Qiniu Cloud StorageSAFE
AI写的七牛上传MCP,以后各种音频图片上传都可以传上去引用,方便很多。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
用于上传文件到七牛云存储的MCP服务
安装指南
- 克隆仓库
- 创建并激活虚拟环境:
python3 -m venv venv source venv/bin/activate
- 安装依赖:
pip install -r requirements.txt
- 配置环境变量:
export QINIU_ACCESS_KEY="你的AccessKey" export QINIU_SECRET_KEY="你的SecretKey" export QINIU_BUCKET_NAME="joemarkdown" export QINIU_DOMAIN="https://img.t5t6.com"
- 启动服务:
python server.py
配置说明
- 复制示例配置文件:
cp .env.example .env
- 编辑
.env文件填写你的七牛云凭证 - 切勿将
.env文件提交到版本控制
示例.env内容:
QINIU_ACCESS_KEY=你的AccessKey QINIU_SECRET_KEY=你的SecretKey QINIU_BUCKET_NAME=你的存储空间名称 QINIU_DOMAIN=https://你的域名
使用方法
- 克隆项目后首次运行:
# 进入项目目录 cd qiniu_mcp_server # 创建虚拟环境 python3 -m venv venv # 激活环境 (Linux/Mac) source venv/bin/activate # 安装依赖 pip install -r requirements.txt # 复制并配置.env文件 cp .env.example .env nano .env # 编辑填入你的七牛云凭证 # 启动服务 python server.py
- 日常使用:
cd qiniu_mcp_server source venv/bin/activate # 激活环境 python server.py # 启动服务
- 调用上传接口示例:
from mcp import McpClient
client = McpClient("qiniu_mcp")
url = client.use_tool("upload_file", {
"file_path": "/path/to/your/file.jpg"
})
print("文件URL:", url)服务提供以下工具:
upload_file(file_path: str) -> str: 上传文件并返回公开访问URL
Trae 集成配置
在Trae的配置文件中添加以下内容(请替换实际路径和凭证):
{
"mcpServers": {
"qiniu_mcp": {
"command": "python",
"args": [
"/path/to/qiniu_mcp_server/server.py"
],
"env": {
"QINIU_ACCESS_KEY": "你的AccessKey",
"QINIU_SECRET_KEY": "你的SecretKey",
"QINIU_BUCKET_NAME": "你的存储空间名称",
"QINIU_DOMAIN": "https://你的域名"
}
}
}
}注意: 实际使用时请确保:
- 替换
/path/to/为实际服务器路径 - 使用真实的凭证信息替换示例值
- 妥善保管凭证信息
ce7275fa35d3OBSERVED · 2026-10-08Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
upload_file | write | Uploads a file to Qiniu and returns its public URL |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
.DS_Store
.DS_Store
fastmcp, qiniu
Gates applied: no_behavioural_pass, no_license.
ce7275fa35d3full audit observations/trust-audit/mcp-server/joeseesun__qiniu-cloud-storage.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ce7275fa35d3 | SAFE | B | 89 | first audit |
Questions
What is the Qiniu Cloud Storage MCP server?
AI写的七牛上传MCP,以后各种音频图片上传都可以传上去引用,方便很多。
What tools does Qiniu Cloud Storage expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Qiniu Cloud Storage safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Qiniu Cloud Storage need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (ce7275fa35d3), read on 2026-10-08. The repository is watched and re-audited when it changes.