Atlas / MCP servers / chenningling / RedBook Search Comment

RedBook Search CommentSAFE

mcp/chenningling/redbook-search-comment

这是一款基于 Playwright 开发的小红书自动搜索和评论工具,作为 MCP Server,可通过特定配置接入 MCP Client,帮助用户自动完成登录小红书、搜索关键词、获取笔记内容及发布智能评论等操作。

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 5r · 1w · 0d
Transport
stdio
License
—
Stars
44
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

本项目基于 JonaFly/RednoteMCP 并结合我自己的使用经验,进行优化和改进(by windsurf)。在此向原作者表示衷心的感谢!

这是一款基于 Playwright 开发的小红书自动搜索和评论工具,作为 MCP Server,可通过特定配置接入 MCP Client(如Claude for Desktop),帮助用户自动完成登录小红书、搜索关键词、获取笔记内容及发布智能评论等操作。

注:Redbook-Search-Comment-MCP2.0已经发布!直接点击前往使用即可!

2.0主要优化内容如下:

  • 优化了搜索笔记时,标题不显示的问题
  • 新增了多类获取笔记的方法,确保能完整获取笔记内容
  • 重构了评论功能,利用MCP客户端(如Claude)的AI能力生成更自然的评论
  • 将功能模块化,分为笔记分析、评论生成和评论发布三个独立模块

一、功能特点

  • 自动登录:支持手动扫码登录方式,首次登录成功后会保存登录状态,后续使用无需重复扫码。
  • 关键词搜索:能依据用户输入的关键词搜索小红书笔记,并可指定返回结果的数量。
  • 笔记内容获取:输入笔记的 URL,即可获取该笔记的详细内容。
  • 笔记评论获取:通过笔记 URL 获取相应笔记的评论信息。
  • 智能评论发布:支持多种评论类型,包括引流(引导用户关注或私聊)、点赞(简单互动获取好感)、咨询(以问题形式增加互动)、专业(展示专业知识建立权威),可根据需求选择发布。

二、安装步骤

  1. Python 环境准备:确保系统已安装 Python 3.8 或更高版本。若未安装,可从 Python 官方网站下载并安装。
  1. 项目获取:将本项目克隆或下载到本地。
  1. 创建虚拟环境:在项目目录下创建并激活虚拟环境(推荐):
# 创建虚拟环境
python3 -m venv venv

# 激活虚拟环境
# Windows
venv\Scripts\activate
# macOS/Linux
source venv/bin/activate
  1. 安装依赖:在激活的虚拟环境中安装所需依赖:
pip install -r requirements.txt
pip install fastmcp
  1. 安装浏览器:安装Playwright所需的浏览器:
playwright install

三、MCP Server 配置

在 MCP Client(如Claude for Desktop)的配置文件中添加以下内容,将本工具配置为 MCP Server:

{
"mcpServers": {
"xiaohongshu MCP": {
"command": "/绝对路径/到/venv/bin/python3",
"args": [
"/绝对路径/到/xiaohongshu_mcp.py",
"--stdio"
]
}
}
}
重要提示: - 请使用虚拟环境中Python解释器的完整绝对路径 - 例如:/Users/username/Desktop/RedBook-Search-Comment-MCP/venv/bin/python3 - 同样,xiaohongshu_mcp.py也需要使用完整绝对路径

四、使用方法

(一)启动服务器

  1. 直接运行:在项目目录下,激活虚拟环境后执行:
python3 xiaohongshu_mcp.py
  1. 通过 MCP Client 启动:配置好MCP Client后,按照客户端的操作流程进行启动和连接。

(二)主要功能操作

在MCP Client(如Claude for Desktop)中连接到服务器后,可以使用以下功能:

Read from source at commit 2edabf63f378OBSERVED · 2026-10-08
02

Exposed tools (6)

5 read · 1 write · 0 destructive.

ToolRiskDescription
get_note_commentsread获取笔记评论
get_note_contentread获取笔记内容
helloread返回一个简单的问候
loginread登录小红书账号
post_smart_commentwrite根据帖子内容发布智能评论,增加曝光并引导用户关注或私聊
search_notesread根据关键词搜索笔记
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
playwright, pytest-playwright, pandas, numpy, mcp, fastapi, uvicorn
Why it matters. 7 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
AI-learn-resource/README.md:453
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
AI-learn-resource/MCP-About.txt:448
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 2edabf63f378full audit observations/trust-audit/mcp-server/chenningling__redbook-search-comment.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082edabf63f378SAFEB89first audit
05

Questions

What is the RedBook Search Comment MCP server?

这是一款基于 Playwright 开发的小红书自动搜索和评论工具,作为 MCP Server,可通过特定配置接入 MCP Client,帮助用户自动完成登录小红书、搜索关键词、获取笔记内容及发布智能评论等操作。

What tools does RedBook Search Comment expose?

6 in total: 5 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is RedBook Search Comment safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does RedBook Search Comment need?

No credential environment variables were found in its source, so it appears to need none.

How does RedBook Search Comment run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (2edabf63f378), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement