Atlas / MCP servers / julesliu390 / Amadeus

AmadeusCAUTION

mcp/julesliu390/amadeus-1

一个可以让你的OpenClaw和支持MCP的agent接入QQ进行私聊或者群聊的MCP。El-psy-congroo.

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
10 7r · 3w · 0d
Transport
stdio
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP Server,通过 NapCatQQ (OneBot v11) 让 AI 客户端收发 QQ 消息。支持群聊和私聊。

功能

  • 6 个 MCP 工具:check_status、get_group_list、get_recent_context、batch_get_recent_context、send_message、compress_context
  • WebSocket 实时消息监听 + 自动重连
  • 消息按自然语义分段发送(句号/逗号/破折号等),模拟真人打字节奏
  • 支持 AI 自主控制消息拆分段数(num_chunks 参数,按标点拆分后合并为指定段数)
  • 群/好友白名单控制
  • 发送速率限制(3s/目标)

前置条件

  • 已安装并运行的原生 NapCatQQ(OneBot v11)
  • Python 3.11+
  • uv

PetGPT 的内置 QQ Connector 会按需管理 uv、Python 和本项目,用户不需要手动安装 Python,也不使用 Docker。独立运行本项目时,可以使用 NapCat 官方提供的 Windows OneKey/Shell、Linux AppImage 或 macOS Installer。

原生 NapCat 快速接入(推荐)

  1. 启动原生 NapCat,并在 WebUI 中完成 QQ 扫码登录。
  2. 创建仅监听 127.0.0.1 的 OneBot HTTP Server(默认端口 3000)。
  3. 创建仅监听 127.0.0.1 的 OneBot WebSocket Server(默认端口 3001)。
  4. 两个 Server 使用同一个随机 token。
  5. 启动 MCP:
uv run qq-agent-mcp --qq 你的QQ号 --access-token 你的OneBot访问令牌

PetGPT 会自动完成第 2~5 步,并在注册前验证 Social Agent 依赖的工具契约。

旧版 Docker 快速开始(Windows,可选)

1. 配置 NapCat

.\scripts\setup-windows.ps1

交互式引导你完成:

  • 检查并自动启动 Docker Desktop
  • 拉取 NapCat Docker 镜像
  • 输入 QQ 号、设备名称
  • 生成 docker-compose.yml
  • 生成 OneBot11 接口配置(HTTP API 端口 3000 + WebSocket 端口 3001)
  • 生成 mcp.json

2. 启动 NapCat

.\scripts\start-docker-windows.ps1

首次启动需扫码登录,查看二维码:

docker compose logs -f napcat

或访问 WebUI:http://localhost:6099

3. 启动 MCP Server

uv run qq-agent-mcp --qq 你的QQ号

4. 配置 MCP 客户端

setup-windows.ps1 已自动生成 mcp.json:

{
"mcpServers": {
"qq-agent": {
"command": "C:/Users/你的用户名/.local/bin/uv.exe",
"args": "run --directory C:/path/to/Amadeus-QQ-MCP qq-agent-mcp --qq 你的QQ号"
}
}
}

将 mcp.json 的内容复制到你的 AI 客户端的 MCP 配置中即可。

旧版 Docker 快速开始(Linux,可选)

1. 安装依赖

scripts/install-linux.sh

自动安装 Docker、uv,初始化项目配置并安装 Python 依赖。安装完成后需要 source ~/.bashrc 或打开新终端让 uv 命令生效。

2. 配置 NapCat

scripts/setup-linux.sh

交互式引导你完成:

  • 拉
Read from source at commit fd488a3f380cOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add qq-agent-mcp --env NAPCAT_ACCESS_TOKEN=${NAPCAT_ACCESS_TOKEN} -- uvx qq-agent-mcp
claude-desktop
{
  "mcpServers": {
    "qq-agent-mcp": {
      "command": "uvx",
      "args": [
        "qq-agent-mcp"
      ],
      "env": {
        "NAPCAT_ACCESS_TOKEN": "${NAPCAT_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (10)

7 read · 3 write · 0 destructive.

ToolRiskDescription
batch_get_recent_contextreadBatch query recent message context for multiple targets.
check_statusreadCheck QQ login status and NapCat connection status.
compress_contextreadCompress all buffered messages for a target into a summary.
get_friend_listreadGet the list of QQ friends.
get_group_listreadGet the list of QQ groups the bot has joined.
get_recent_contextreadGet recent message context for a monitored group or whitelisted friend.
screenshot_chatreadTake a QQ-style screenshot of chat messages starting from a specific message.
send_imagewriteSend an image to a monitored group or whitelisted friend.
send_messagewriteSend a message to a monitored group or whitelisted friend.
send_voicewriteSend a voice message to a monitored group or whitelisted friend.
04

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (15)

MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
screenshot_test/faces/122.png:81
<img width="32" height="32" title="" alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyRpVFh0WE1MOmNvbS5hZG9iZS54bXAAA
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
screenshot_test/faces/122.png:85
<img width="32" height="32" title="" alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAAABACAYAAACqaXHeAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyRpVFh0WE1MOmNvbS5hZG9iZS54bXAAA
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
screenshot_test/faces/148.png:81
<img width="32" height="32" title="" alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyRpVFh0WE1MOmNvbS5hZG9iZS54bXAAA
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
screenshot_test/faces/148.png:85
<img width="32" height="32" title="" alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAAABACAYAAACqaXHeAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyRpVFh0WE1MOmNvbS5hZG9iZS54bXAAA
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
docker-compose.yml:1
services:
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
mcp.json:1
{
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/setup-windows.ps1:1
# ============================================================
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/start-docker-windows.ps1:1
# ============================================================
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
screenshot_test/test_render.py:218
idx = int(hashlib.md5(sender_id.encode()).hexdigest(), 16) % len(_AVATAR_COLORS)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/qq_agent_mcp/renderer.py:112
idx = int(hashlib.md5(sender_id.encode()).hexdigest(), 16) % len(_AVATAR_COLORS)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/qq_agent_mcp/tools.py:94
h = hashlib.md5(_normalize_content(content).encode()).hexdigest()
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
screenshot_test/test_real.py:16
ONEBOT_URL = "http://127.0.0.1:3000"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_auth.py:15
client = OneBotClient("http://127.0.0.1:3000", access_token="secret")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_auth.py:42
client = OneBotClient("http://127.0.0.1:3000", access_token="secret")
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
screenshot_test/chat_debug.html:485
<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABDAAAAFWCAYAAACfAW32AAAAAXNSR0IArs4c6QAAIABJREFUeF7snQeYFEX6xr/dZVFQQRFQMioYULIJxYAJAxIEDCgKCCqKghE9w3mn593fnAFRkphAQEHBQAYDKMGAoCggEgSUpMAum/7P

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha fd488a3f380cfull audit observations/trust-audit/mcp-server/julesliu390__amadeus-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09fd488a3f380cCAUTIONC79first audit
06

Questions

What is the Amadeus MCP server?

一个可以让你的OpenClaw和支持MCP的agent接入QQ进行私聊或者群聊的MCP。El-psy-congroo.

What tools does Amadeus expose?

10 in total: 7 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Amadeus safe to connect to an agent?

With care. The audit graded it C (79/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Amadeus need?

It reads NAPCAT_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Amadeus run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as qq-agent-mcp.

How current is this page?

The grade is for one exact copy of the source (fd488a3f380c), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement