Atlas / MCP servers / joey-zhou / Xiaozhi ESP32 Server

Xiaozhi ESP32 ServerBLOCK

mcp/joey-zhou/xiaozhi-esp32-server

小智ESP32的Java企业级管理平台,提供设备监控、音色定制、角色切换和对话记录管理的前后端及服务端一体化解决方案

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
5 5r · 0w · 0d
Transport
—
License
MIT
Stars
1,357
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Xiaozhi ESP32 Server Java

基于 Xiaozhi ESP32 项目开发的 Java 版本服务端,包含完整前后端管理平台 为智能硬件设备提供强大的后端支持和直观的管理界面

反馈问题 · 部署文档 · 更新日志

Read from source at commit 4b6cd3218ea0OBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add xiaozhi-esp32-server-java-vue3 -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "xiaozhi-esp32-server-java-vue3": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
NamereadDescription
func_changeRoleread切换角色
func_exitSessionread退出
func_playMusicread
名称read描述
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (9 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
web/public/libopus.js:15
y.removeFunction=y.A;var H=!1;function assert(a,c){a||G("Assertion failed: "+c)}function ba(a){var c=b["_"+a];if(!c)try{c=eval("_"+a)}catch(d){}assert(c,"Cannot call unknown function "+a+" (perhaps LL
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
web/public/libopus.js:17
0;n<g.length;n++){var P=e[d[n]];P?(0===D&&(D=y.g()),C[n]=P(g[n])):C[n]=g[n]}d=a.apply(null,C);"string"===c&&(d=I(d));if(0!==D){if(k&&k.async){EmterpreterAsync.F.push(function(){y.c(D)});return}y.c(D)}
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
web/public/libopus.js:18
") {";var D=g.length;if(!d){c();e+="var stack = "+k.stackSave.body+";";for(var n=0;n<D;n++){var P=C[n],K=g[n];"number"!==K&&(K=k[K+"ToC"],e+="var "+K.arguments+" = "+P+";",e+=K.body+";",e+=P+"=("+K.re
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
repo/com/k2fsa/sherpa-onnx/1.12.21/sherpa-onnx-1.12.21.jar
sherpa-onnx-1.12.21.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
lib/libonnxruntime.dylib
lib/libonnxruntime.dylib
Why it matters. link not followed
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
bin/_common.ps1:1
# =============================================================================
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
bin/all.ps1:1
# =============================================================================
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
bin/dialogue.ps1:1
# =============================================================================
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
bin/server.ps1:1
# =============================================================================
LOWInventory / provenance · inv.hidden_file · CWE-1104
web/.env.development
.env.development
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
web/.env.local.example
.env.local.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
web/.env.production
.env.production
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
web/.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/locales/__tests__/locale-parity.test.ts:9
import { CONNECTION_STATUS_KEYS } from '../../services/websocket'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/locales/__tests__/locale-parity.test.ts:11
const SRC_ROOT = fileURLToPath(new URL('../../', import.meta.url))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
web/src/views/__tests__/publicAssetRefs.test.ts:8
const WEB_ROOT = fileURLToPath(new URL('../../../', import.meta.url))
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CENTOS_DEVELOPMENT.md:79
proxy_pass http://127.0.0.1:8091;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CENTOS_DEVELOPMENT.md:86
proxy_pass http://127.0.0.1:8091;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CENTOS_DEVELOPMENT.md:90
proxy_pass http://127.0.0.1:8092;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/FIRMWARE-BUILD.md:41
改成你自己的地址,例如,我的接口地址是`http://192.168.5.165:8091/api/device/ota/`,就把内容改成这个。
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/FIRMWARE-BUILD.md:56
default "http://192.168.5.167:8091/api/device/ota"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
web/package.json
@antv/g2plot, @vueuse/core, ant-design-vue, axios, dayjs, exceljs, jsencrypt, jsonp
Why it matters. 41 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/CENTOS_DEVELOPMENT.md:13
curl -sL https://rpm.nodesource.com/setup_22.x | sudo bash - && sudo yum install -y nodejs
INFOInventory / provenance · inv.oversize · CWE-1104
lib/libsherpa-onnx-jni.dylib
lib/libsherpa-onnx-jni.dylib
Why it matters. 4441512 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
lib/libvosk.dylib
lib/libvosk.dylib
Why it matters. 12533472 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha 4b6cd3218ea0full audit observations/trust-audit/mcp-server/joey-zhou__xiaozhi-esp32-server.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-244b6cd3218ea0BLOCKF55first audit
06

Questions

What is the Xiaozhi ESP32 Server MCP server?

小智ESP32的Java企业级管理平台,提供设备监控、音色定制、角色切换和对话记录管理的前后端及服务端一体化解决方案

What tools does Xiaozhi ESP32 Server expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Xiaozhi ESP32 Server safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Xiaozhi ESP32 Server need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (4b6cd3218ea0), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement