Atlas / MCP servers / joeseesun / Qiniu Cloud Storage

Qiniu Cloud StorageSAFE

mcp/joeseesun/qiniu-cloud-storage

AI写的七牛上传MCP,以后各种音频图片上传都可以传上去引用,方便很多。

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 0r · 1w · 0d
Transport
—
License
—
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

用于上传文件到七牛云存储的MCP服务

安装指南

  1. 克隆仓库
  2. 创建并激活虚拟环境:
python3 -m venv venv
source venv/bin/activate
  1. 安装依赖:
pip install -r requirements.txt
  1. 配置环境变量:
export QINIU_ACCESS_KEY="你的AccessKey"
export QINIU_SECRET_KEY="你的SecretKey" 
export QINIU_BUCKET_NAME="joemarkdown"
export QINIU_DOMAIN="https://img.t5t6.com"
  1. 启动服务:
python server.py

配置说明

  1. 复制示例配置文件:
cp .env.example .env
  1. 编辑.env文件填写你的七牛云凭证
  2. 切勿将.env文件提交到版本控制

示例.env内容:

QINIU_ACCESS_KEY=你的AccessKey
QINIU_SECRET_KEY=你的SecretKey
QINIU_BUCKET_NAME=你的存储空间名称
QINIU_DOMAIN=https://你的域名

使用方法

  1. 克隆项目后首次运行:
# 进入项目目录
cd qiniu_mcp_server

# 创建虚拟环境
python3 -m venv venv

# 激活环境 (Linux/Mac)
source venv/bin/activate

# 安装依赖
pip install -r requirements.txt

# 复制并配置.env文件
cp .env.example .env
nano .env  # 编辑填入你的七牛云凭证

# 启动服务
python server.py
  1. 日常使用:
cd qiniu_mcp_server
source venv/bin/activate  # 激活环境
python server.py          # 启动服务
  1. 调用上传接口示例:
from mcp import McpClient

client = McpClient("qiniu_mcp")
url = client.use_tool("upload_file", {
"file_path": "/path/to/your/file.jpg"
})
print("文件URL:", url)

服务提供以下工具:

  • upload_file(file_path: str) -> str: 上传文件并返回公开访问URL

Trae 集成配置

在Trae的配置文件中添加以下内容(请替换实际路径和凭证):

{
"mcpServers": {
"qiniu_mcp": {
"command": "python",
"args": [
"/path/to/qiniu_mcp_server/server.py"
],
"env": {
"QINIU_ACCESS_KEY": "你的AccessKey",
"QINIU_SECRET_KEY": "你的SecretKey",
"QINIU_BUCKET_NAME": "你的存储空间名称",
"QINIU_DOMAIN": "https://你的域名"
}
}
}
}

注意: 实际使用时请确保:

  1. 替换/path/to/为实际服务器路径
  2. 使用真实的凭证信息替换示例值
  3. 妥善保管凭证信息
Read from source at commit ce7275fa35d3OBSERVED · 2026-10-08
02

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
upload_filewriteUploads a file to Qiniu and returns its public URL
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, qiniu
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha ce7275fa35d3full audit observations/trust-audit/mcp-server/joeseesun__qiniu-cloud-storage.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08ce7275fa35d3SAFEB89first audit
05

Questions

What is the Qiniu Cloud Storage MCP server?

AI写的七牛上传MCP,以后各种音频图片上传都可以传上去引用,方便很多。

What tools does Qiniu Cloud Storage expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Qiniu Cloud Storage safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Qiniu Cloud Storage need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (ce7275fa35d3), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement