AmadeusCAUTION
一个可以让你的OpenClaw和支持MCP的agent接入QQ进行私聊或者群聊的MCP。El-psy-congroo.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP Server,通过 NapCatQQ (OneBot v11) 让 AI 客户端收发 QQ 消息。支持群聊和私聊。
功能
- 6 个 MCP 工具:
check_status、get_group_list、get_recent_context、batch_get_recent_context、send_message、compress_context - WebSocket 实时消息监听 + 自动重连
- 消息按自然语义分段发送(句号/逗号/破折号等),模拟真人打字节奏
- 支持 AI 自主控制消息拆分段数(
num_chunks参数,按标点拆分后合并为指定段数) - 群/好友白名单控制
- 发送速率限制(3s/目标)
前置条件
- 已安装并运行的原生 NapCatQQ(OneBot v11)
- Python 3.11+
- uv
PetGPT 的内置 QQ Connector 会按需管理 uv、Python 和本项目,用户不需要手动安装 Python,也不使用 Docker。独立运行本项目时,可以使用 NapCat 官方提供的 Windows OneKey/Shell、Linux AppImage 或 macOS Installer。
原生 NapCat 快速接入(推荐)
- 启动原生 NapCat,并在 WebUI 中完成 QQ 扫码登录。
- 创建仅监听
127.0.0.1的 OneBot HTTP Server(默认端口 3000)。 - 创建仅监听
127.0.0.1的 OneBot WebSocket Server(默认端口 3001)。 - 两个 Server 使用同一个随机 token。
- 启动 MCP:
uv run qq-agent-mcp --qq 你的QQ号 --access-token 你的OneBot访问令牌
PetGPT 会自动完成第 2~5 步,并在注册前验证 Social Agent 依赖的工具契约。
旧版 Docker 快速开始(Windows,可选)
1. 配置 NapCat
.\scripts\setup-windows.ps1
交互式引导你完成:
- 检查并自动启动 Docker Desktop
- 拉取 NapCat Docker 镜像
- 输入 QQ 号、设备名称
- 生成
docker-compose.yml - 生成 OneBot11 接口配置(HTTP API 端口 3000 + WebSocket 端口 3001)
- 生成
mcp.json
2. 启动 NapCat
.\scripts\start-docker-windows.ps1
首次启动需扫码登录,查看二维码:
docker compose logs -f napcat
或访问 WebUI:http://localhost:6099
3. 启动 MCP Server
uv run qq-agent-mcp --qq 你的QQ号
4. 配置 MCP 客户端
setup-windows.ps1 已自动生成 mcp.json:
{
"mcpServers": {
"qq-agent": {
"command": "C:/Users/你的用户名/.local/bin/uv.exe",
"args": "run --directory C:/path/to/Amadeus-QQ-MCP qq-agent-mcp --qq 你的QQ号"
}
}
}将 mcp.json 的内容复制到你的 AI 客户端的 MCP 配置中即可。
旧版 Docker 快速开始(Linux,可选)
1. 安装依赖
scripts/install-linux.sh
自动安装 Docker、uv,初始化项目配置并安装 Python 依赖。安装完成后需要 source ~/.bashrc 或打开新终端让 uv 命令生效。
2. 配置 NapCat
scripts/setup-linux.sh
交互式引导你完成:
- 拉
fd488a3f380cOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add qq-agent-mcp --env NAPCAT_ACCESS_TOKEN=${NAPCAT_ACCESS_TOKEN} -- uvx qq-agent-mcp{
"mcpServers": {
"qq-agent-mcp": {
"command": "uvx",
"args": [
"qq-agent-mcp"
],
"env": {
"NAPCAT_ACCESS_TOKEN": "${NAPCAT_ACCESS_TOKEN}"
}
}
}
}Exposed tools (10)
7 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
batch_get_recent_context | read | Batch query recent message context for multiple targets. |
check_status | read | Check QQ login status and NapCat connection status. |
compress_context | read | Compress all buffered messages for a target into a summary. |
get_friend_list | read | Get the list of QQ friends. |
get_group_list | read | Get the list of QQ groups the bot has joined. |
get_recent_context | read | Get recent message context for a monitored group or whitelisted friend. |
screenshot_chat | read | Take a QQ-style screenshot of chat messages starting from a specific message. |
send_image | write | Send an image to a monitored group or whitelisted friend. |
send_message | write | Send a message to a monitored group or whitelisted friend. |
send_voice | write | Send a voice message to a monitored group or whitelisted friend. |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (15)
<img width="32" height="32" title="" alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyRpVFh0WE1MOmNvbS5hZG9iZS54bXAAA
<img width="32" height="32" title="" alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAAABACAYAAACqaXHeAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyRpVFh0WE1MOmNvbS5hZG9iZS54bXAAA
<img width="32" height="32" title="" alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyRpVFh0WE1MOmNvbS5hZG9iZS54bXAAA
<img width="32" height="32" title="" alt="" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAAABACAYAAACqaXHeAAAAGXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAAAyRpVFh0WE1MOmNvbS5hZG9iZS54bXAAA
services:
{# ============================================================
# ============================================================
idx = int(hashlib.md5(sender_id.encode()).hexdigest(), 16) % len(_AVATAR_COLORS)
idx = int(hashlib.md5(sender_id.encode()).hexdigest(), 16) % len(_AVATAR_COLORS)
h = hashlib.md5(_normalize_content(content).encode()).hexdigest()
ONEBOT_URL = "http://127.0.0.1:3000"
client = OneBotClient("http://127.0.0.1:3000", access_token="secret")client = OneBotClient("http://127.0.0.1:3000", access_token="secret")<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABDAAAAFWCAYAAACfAW32AAAAAXNSR0IArs4c6QAAIABJREFUeF7snQeYFEX6xr/dZVFQQRFQMioYULIJxYAJAxIEDCgKCCqKghE9w3mn593fnAFRkphAQEHBQAYDKMGAoCggEgSUpMAum/7P
Gates applied: no_behavioural_pass.
fd488a3f380cfull audit observations/trust-audit/mcp-server/julesliu390__amadeus-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | fd488a3f380c | CAUTION | C | 79 | first audit |
Questions
What is the Amadeus MCP server?
一个可以让你的OpenClaw和支持MCP的agent接入QQ进行私聊或者群聊的MCP。El-psy-congroo.
What tools does Amadeus expose?
10 in total: 7 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Amadeus safe to connect to an agent?
With care. The audit graded it C (79/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Amadeus need?
It reads NAPCAT_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Amadeus run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as qq-agent-mcp.
How current is this page?
The grade is for one exact copy of the source (fd488a3f380c), read on 2026-10-09. The repository is watched and re-audited when it changes.