WeChat Claude CodeBLOCK
WeChat Channel plugin for Claude Code — bidirectional messaging between WeChat and Claude Code via MCP protocol
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
微信 Channel 插件 for Claude Code —— 通过微信与 Claude Code 双向通信。
基于 `weixin-bot-plugin` 微信通信库,适配 Claude Code 的 Channel 功能实现。
English
功能
- 在微信中给 Claude Code 发消息,Claude 直接在终端中处理并回复到微信
- 支持文本、图片、语音、视频、文件等全媒体类型
- 微信扫码登录,零配置即用
- Claude 回复自动转为纯文本(微信不支持 Markdown)
- 权限转发:Claude Code 的工具调用审批(如 Bash、Write、Edit)会转发到微信,直接回复 yes/no 即可远程授权,无需守在终端前
前置要求
- Claude Code v2.1.80+
- Bun 运行时
- claude.ai 账号登录(不支持 API Key 认证)
安装
# 1. 添加插件源 /plugin marketplace add Dcatfly/claude-plugins # 2. 安装插件 /plugin install weixin-claude-code@dcatfly-plugins
使用
启动
claude --dangerously-load-development-channels plugin:weixin-claude-code@dcatfly-plugins
自定义 Channel 目前处于研究预览阶段,需要使用 --dangerously-load-development-channels 标志启动。首次登录
启动后 Claude 会提示你调用 login 工具,扫描二维码完成微信连接:
- Claude 调用 login 工具,展示二维码(如被折叠按
ctrl+o展开) - 用微信扫描二维码
- 在微信中确认登录
- 连接成功,开始收发消息
收发消息
连接成功后,你在微信中发送的消息会实时推送到 Claude Code 会话中。Claude 处理后通过 reply 工具将回复发回微信。
发送文本:直接在微信中输入文字
发送媒体:支持发送图片、语音、视频、文件,Claude 会下载并处理
接收回复:Claude 的回复会自动转为纯文本发送到微信
可用工具
登出
在 Claude Code 中调用 logout 工具即可断开微信连接并清除本地凭证。
工作原理
微信用户 微信服务器 iLink Bot API [本插件 MCP Server] Claude Code
插件作为 MCP Channel 服务器运行。微信通信由 `weixin-bot-plugin` 库处理(iLink Bot API long-poll 收消息、CDN 媒体加解密、SILK 语音转码等),本插件将收到的消息以 Channel notification 推送到 Claude Code 会话中。Claude 通过 reply 工具将回复发回微信。
局限性
- 仅接受登录者自己的消息 —— 其他人发的消息和群消息会被过滤,这是安全设计
- 不支持 Claude Code 原生命令 —— 微信消息是作为对话内容处理的,无法触发
/clear、/compact等 C
eb5dde9b2b9eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add weixin-claude-code -- npx -y [email protected]
{
"mcpServers": {
"weixin-claude-code": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
login | read | \u53D1\u8D77\u5FAE\u4FE1\u626B\u7801\u767B\u5F55\uFF0C\u8FD4\u56DE\u4E8C\u7EF4\u7801 URL |
logout | read | \u767B\u51FA\u5FAE\u4FE1\uFF0C\u6E05\u9664\u51ED\u8BC1\u5E76\u505C\u6B62\u6D88\u606F\u63A5\u6536 |
reply | read | \u56DE\u590D\u5FAE\u4FE1\u6D88\u606F |
status | read | \u67E5\u8BE2\u5F53\u524D\u5FAE\u4FE1\u8FDE\u63A5\u72B6\u6001 |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
if (k = new Function(...yb, zb)(...z2), p = Object.defineProperty(k, "name", { value: p }), k = b - 1, !g.hasOwnProperty(l))`), a = new Function(...h, e + `};
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);let { filePath: t, toUserId: n, opts: r, cdnBaseUrl: i, mediaType: o, label: c } = e, a = await nn.readFile(t), d = a.length, l = fe.createHash("md5").update(a).digest("hex"), g = at(d), u = fe.randomconst binaryString = atob(base64);
atob(data);
const parsedHeader = JSON.parse(atob(header));
atob(val);
@modelcontextprotocol/sdk, weixin-bot-plugin, @types/node, typescript
Gates applied: no_behavioural_pass.
eb5dde9b2b9efull audit observations/trust-audit/mcp-server/dcatfly__wechat-claude-code.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | eb5dde9b2b9e | BLOCK | D | 66 | first audit |
Questions
What is the WeChat Claude Code MCP server?
WeChat Channel plugin for Claude Code — bidirectional messaging between WeChat and Claude Code via MCP protocol
What tools does WeChat Claude Code expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is WeChat Claude Code safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does WeChat Claude Code need?
No credential environment variables were found in its source, so it appears to need none.
How does WeChat Claude Code run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as weixin-claude-code at 0.5.0.
How current is this page?
The grade is for one exact copy of the source (eb5dde9b2b9e), read on 2026-10-08. The repository is watched and re-audited when it changes.