Atlas / MCP servers / henryhaoson / Yuque

YuqueSAFE

mcp/henryhaoson/yuque

Yuque mcp server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
14 11r · 2w · 1d
Transport
sse · stdio
License
—
Stars
69
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@HenryHaoson/Yuque-MCP-Server)

English Version

一个用于与语雀 API 集成的 Model-Context-Protocol (MCP) 服务器。此实现受 Figma-Context-MCP 的启发,并使用 语雀开放 API。

概述

该服务器提供了与语雀知识库平台交互的 MCP 工具,允许 AI 模型:

  • 获取用户和文档信息
  • 创建、读取、更新和删除文档
  • 搜索语雀中的内容
  • 获取知识库信息
  • 获取统计数据和分析信息

安装

安装 via Smithery

要使用 Smithery 将 Yuque MCP Server 自动安装到 Claude 桌面端:

npx -y @smithery/cli install @HenryHaoson/Yuque-MCP-Server --client claude

前提条件

  • Node.js 18+ (推荐)
  • 拥有 API 令牌的语雀账号

设置

  1. 克隆此仓库:
git clone https://github.com/Henryhaoson/Yueque-MCP-Server.git
cd Yueque-MCP-Server
  1. 安装依赖:
npm install
  1. 基于 .env.example 创建 .env 文件:
cp .env.example .env
  1. (可选) 在 .env 文件中添加你的语雀 API 令牌:
YUQUE_API_TOKEN=your_yuque_api_token_here

你也可以选择在连接到服务器时通过查询参数提供令牌,而不是在 .env 文件中设置。

使用方法

运行服务器

开发模式

# HTTP 服务器模式
npm run dev

# CLI stdio 模式
npm run dev:cli

生产模式

首先,构建项目:

npm run build

然后在 HTTP 或 CLI 模式下运行:

# HTTP 服务器模式
npm run start

# CLI stdio 模式
npm run start:cli

使用 Docker 部署

本项目提供了 Docker 支持,使您可以轻松地容器化和部署服务器。

使用 Docker Compose(推荐)

  1. 构建并启动容器:
docker-compose up -d
  1. 查看日志:
docker-compose logs -f
  1. 停止服务:
docker-compose down
Read from source at commit bd161bcc7506OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add yueque-mcp-server --env YUQUE_API_TOKEN=${YUQUE_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "yueque-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "YUQUE_API_TOKEN": "${YUQUE_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (14)

11 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_docwrite在指定知识库中创建新的语雀文档,支持多种格式内容
delete_docdestructive从语雀知识库中删除指定文档,此操作不可撤销
get_current_userread获取当前认证用户的信息,包括用户ID、用户名、头像等语雀账号基本信息
get_docread获取语雀中特定文档的详细内容,包括正文、修改历史和权限信息(支持分块处理大型文档)
get_doc_chunks_inforead获取文档的分块元信息,包括总块数、每块的字符数等
get_group_book_statisticsread获取团队知识库的统计数据,包括各知识库的文档数、字数、阅读量等
get_group_doc_statisticsread获取团队文档的统计数据,包括各文档的字数、阅读量、评论量等
get_group_member_statisticsread获取团队成员的统计数据,包括各成员的编辑次数、阅读量、点赞量等
get_group_statisticsread获取团队的汇总统计数据,包括成员人数、文档数量、阅读量和互动数据等
get_repo_docsread获取特定知识库中的所有文档列表,包括文档标题、更新时间等信息
get_user_docsread获取当前用户的所有知识库文档列表,包括私人和协作文档
get_user_reposread获取指定用户的知识库列表,知识库是语雀中组织文档的集合
searchread在语雀平台中搜索文档或知识库内容,支持范围和作者筛选
update_docwrite更新语雀中已存在的文档,可以修改标题、内容或权限设置
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_doc
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.docker.example
.env.docker.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/content-type, axios, content-type, cors, cross-env, dotenv, express
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha bd161bcc7506full audit observations/trust-audit/mcp-server/henryhaoson__yuque.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07bd161bcc7506SAFEB89first audit
06

Questions

What is the Yuque MCP server?

Yuque mcp server

What tools does Yuque expose?

14 in total: 11 read-only, 2 that write, and 1 that can delete or overwrite (delete_doc). Every one is listed on this page with its risk.

Is Yuque safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Yuque need?

It reads YUQUE_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Yuque run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as yueque-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (bd161bcc7506), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement