. Returns relation records including relationRecordId (used for deletion), testcaseId, subject and owner.
merge_change_requestwrite[Code Management] Merge a change request (merge request) using a specific merge type (ff-only / no-fast-forward / squash / rebase), with an optional merge message and optional source-branch deletion. This rewrites the target branch and is not reversible.
pass_app_release_stage_validateread[application delivery] 通过发布流程阶段验证
pass_pipeline_validateread[Pipeline Management] Approve/pass a manual checkpoint (human validation gate) in a pipeline run.
refuse_app_release_stage_validateread[application delivery] 拒绝发布流程阶段验证
refuse_pipeline_validateread[Pipeline Management] Refuse/reject a manual checkpoint (human validation gate) in a pipeline run.
rerun_pipeline_job_runwrite[Pipeline Management] Rerun a pipeline job. Only deploy-type jobs are supported. You can set a job as deploy type in its configuration.
resume_vm_deploy_orderwrite[VM Deploy Order Management] Resume VM deploy order
retry_app_release_stage_pipelineread[application delivery] 重试变更请求的发布流程阶段流水线
retry_pipeline_job_runwrite[Pipeline Management] Retry a failed pipeline job run.
retry_vm_deploy_machinewrite[VM Deploy Order Management] Retry VM deploy machine
review_change_requestwrite[Code Management] Review a change request (merge request): submit a PASS / NOT_PASS opinion, optionally with a comment, and optionally submit pending draft comments at the same time.
search_app_tagsread[application delivery] Search application tags
search_app_templatesread[application delivery] Search application templates
search_organization_membersread[Organization Management] Search for organization members
search_programswrite[Project Management] Search for Yunxiao Program (Project Set) List. A Program is a collection of multiple related projects, used for unified management and coordination of large projects.\n\nUse Cases:\n\nQuery programs by name\nQuery programs by status\nQuery programs by creator
search_projectsread[Project Management] Search for Yunxiao Project List. A Project is a project management unit that includes work items and sprints, and it is different from a code repository (Repository).\n\nUse Cases:\n\nQuery projects I am involved in\nQuery projects I have created
search_testcasesread[test management] 搜索测试用例。分页有上限:page * perPage 不能超过 10000,超出会返回 400,需要更多结果时用 directoryId 或 conditions 缩小范围
search_workitemsread[Project Management] Search work items with various filter conditions. Paging is capped: page * perPage must not exceed 10000, otherwise the API returns 400 — narrow the filters to reach more results
skip_app_release_stage_pipelineread[application delivery] 跳过变更请求的发布流程阶段流水线
skip_pipeline_job_runwrite[Pipeline Management] Skip a pipeline job run.
skip_vm_deploy_machinewrite[VM Deploy Order Management] Skip VM deploy machine
smart_list_pipelinesread[Pipeline Management] Intelligently search pipelines with natural language time references (e.g.,
stop_pipeline_job_rundestructive[Pipeline Management] Stop/terminate a running pipeline job.
stop_vm_deploy_orderwrite[VM Deploy Order Management] Stop VM deploy order
update_app_orchestrationwrite[application delivery] Update an application orchestration. This is a full replacement — include all existing spec fields (componentList, labels, placeholderList, groupNameMap) to avoid data loss. Call get_app_orchestration first to retrieve the current state.
update_app_release_stagewrite[application delivery] 更新应用发布流程阶段
update_app_tagwrite[application delivery] Update an application tag
update_app_tag_bindwrite[application delivery] Update application tag bindings
update_applicationwrite[application delivery] Update an existing application
update_change_requestwrite[Code Management] Update an existing change request (merge request) title and/or description. At least one field is required.
update_change_request_commentwrite[Code Management] Update a comment on a change request. Can update the comment content and/or resolved status.
update_effort_recordwrite[Project Management] 更新已登记的实际工时(云效实际工时受控字段,不能走 update_work_item.customFieldValues)。
update_estimated_effortwrite[Project Management] 更新已登记的预计工时(云效预计工时受控字段,不能走 update_work_item.customFieldValues)。
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (11 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

MEDIUMInventory / provenance · inv.binary · CWE-1104
skills/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
debug-both.sh:40
sse_code=$(curl -s -o /dev/null -w "%{http_code}" "http://127.0.0.1:$PORT/sse" 2>/dev/null || echo "000")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
debug-both.sh:41
mcp_code=$(curl -s -o /dev/null -w "%{http_code}" -X OPTIONS "http://127.0.0.1:$PORT${MCP_PATH}" 2>/dev/null || echo "000")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
debug-both.sh:44
echo "  SSE:        http://127.0.0.1:$PORT/sse"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
debug-both.sh:45
echo "  Streamable: http://127.0.0.1:$PORT${MCP_PATH}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
debug-sse.sh:37
if curl -s -o /dev/null -w "%{http_code}" "http://127.0.0.1:$PORT/sse" 2>/dev/null | grep -q "200"; then
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_app_orchestration, delete_branch, delete_file, delete_flow_variable_group, delete_resource_member, delete_tag, delete_tag_group, delete_testcase, delete_variable_group, delete_version, delete_w
Why it matters. 14 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
skills/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
operations/appstack/appOrchestrations.ts:2
import { yunxiaoRequest, buildUrl, isRegionEdition } from '../../common/utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
operations/appstack/appTags.ts:2
import { yunxiaoRequest, buildUrl, isRegionEdition } from '../../common/utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
operations/appstack/appTemplates.ts:2
import { yunxiaoRequest, buildUrl, isRegionEdition } from '../../common/utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
operations/appstack/applications.ts:2
import { yunxiaoRequest, buildUrl, isRegionEdition } from '../../common/utils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
operations/appstack/applications.ts:4
import { YunxiaoError } from '../../common/errors.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, express, pino, universal-user-agent, zod, zod-to-json-schema, @types/express
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
IFLOW.md:122
4. Later requests must send `Mcp-Session-Id` (and protocol headers per MCP); the server routes each session to its stored Yunxiao credentials.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c8316cc7a151full audit observations/trust-audit/mcp-server/aliyun__yunxiao-devops.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c8316cc7a151CAUTIONB85first audit
06

Questions

What is the Yunxiao DevOps MCP server?

Yunxiao MCP Server provides AI assistants with the ability to interact with the Yunxiao platform. It provides a set of tools that interact with Yunxiao's API, allowing AI assistants to manage Codeup repository, Project, Pipeline, Packages etc.

What tools does Yunxiao DevOps expose?

200 in total: 116 read-only, 84 that write, and 14 that can delete or overwrite (delete_app_orchestration, delete_branch, delete_file, delete_flow_variable_group, delete_resource_member). Every one is listed on this page with its risk.

Is Yunxiao DevOps safe to connect to an agent?

With care. The audit graded it B (85/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Yunxiao DevOps need?

It reads MCP_AUTH_CHECK and YUNXIAO_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Yunxiao DevOps run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as alibabacloud-devops-mcp-server at 0.3.64.

How current is this page?

The grade is for one exact copy of the source (c8316cc7a151), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement