XiaozhiSAFE
小智MCP合集
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A powerful interface for extending AI capabilities through remote control, calculations, email operations, knowledge search, and more.
一个强大的接口,用于通过远程控制、计算、邮件操作、知识搜索等方式扩展AI能力。
Overview | 概述
MCP (Model Context Protocol) is a protocol that allows servers to expose tools that can be invoked by language models. Tools enable models to interact with external systems, such as querying databases, calling APIs, or performing computations. Each tool is uniquely identified by a name and includes metadata describing its schema.
MCP(模型上下文协议)是一个允许服务器向语言模型暴露可调用工具的协议。这些工具使模型能够与外部系统交互,例如查询数据库、调用API或执行计算。每个工具都由一个唯一的名称标识,并包含描述其模式的元数据。
Tools | 工具集
- conversation_dingtalk: Send conversation to dingtalk | 将会话内容发送到钉钉群机器人
- email_qq: Send email with qq mail account | 使用QQ邮箱发送邮件
- system: Get server status | 获取服务器状态监控信息包含 CPU、内存、磁盘等使用情况
- web_webpilot: Web search by WebPilot | 通过 WebPilot 实现联网搜索
Features | 特性
- 🔌 Bidirectional communication between AI and external tools | AI与外部工具之间的双向通信
- 🔄 Automatic reconnection with exponential backoff | 具有指数退避的自动重连机制
- 📊 Real-time data streaming | 实时数据流传输
- 🛠️ Easy-to-use tool creation interface | 简单易用的工具创建接口
- 🔒 Secure WebSocket communication | 安全的WebSocket通信
Quick Start | 快速开始
- Install dependencies | 安装依赖:
python3 -m venv venv source venv/bin/activate pip3 install -r requirements.txt
- Set up environment variables | 设置环境变量:
# Copy the .env.example file to your own configuration file, e.g., .env.xiaozhi1 # 参考 .env.example 文件,复制到你自己的配置文件例如 .env.xiaozhi1
- Run the example | 运行示例:
# You can run different XiaoZhi MCP access points through different configuration files # 可以通过不同的配置文件,来运行到不同的多个小智MCP接入点 python mcp_pipe.py aggregate.py --env-file .env.xiaozhi1
Creating Your Own MCP Tools | 创建自己的MCP工具
Here's a simple example of creating an MCP tool | 以下是一个创建MCP工具的简单示例:
- According to the example in the tools folder, create your own tool | 根据
f442e84e3521OBSERVED · 2026-10-08Exposed tools (5)
3 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_server_status | read | |
read_webpage | read | |
send_conversation_to_dingtalk | write | |
send_email | write | |
web_search | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
python-dotenv, websockets, mcp, pydantic, requests, psutil
Gates applied: no_behavioural_pass, no_license.
f442e84e3521full audit observations/trust-audit/mcp-server/avxxoo__xiaozhi.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f442e84e3521 | SAFE | B | 89 | first audit |
Questions
What is the Xiaozhi MCP server?
小智MCP合集
What tools does Xiaozhi expose?
5 in total: 3 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Xiaozhi safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Xiaozhi need?
It reads EMAIL_AUTHCODE and WEB_WEBPILOT_APIKEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Xiaozhi run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (f442e84e3521), read on 2026-10-08. The repository is watched and re-audited when it changes.