Atlas / MCP servers / brhiza / Mingyu

MingyuBLOCK

mcp/brhiza/mingyu

八字、紫微、星盘、六爻、梅花、奇门、大六壬、小六壬、塔罗、雷诺曼、灵签、择日一站式玄学算命占卜工具包,输出结构化提示词与数据。提供公开 API、MCP Server 与 skill。

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
145 145r · 0w · 0d
Transport
sse · stdio · streamable-http
License
AGPL-3.0
Stars
470
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

命语是一套免费开源的在线算命、占卜排盘与 AI 解读提示词工具。输入出生时间或所问之事,即可完成高精度排盘,并生成可直接交给任意大模型解读的完整提示词。

⚡ 一键接入(Agent 技能 & 在线 MCP)

  • Agent Skill(推荐 · 免配置一句话安装):
npx skills add Brhiza/mingyu --skill mingyu -g -y
  • Skill 安装不会自动注册 MCP 服务。需要连接 MCP 时,如果客户端能启动本地进程,优先单独配置 npx -y mingyu-mcp stdio;默认 full,请求在本机处理,不占用 Cloudflare Pages Functions 配额。
  • 在线 Remote MCP(本地进程不可用或需要远程免安装时):
  • 在支持 Remote MCP 的客户端添加 Streamable HTTP 类型的 Server URL:https://aov.cc/mcp
  • QQ 交流群:命语 Mingyu 技术交流群(1080947018)

📿 功德箱

命语与时月东方均为个人业余维护的免费开源项目。

为什么叫“功德箱”? 本项目收到的全部赞助款项目前均定期全额捐赠给社会正规慈善与公益事业(用于爱心助学、困境老人救助与乡村公益等)。感谢每一位支持者的善意!

👉 前往功德箱(赞助与爱心支持)

🌐 在线使用 · 📖 新手教程 · 📚 完整文档 · 🔌 OpenAPI · 📦 mingyu-core (npm)

🔮 支持功能

Read from source at commit 31a242c2a486OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mingyu-mcp --env AI_API_KEY=${AI_API_KEY} --env MODEL_API_KEY=${MODEL_API_KEY} --env MODEL_MAX_TOKENS=${MODEL_MAX_TOKENS} --env MODEL_REASONING_MAX_TOKENS=${MODEL_REASONING_MAX_TOKENS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mingyu-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AI_API_KEY": "${AI_API_KEY}",
        "MODEL_API_KEY": "${MODEL_API_KEY}",
        "MODEL_MAX_TOKENS": "${MODEL_MAX_TOKENS}",
        "MODEL_REASONING_MAX_TOKENS": "${MODEL_REASONING_MAX_TOKENS}"
      }
    }
  }
}
03

Exposed tools (145)

145 read · 0 write · 0 destructive.

ToolRiskDescription
almanac_promptread
astrolabe_promptread
astrolabe_synastryread
astrolabe_synastry_promptread
bazhai_promptread
bazi_calculateread
bazi_compatibilityread
bazi_compatibility_promptread
bazi_promptread
bazi_ziwei_promptread
calendar_astronomical_timeread
calendar_bazi_reverseread
calendar_moon_phaseread
calendar_solar_illuminationread
calendar_solar_termread
calendar_true_solar_birthread
calendar_true_solar_timeread
character_analyzeread
character_selectread
classics_yilin_queryread
divine_almanacread
divine_astrolaberead
divine_jinkoujueread
divine_kongmingread
divine_lenormandread
divine_liurenread
divine_liuyaoread
divine_meihuaread
divine_qimenread
divine_qimen_lifetimeread
divine_ssgwread
divine_tarotread
divine_xiaoliurenread
divine_zhugeread
foundation_capabilitiesread
foundation_directionread
foundation_ganzhiread
foundation_shensharead
foundation_wuxingread
huangji_jingshi_promptread
huangji_reference_tablesread
instant_chartread
jinkoujue_promptread
lenormand_promptread
liuren_promptread
liuyao_promptread
meihua_promptread
metaphysics_bazhairead
metaphysics_huangji_jingshiread
metaphysics_qizhengread
metaphysics_residentialread
metaphysics_taiyiread
metaphysics_wuyun_liuqiread
metaphysics_xuankongread
metaphysics_zodiacread
name_analyzeread
name_analyze_promptread
name_generateread
name_generate_promptread
number_analyzeread
number_energy_promptread
qimen_lifetime_promptread
qimen_promptread
qizheng_promptread
residential_promptread
ssgw_promptread
taiyi_promptread
tarot_promptread
thematic_consultation_promptread
wuyun_liuqi_promptread
xiaoliuren_promptread
xuankong_promptread
ziwei_calculateread
ziwei_compatibilityread
ziwei_compatibility_promptread
ziwei_promptread
zodiac_promptread
丁壬化木格read丁壬合化木,月令亥卯未或寅卯辰木旺之地,天干丁壬同透,丁壬不重出争合妒合破局。化气纯粹则贵,喜水木生扶,忌金克木破化。
七脉轮牌阵read按七个脉轮位置观察身心状态与能量侧重。
万能牌阵read从现状、阻力、可用资源、行动与趋势观察通用问题。
丑午相害read争进官非,性情急躁
丑未相冲read湿燥相激,多主田宅资产或脾胃变动
丙辛化水格read丙辛合化水,月令申子辰或亥子丑水旺之地,天干丙辛同透,丙辛不重出争合妒合破局。化气纯粹则贵,喜金水生扶,忌土克水破化。
乙庚化金格read乙庚合化金,月令巳酉丑或申酉戌金旺之地,天干乙庚同透,乙庚不重出争合妒合破局。化气纯粹则贵,喜土金生扶,忌火克金破化。
事业牌阵read从现状、优势、挑战、机会、行动与结果观察事业议题。
井栏叉格read庚日地支申子辰全,取水局暗冲寅午戌中财官印。忌丙丁巳午填实破局。
亥亥自刑read欲望过溢,多生迷惘纠结
从革格read庚辛日见申酉戌三会金局。金气纯粹,忌火来克金,喜土金相助。
倒冲格read丙日见午多或丁日见巳多,火势极旺,反冲子水为官。忌壬癸亥子填实,喜火旺助冲。主异路功名。
六乙鼠贵格read乙日见丙子时,为六乙鼠贵的基本结构;须避午冲、丑绊、卯刑,并避申庚、酉辛显露破格。月令另有财官印可取时,仍应先按正常格局论。
六芒星牌阵read以内外因素与显隐力量交叉观察复杂问题。
六阴朝阳格read辛日见戊子时,取子位一阳来复。忌午冲子,忌丙丁火出干填实。
关系牌阵read对照双方的状态、需求与互动模式,观察关系走向。
凯尔特十字read从背景、阻碍、环境、态度与结果多层观察复杂问题。
十二宫牌阵read按十二个生活领域展开全景观察,适合周期性综合复盘。
午午自刑read性情急躁,多生心火燥烈
单牌指引read以一张牌给出当前问题的核心线索,适合快速聚焦当下状态。
卯午相破read木火旺极,劳碌心力
卯辰相害read长幼失和,事多掣肘
卯酉相冲read金木相伤,门户变动、情思纠葛
印比相生read人脉/资源相互支撑
四元素牌阵read从行动、情感、思考和现实基础四个层面检视问题。
圣三角牌阵read从问题根源、当前状况与发展结果快速把握一件事的主线。
壬骑龙背格read壬辰日生,地支多辰,取辰多冲戌中官星。忌戌字填实冲破。
子午双包格read四柱须同时见子、午,并构成两子包一午、两午包一子或两子两午;只有两个子或只有两个午均不成格,须按上述支数结构成立。
子午相冲read水火相战,多主心肾不安、动荡奔波
子未相害read骨肉生隙,事多羁绊
子酉相破read金沉水底,做事有头无尾
官杀生印read官杀与印绶同见,具备官印或杀印相生的结构线索
寅亥相破read生中有破,好中有损
寅巳相害read恩中有怨,进退两难
寅申相冲read金木交加,驿马道路奔波、骨骼筋腱注意
巳亥相冲read水火冲突,文书破耗或远行变动
巳申相破read合中带破,吉凶参半
年运牌阵read按年度阶段与主题位置观察一整年的重点变化。
建禄格read月支为日干禄位,如甲日寅月、戊日巳月、己日午月。成败仍须结合财官食伤及全局制化核对。
戊癸化火格read戊癸合化火,月令寅午戌或巳午未火旺之地,天干戊癸同透,戊癸不重出争合妒合破局。化气纯粹则贵,喜木火生扶,忌水克火破化。
日德格read甲寅、丙辰、戊辰、庚辰、壬戌五日生人。日德入命,传统多取象为性格敦厚宽仁。
日贵格read日贵只有丁酉、丁亥、癸巳、癸卯四日。古籍另分昼夜:癸卯、丁亥宜日生,癸巳、丁酉宜夜生;昼夜取法还需结合出生时刻,刑冲破害等影响需结合全盘核对。
时间流牌阵read按过去、现在、未来梳理事件脉络,适合观察趋势推进。
曲直格read甲乙日以亥卯未局全,或春生寅卯辰全而无间断破坏立曲直;采用《神峰通考》所引《格解》的严格口径核庚辛透藏,并按张楠按语核局外支直接冲破。水木顺势、火可泄秀,土财按实际作用另论。
未戌相破read燥土相凌,刑伤破败
比劫泄秀read比劫同党与食伤承接,可能靠技能/表达输出
润下格read壬癸日见亥子丑三会水局或申子辰三合水局,水势泛滥。忌土来制水,喜木泄水为用。
炎上格read丙丁日见巳午未三会火局。火势炎上,忌水来破局,喜木火相助。
爱情牌阵read从双方状态、关系现状、建议与走向观察亲密关系。
甲己化土格read甲己合化土,月令辰戌丑未土旺之地,天干甲己同透,甲己不重出争合妒合破局。化气纯粹则贵,喜火土生扶,忌木克土破化。
申亥相害read争嫉破耗,先好后疑
福德秀气格read福德秀气专取乙、丁、己、辛、癸五阴干,日支坐巳、酉、丑之一,并须四柱会齐巳酉丑金局;各日干的成败与喜忌,仍按对应原局与岁运核定。
稼穑格read戊己日见辰戌丑未全局。土性厚重,忌木来克土,喜火土相助。
财富牌阵read检视当前财务状态、收入机会、潜在风险与改善路径。
财生官杀read财富可带来地位/权力
身心灵牌阵read检视个人在思想、情感和精神层面的状态,找到内在平衡与和谐。
辰丑相破read泥土相杂,破耗不宁
辰戌相冲read魁罡相冲,官非权柄或住所迁变
辰辰自刑read思虑过重,多生沉郁自扰之感
选择牌阵read比较两个选择的条件与走向,适合需要权衡取舍的问题。
酉戌相害read嫉妒相伤,多生口舌
酉酉自刑read刚愎过重,自伤和气
金神格read甲日生,时柱为乙丑、己巳或癸酉,构成金神格的基本结构。古籍以火制金神为成格关键,明言喜火乡、惧水乡,原局与岁运的火水制化决定成败。
问题解决牌阵read拆解问题的表象、根源、阻力、突破口与行动结果。
阳刃格read甲羊刃在卯,丙戊羊刃在午,庚羊刃在酉,壬羊刃在子。阴干不论阳刃。羊刃帮身有力,但需官杀制伏方为贵。
飞天禄马格read庚子日地支多子,暗冲午中丁火为官、己土为印。忌丑绊、午冲及丁己填实。
食伤生财read才华/技能可转化为财富
马蹄铁牌阵read对特定问题提供一个全面的概述,涵盖过去、现在、未来、建议和最终结果等七个方面。
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (9 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
src/workers/ziwei-payload.worker.ts
ziwei-payload.worker.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
android/app/src/main/java/cc/aov/mingyu/AndroidDirectAiPlugin.java:354
"metadata.google.internal".equals(host) ||
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/lib/ai/android-custom-ai.ts:42
const BLOCKED_HOSTS = new Set(['localhost', 'metadata', 'metadata.google.internal']);
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/lib/ai/proxy.ts:24
const BLOCKED_CUSTOM_AI_HOSTS = new Set(['localhost', 'metadata', 'metadata.google.internal']);
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMInventory / provenance · inv.binary · CWE-1104
android/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/verify-docker-runtime.mjs:11
const origin = `http://127.0.0.1:${port}`;
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
mcp/src/catalog/tool-catalog.ts:157
description: '计算儒略日、近似 UT1、ΔT 与近似 TT 证据',
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
mcp/src/tools/calendar.ts:222
'将当地钟表时间和固定偏移或IANA历史时区换算为UTC、JD(UTC)、近似UT1、ΔT与近似TT,并返回时区诊断、计算链、反证和精度限制',
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
packages/core/src/calendar/astronomical-time.ts:23
stage: '时区解析' | 'UTC换算' | 'UTC儒略日' | 'UT1近似' | 'ΔT与TT';
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
packages/core/src/calendar/astronomical-time.ts:45
type: 'UT1近似' | 'ΔT模型等级';
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
packages/core/src/calendar/astronomical-time.ts:51
limitation: '反证事实只记录 UT1≈UTC 与 ΔT 分段模型的近似或外推状态;不得据模型等级生成可信度百分比或宣称达到观测精度';
LOWInventory / provenance · inv.hidden_file · CWE-1104
.dev.vars.example
.dev.vars.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
tests/ziwei-display-payload.test.ts
ziwei-display-payload.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
tests/ziwei-payload-cancellation.test.ts
ziwei-payload-cancellation.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
functions/.well-known/[[path]].ts:1
import { getPublicApiManifestForRequest } from '../../src/lib/public-api/metadata';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
functions/api/v1/[[path]].ts:1
import { handlePublicApiRequest, normalizeApiPath } from '../../../src/lib/public-api/handler';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
functions/api/v1/[[path]].ts:2
import type { AiEnv } from '../../../src/lib/ai/proxy';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
functions/api/v1/[[path]].ts:3
import { AI_CLIENT_ADDRESS_HEADER } from '../../../src/lib/ai/rate-limit';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp/src/create-server.ts:40
import packageJson from '../../package.json';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/ai-config.test.ts:318
'https://169.254.169.254/latest',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/ai-config.test.ts:323
'https://metadata.google.internal/v1',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/ai-config.test.ts:314
'https://127.0.0.1:11434/v1',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/ai-config.test.ts:315
'https://10.0.0.2/v1',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/ai-config.test.ts:316
'https://172.16.0.2/v1',

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 31a242c2a486full audit observations/trust-audit/mcp-server/brhiza__mingyu.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0631a242c2a486BLOCKD69first audit
06

Questions

What is the Mingyu MCP server?

八字、紫微、星盘、六爻、梅花、奇门、大六壬、小六壬、塔罗、雷诺曼、灵签、择日一站式玄学算命占卜工具包,输出结构化提示词与数据。提供公开 API、MCP Server 与 skill。

What tools does Mingyu expose?

145 in total: 145 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mingyu safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Mingyu need?

It reads AI_API_KEY, MODEL_API_KEY, MODEL_MAX_TOKENS, MODEL_REASONING_MAX_TOKENS and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mingyu run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mingyu-mcp at 0.4.0.

How current is this page?

The grade is for one exact copy of the source (31a242c2a486), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement