LanhuBLOCK
⚡ 需求分析效率提升 200%!全球首个为 AI 编程时代设计的团队协作 MCP 服务器,自动分析需求自动编写前后端代码,下载切图
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
让所有 AI 助手共享团队知识,打破 AI IDE 孤岛
lanhumcp | 蓝湖mcp | lanhu-mcp | 蓝湖AI助手 | 蓝湖skills | Lanhu AI Integration
[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://modelcontextprotocol.io/) [](https://github.com/jlowin/fastmcp) [](CONTRIBUTING.md) [](https://github.com/dsphper/lanhu-mcp/stargazers) [](https://github.com/dsphper/lanhu-mcp/issues) [](https://github.com/dsphper/lanhu-mcp/releases) [](CODEOFCONDUCT.md)
English | 简体中文
快速开始 • 功能特性 • 使用文档 • 贡献指南
🌟 项目亮点
一个面向蓝湖设计交付与需求阅读的 Model Context Protocol (MCP) 服务器。由 MCP 提供来源数据和资源,大模型结合画面理解并适配目标工程。
v1.8.3:Windows 一键安装进入真实 CI 发布门禁。 版本说明 · 设计工作流 · 维护流程
🔥 核心创新:
- 📋 需求分析支持:提取 Axure 页面、文字与注释,提供开发、测试、探索视角;业务结论由 AI 与使用者核对。
- 💬 团队知识库:打破 AI IDE 孤岛,让所有 AI 助手共享知识库和上下文
- 🎨 UI设计支持:自动下载设计稿,智能提取切图,语义化命名;设计图分析可获取尺寸/间距/颜色/字体等精确参数,并得到转换后的 HTML+CSS 代码参考
- ⚡ 性能优化:基于版本号的智能缓存,增量更新,并发处理
🎯 适用场景:
- ✅ Cursor + 蓝湖:让 Cursor AI 直接读取蓝湖需求文档和设计稿
- ✅ Windsurf + 蓝湖:Windsurf Cascade AI 直接读取蓝湖需求文档和设计稿
- ✅ Claude Code + 蓝湖:Claude AI 直接读取蓝湖需求文档和设计稿
- ✅ OpenClaw + 蓝湖:OpenClaw 原生支持读取蓝湖需求文档和设计稿
- ✅ ClawBot + 蓝湖:Cl
9fd213c64a21OBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add lanhu-mcp-server --env LANHU_MCP_AUTH_TOKEN=${LANHU_MCP_AUTH_TOKEN} -- uvx lanhu-mcp-server{
"mcpServers": {
"lanhu-mcp-server": {
"command": "uvx",
"args": [
"lanhu-mcp-server"
],
"env": {
"LANHU_MCP_AUTH_TOKEN": "${LANHU_MCP_AUTH_TOKEN}"
}
}
}
}Exposed tools (9)
6 read · 1 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
lanhu_export_design_assets | read | Download original design assets, verify pixels/hash and deliver a portable ZIP + manifest. |
lanhu_get_design_overview | read | Prepare an immutable UI design snapshot and return an image plus a paginated node index. |
lanhu_get_members | read | |
lanhu_inspect_design_region | destructive | Return a clear crop with stable node labels, source ancestors/styles and associated asset IDs. |
lanhu_resolve_invite_link | read | |
lanhu_say_delete | destructive | |
lanhu_say_detail | read | |
lanhu_say_edit | write | |
lanhu_say_list | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
echo " Ubuntu: sudo apt install python3 python3-venv python3-pip"
system use found in code, not declared in the description
lanhu_inspect_design_region, lanhu_say_delete
install_bundle(_bundle(extra=(link, b"../../elsewhere")), tmp_path / "frontend")
return base64.b64decode(blob, validate=True)
payload = b"".join(base64.b64decode(item.blob) for item in resource)
assert base64.b64decode(preview[0].blob).startswith(b"\x89PNG")
chunks = ["中", "😀", "👩💻", "\n", "e\u0301", "文"]
fastmcp, httpx, beautifulsoup4, playwright, lxml, python-dotenv, htmlmin2, pillow
Gates applied: no_behavioural_pass.
9fd213c64a21full audit observations/trust-audit/mcp-server/dsphper__lanhu.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 9fd213c64a21 | BLOCK | D | 69 | source changed, verdict held |
| 2026-09-19 | eb0a79ca27f3 | BLOCK | D | 69 | first audit |
Questions
What is the Lanhu MCP server?
⚡ 需求分析效率提升 200%!全球首个为 AI 编程时代设计的团队协作 MCP 服务器,自动分析需求自动编写前后端代码,下载切图
What tools does Lanhu expose?
9 in total: 6 read-only, 1 that write, and 2 that can delete or overwrite (lanhu_inspect_design_region, lanhu_say_delete). Every one is listed on this page with its risk.
Is Lanhu safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Lanhu need?
It reads LANHU_MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Lanhu run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as lanhu-mcp-server.
How current is this page?
The grade is for one exact copy of the source (9fd213c64a21), read on 2026-09-23. The repository is watched and re-audited when it changes.