Atlas / MCP servers / ditingdapeng / WeChat Official Accounts Scraper

WeChat Official Accounts ScraperCAUTION

mcp/ditingdapeng/wechat-official-accounts-scraper

微信公众号文章MCP工具

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
—
Stars
43
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://python.org) [](https://github.com/modelcontextprotocol) [](https://github.com/jlowin/fastmcp) [](LICENSE)

基于 FastMCP 框架构建的微信公众号文章爬虫系统,让AI智能体能够直接访问和分析微信公众号内容。通过MCP (Model Context Protocol) 标准协议,实现AI智能体与Selenium爬虫的无缝集成。

🎯 项目背景

在使用AI平台或智能体时,我们发现智能体无法直接访问微信公众号文章内容。为了解决这个问题,我们开发了这个基于MCP协议的爬虫服务,让AI智能体能够获取和分析微信公众号的内容。

✨ 核心特性

  • 🤖 FastMCP框架 - 基于FastMCP高级封装,简化MCP服务器开发
  • 🕷️ 智能爬虫 - 使用Selenium自动化浏览器,支持动态内容抓取
  • 🖼️ 图片处理 - 自动下载文章图片并转换为本地文件
  • 📊 内容分析 - 提供文章统计、关键词提取等分析功能
  • 🔌 标准协议 - 完全兼容MCP 1.0+规范,支持stdio通信
  • 🎯 AI集成 - 可与Claude Desktop、ChatGPT等AI智能体无缝集成
  • 💻 多种接口 - 提供Python API和交互式命令行界面

🏗️ 系统架构

graph TB
subgraph "AI智能体层"
A[Claude Desktop]
B[ChatGPT]
C[其他AI智能体]
end

subgraph "MCP协议层"
D[MCP客户端]
E[stdio通信]
F[MCP服务器FastMCP]
end

subgraph "爬虫引擎层"
G[Selenium WebDriver]
H[Chrome浏览器]
I[图片下载器]
end

subgraph "数据存储层"
J[JSON文件]
K[TXT文件]
L[图片文件]
end

A --> D
B --> D
C --> D
D  E
E  F
F --> G
G --> H
F --> I
G --> J
G --> K
I --> L

🔧 核心组件

1. FastMCP服务器 (server.py)

  • 基于FastMCP框架的高级封装
  • 提供3个核心工具:文章爬取、内容分析、统计信息
  • 单例模式管理Selenium爬虫实例
  • 完整的错误处理和参数验证

2. MCP标准客户端 (client.py)

  • 标准MCP协议客户端实现
  • 异步通信和会话管理
  • 交互式命令行界面
  • Python API接口

3. Selenium爬虫引擎 (weixin_spider_simple.py)

  • Chrome浏览器自动化控制
  • 反爬虫机制处理
  • 图片下载和格式转换
  • 多格式文件保存

🚀 快速开始

📋 环境要求

  • Python: 3.8+ (推荐 3.10+)
  • 浏览器: Chrome/Chromium (自动管理ChromeDriver)
  • 系统: macOS/Windows/Linux

📦 安装步骤

# 1. 克隆项目
git clone 
cd mcp-weixin

# 2. 安装依赖
pip install -r requirements.txt
`
Read from source at commit 46b5990bf49cOBSERVED · 2026-10-08
02

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_article_contentread
crawl_weixin_articleread
get_article_statisticsread
03

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (2 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/mcp_weixin_spider/__pycache__/__init__.cpython-310.pyc
__init__.cpython-310.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/mcp_weixin_spider/__pycache__/server.cpython-310.pyc
server.cpython-310.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
weixin_spider_simple.py:730
__import__(import_name)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
weixin_spider_simple.py:509
os.remove(temp_filepath)
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
weixin_spider_simple.py:70
'/usr/local/bin/chromedriver',
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
weixin_spider_simple.py:545
image_data = base64.b64decode(data)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, selenium, beautifulsoup4, requests, webdriver-manager, Pillow, lxml, aiofiles
Why it matters. 15 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 46b5990bf49cfull audit observations/trust-audit/mcp-server/ditingdapeng__wechat-official-accounts-scraper.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0846b5990bf49cCAUTIONB81first audit
05

Questions

What is the WeChat Official Accounts Scraper MCP server?

微信公众号文章MCP工具

What tools does WeChat Official Accounts Scraper expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is WeChat Official Accounts Scraper safe to connect to an agent?

With care. The audit graded it B (81/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does WeChat Official Accounts Scraper need?

No credential environment variables were found in its source, so it appears to need none.

How does WeChat Official Accounts Scraper run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (46b5990bf49c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement