Atlas / MCP servers / dcatfly / WeChat Claude Code

WeChat Claude CodeBLOCK

mcp/dcatfly/wechat-claude-code

WeChat Channel plugin for Claude Code — bidirectional messaging between WeChat and Claude Code via MCP protocol

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
4 4r · 0w · 0d
Transport
stdio
License
MIT
Stars
56
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

微信 Channel 插件 for Claude Code —— 通过微信与 Claude Code 双向通信。

基于 `weixin-bot-plugin` 微信通信库,适配 Claude Code 的 Channel 功能实现。

English

功能

  • 在微信中给 Claude Code 发消息,Claude 直接在终端中处理并回复到微信
  • 支持文本、图片、语音、视频、文件等全媒体类型
  • 微信扫码登录,零配置即用
  • Claude 回复自动转为纯文本(微信不支持 Markdown)
  • 权限转发:Claude Code 的工具调用审批(如 Bash、Write、Edit)会转发到微信,直接回复 yes/no 即可远程授权,无需守在终端前

前置要求

  • Claude Code v2.1.80+
  • Bun 运行时
  • claude.ai 账号登录(不支持 API Key 认证)

安装

# 1. 添加插件源
/plugin marketplace add Dcatfly/claude-plugins

# 2. 安装插件
/plugin install weixin-claude-code@dcatfly-plugins

使用

启动

claude --dangerously-load-development-channels plugin:weixin-claude-code@dcatfly-plugins
自定义 Channel 目前处于研究预览阶段,需要使用 --dangerously-load-development-channels 标志启动。

首次登录

启动后 Claude 会提示你调用 login 工具,扫描二维码完成微信连接:

  1. Claude 调用 login 工具,展示二维码(如被折叠按 ctrl+o 展开)
  2. 用微信扫描二维码
  3. 在微信中确认登录
  4. 连接成功,开始收发消息

收发消息

连接成功后,你在微信中发送的消息会实时推送到 Claude Code 会话中。Claude 处理后通过 reply 工具将回复发回微信。

发送文本:直接在微信中输入文字

发送媒体:支持发送图片、语音、视频、文件,Claude 会下载并处理

接收回复:Claude 的回复会自动转为纯文本发送到微信

可用工具

登出

在 Claude Code 中调用 logout 工具即可断开微信连接并清除本地凭证。

工作原理

微信用户  微信服务器  iLink Bot API  [本插件 MCP Server]  Claude Code

插件作为 MCP Channel 服务器运行。微信通信由 `weixin-bot-plugin` 库处理(iLink Bot API long-poll 收消息、CDN 媒体加解密、SILK 语音转码等),本插件将收到的消息以 Channel notification 推送到 Claude Code 会话中。Claude 通过 reply 工具将回复发回微信。

局限性

  • 仅接受登录者自己的消息 —— 其他人发的消息和群消息会被过滤,这是安全设计
  • 不支持 Claude Code 原生命令 —— 微信消息是作为对话内容处理的,无法触发 /clear、/compact 等 C
Read from source at commit eb5dde9b2b9eOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add weixin-claude-code -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "weixin-claude-code": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
loginread\u53D1\u8D77\u5FAE\u4FE1\u626B\u7801\u767B\u5F55\uFF0C\u8FD4\u56DE\u4E8C\u7EF4\u7801 URL
logoutread\u767B\u51FA\u5FAE\u4FE1\uFF0C\u6E05\u9664\u51ED\u8BC1\u5E76\u505C\u6B62\u6D88\u606F\u63A5\u6536
replyread\u56DE\u590D\u5FAE\u4FE1\u6D88\u606F
statusread\u67E5\u8BE2\u5F53\u524D\u5FAE\u4FE1\u8FDE\u63A5\u72B6\u6001
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dist/index.js:692
if (k = new Function(...yb, zb)(...z2), p = Object.defineProperty(k, "name", { value: p }), k = b - 1, !g.hasOwnProperty(l))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dist/index.js:811
`), a = new Function(...h, e + `};
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dist/index.js:4760
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
dist/index.js:23415
let { filePath: t, toUserId: n, opts: r, cdnBaseUrl: i, mediaType: o, label: c } = e, a = await nn.readFile(t), d = a.length, l = fe.createHash("md5").update(a).digest("hex"), g = at(d), u = fe.random
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
dist/index.js:9622
const binaryString = atob(base64);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
dist/index.js:10958
atob(data);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
dist/index.js:11015
const parsedHeader = JSON.parse(atob(header));
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
dist/index.js:22209
atob(val);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, weixin-bot-plugin, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha eb5dde9b2b9efull audit observations/trust-audit/mcp-server/dcatfly__wechat-claude-code.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08eb5dde9b2b9eBLOCKD66first audit
06

Questions

What is the WeChat Claude Code MCP server?

WeChat Channel plugin for Claude Code — bidirectional messaging between WeChat and Claude Code via MCP protocol

What tools does WeChat Claude Code expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is WeChat Claude Code safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does WeChat Claude Code need?

No credential environment variables were found in its source, so it appears to need none.

How does WeChat Claude Code run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as weixin-claude-code at 0.5.0.

How current is this page?

The grade is for one exact copy of the source (eb5dde9b2b9e), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement