Atlas / MCP servers / javen-yan / MiOT

MiOTSAFE

mcp/javen-yan/miot

基于 MijiaAPI 的米家设备智能控制代理,提供标准化的 MCP 服务,支持动态设备发现、属性读写和动作调用

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
26 16r · 8w · 2d
Transport
stdio
License
MIT
Stars
70
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

中文文档 | English

一个基于 mijiaAPI 3.x 的产品化米家 MCP 服务。它不再要求客户端先理解 did、siid/piid/aiid 这些协议细节,而是优先面向“家庭、房间、设备名、场景名”提供更自然的查询和控制能力。

这版解决什么问题

  • 面向 AI 客户端:优先暴露稳定、清晰的产品级工具,而不是底层协议字段
  • 面向真实家庭场景:先看家庭与房间,再定位设备,再执行控制
  • 面向 MCP 标准:工具返回结构化结果,服务状态和登录状态可直接被客户端消费
  • 面向扩展:标准能力 schema、profile 驱动控制、资源模型可以继续演进

当前能力

服务与登录

  • get_service_status
  • prepare_login
  • reconnect_service
  • clear_saved_login
  • refresh_devices
  • get_tool_catalog
  • ping

家庭与设备

  • get_home_overview
  • list_homes
  • list_devices
  • get_device
  • get_device_status
  • get_device_capabilities

设备控制

  • control_by_intent
  • control_device
  • turn_on_device
  • turn_off_device
  • set_brightness
  • set_color_temperature
  • set_target_temperature
  • set_hvac_mode
  • set_fan_speed
  • set_cover_position

场景与耗材

  • list_scenes
  • execute_scene
  • get_consumable_items

MCP 资源

  • mijia://service
  • mijia://homes
  • mijia://devices
  • mijia://scenes
  • mijia://capabilities
  • mijia://tooling

安装

建议使用 Python 3.10+。

poetry install

如果你不用 Poetry:

pip install -r requirements.txt

启动

poetry run python mcp_server/mcp_server.py

测试握手:

poetry run python mcp_server/mcp_test.py

登录方式

mijiaAPI 3.x 已移除账号密码登录,只支持二维码登录。

首次需要登录时,服务会:

  • 生成浏览器页:~/.miot-mcp/qr.html
  • 同时生成二维码图片:~/.miot-mcp/qr.png
  • 默认优先用系统浏览器打开 qr.html
  • 只有浏览器打不开时,才回退到图片查看器或终端二维码

认证信息会保存到:

~/.miot-mcp/auth_data.json

推荐登录主路径

  1. 调用 prepare_login
  2. 调用 get_service_status
  3. 读取 service.qr.page_path 或 service.qr.image_path
  4. 完成扫码后调用 reconnect_service 或直接 refresh_devices

登录相关状态

get_service_status 和 mijia://service 都会返回结构化登录状态,重点字段包括:

  • service.connected
  • service.has_saved_login
  • service.qr.open_mode
  • service.qr.page_path
  • service.qr.image_path
  • service.qr.login_url
  • assistant_summary
  • next_steps.should_scan_qr

环境变量

export MIJIA_ENABLE_QR="tr
Read from source at commit 67015f774b20OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add miot-mcp --env MIJIA_PASSWORD=${MIJIA_PASSWORD} -- uvx miot-mcp
claude-desktop
{
  "mcpServers": {
    "miot-mcp": {
      "command": "uvx",
      "args": [
        "miot-mcp"
      ],
      "env": {
        "MIJIA_PASSWORD": "${MIJIA_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (26)

16 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
clear_saved_logindestructiveClear saved login credentials so the next connection triggers QR login.
control_by_intentreadRoute a natural-language-like smart-home request to the best product tool.
control_devicewriteControl a device through capability operations like turn_on, set_brightness, set_target_temperature, or run_action.
execute_scenewriteExecute a scene by friendly name or scene id.
get_consumable_itemsreadGet consumable items globally or for a specific home.
get_devicereadResolve one device and return its summary, capabilities, and common state.
get_device_capabilitiesreadResolve one device and return its standard capability schema for stable client-side routing.
get_device_statusreadReturn the current state and recommended next actions for one device.
get_home_overviewreadReturn a room-first overview of homes and devices for everyday browsing.
get_service_statusreadReturn service status, authentication status, and local file locations.
get_tool_catalogreadReturn the recommended everyday tools, advanced tools, and workflow.
list_devicesreadList devices by friendly filters like name, room, home, or model.
list_homesreadList all homes and rooms in a user-friendly structure.
list_scenesreadList scenes globally or within a specific home.
pingreadTest server connectivity.
prepare_logindestructivePrepare QR login artifacts and optionally force a fresh QR login flow.
reconnect_servicereadReconnect to Mijia cloud, optionally clearing saved login first.
refresh_devicesreadRefresh homes, devices, and room mappings from Mijia cloud.
set_brightnesswriteSet device brightness.
set_color_temperaturewriteSet device color temperature.
set_cover_positionwriteSet position for any cover-capable device such as a curtain or blind.
set_fan_speedwriteSet fan speed on any fan-speed-capable device such as a fan, air conditioner, or purifier.
set_hvac_modewriteSet mode on a mode-capable device such as an air conditioner, fan, or purifier.
set_target_temperaturewriteSet target temperature on any target-temperature-capable device.
turn_off_devicereadTurn off a device.
turn_on_devicereadTurn on a device.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_saved_login, prepare_login
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, mijiaAPI, Pillow, qrcode, setuptools
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 67015f774b20full audit observations/trust-audit/mcp-server/javen-yan__miot.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0767015f774b20SAFEB89first audit
06

Questions

What is the MiOT MCP server?

基于 MijiaAPI 的米家设备智能控制代理,提供标准化的 MCP 服务,支持动态设备发现、属性读写和动作调用

What tools does MiOT expose?

26 in total: 16 read-only, 8 that write, and 2 that can delete or overwrite (clear_saved_login, prepare_login). Every one is listed on this page with its risk.

Is MiOT safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MiOT need?

It reads MIJIA_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MiOT run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as miot-mcp.

How current is this page?

The grade is for one exact copy of the source (67015f774b20), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement