PmHubBLOCK
PmHub,一个基于 SpringCloud & LLM 的智能项目管理系统,该项目旨在帮助小伙伴们快速掌握微服务/分布式项目的架构设计和开发流程。如果你想在校招或者社招中拿到一个满意的 offer,PmHub 将是一个非常 nice 的选择😄。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
PmHub,一个基于 SpringCloud & LLM 的智能项目管理系统
PmHub 是一套基于 SpringCloud & LLM 的微服务智能项目管理系统,这个项目旨在帮助小伙伴们快速掌握微服务/分布式项目的架构设计和开发流程,如果想在校招或者社招中拿到一个满意的 offer,PmHub 将是一个非常 nice 的选择。
项目亮点
- 热门技术:采用时下企业最热门的技术框架,如 SpringCloud-Gateway、Nacos、Sentinel 等,主打一个硬核,与真实的企业项目接轨。
- 单体与微服务:提供单体和微服务两个版本,完美照顾零基础和需要进阶的同学,带大家体验从单体到微服务架构的改造全过程,并深入理解两种架构的优缺点。
- 硬核面试题:我们将结合付费球友的实际面试体验,为大家提供可以真正吊打面试官的真是面试场景和题目,并提供 1v1 的简历修改服务,主打一个投了就有、面了就拿 offer 的快乐体感。
- 代码质量:由蚂蚁金服工作过的技术专家苍何亲自下场,严格遵循代码规范和最佳实践,帮大家养成优雅的代码编写习惯。
- 持续集成:提供持续集成和持续部署的完整配置,带你从 0-1 用 Docker 上线 生产环境级别的真实项目。
- 产品设计:提供完整的产品设计文档,包括产品需求、产品架构、产品原型等,这是别的项目不曾给你的,但工作后又不可或缺的能力。
- 企业工作流:提供企业级的工作流系统,代码完全开源,你可以在此基础上进行二开,为公司节省巨额的研发成本,从而升职加薪。
一、项目简介
PmHub 包括认证、流程、项目管理、用户、网关等服务。包含了 Redis 缓存、RocketMQ 消息队列、Docker 容器化、Jenkins 自动化部署、Spring Security 安全框架、Nacos 服务注册和发现、Sentinel 熔断限流、Seata 分布式事务、Spring Boot Actuator 服务监控、SkyWalking 链路追踪、OpenFeign 服务调用,Vue3 前端框架等互联网开发中需要用到的主流技术栈,可以帮助同学们快速掌握微服务/分布式项目的核心知识点。
并且同时 PmHub 也是一套企业工作流的开发框架,您可以根据自身需求,快速定制出适合自己公司的企业工作流系统。
f9ecf83f9402OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add form-gen-tinymce -- npx -y [email protected]
{
"mcpServers": {
"form-gen-tinymce": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (200)
405 read · 16 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
-moz-box | read | The element lays out its contents using flow layout (block-and-inline layout). Standardized as |
-moz-grab | read | Indicates that something can be grabbed. |
-moz-grabbing | read | Indicates that something is being grabbed. |
-moz-hidden-unscrollable | read | Same as the standardized |
-moz-inline-box | read | Inline-level flex container. Standardized as |
-moz-zoom-in | read | Indicates that something can be zoomed (magnified) in. |
-moz-zoom-out | read | Indicates that something can be zoomed (magnified) out. |
-ms-autohiding-scrollbar | read | Indicates the element displays auto-hiding scrollbars during mouse interactions and panning indicators during touch and keyboard interactions. |
-ms-flexbox | read | The element lays out its contents using flow layout (block-and-inline layout). Standardized as |
-ms-grid | read | The element generates a principal grid container box, and establishes a grid formatting context. |
-ms-inline-flexbox | read | Inline-level flex container. Standardized as |
-ms-inline-grid | read | Inline-level grid container. |
-ms-page | read | The box |
-webkit-box | read | The element lays out its contents using flow layout (block-and-inline layout). Standardized as |
-webkit-flex | read | The element lays out its contents using flow layout (block-and-inline layout). |
-webkit-grab | read | Indicates that something can be grabbed. |
-webkit-grabbing | read | Indicates that something is being grabbed. |
-webkit-inline-box | read | Inline-level flex container. Standardized as |
-webkit-inline-flex | read | Inline-level flex container. |
-webkit-sticky | read | The box |
-webkit-zoom-in | read | Indicates that something can be zoomed (magnified) in. |
-webkit-zoom-out | read | Indicates that something can be zoomed (magnified) out. |
100 | read | Thin |
200 | read | Extra Light (Ultra Light) |
300 | read | Light |
400 | read | Normal |
500 | read | Medium |
600 | read | Semi Bold (Demi Bold) |
700 | read | Bold |
800 | read | Extra Bold (Ultra Bold) |
900 | read | Black (Heavy) |
abbr | read | This attribute contains a short abbreviated description of the cell |
above | read | The reflection appears above the border box. |
absolute | read | The box |
accept | read | A comma-separated list of content types that the server accepts.\n\n**Usage note:** This attribute has been removed in HTML5 and should no longer be used. Instead, use the [ |
accumulate | read | If the ancestor container element has a property of new, then all graphics elements within the current container are rendered both on the parent |
active | read | The input method editor is initially active; text entry is performed using it unless the user specifically dismisses it. |
additional-ligatures | read | Enables display of additional ligatures. |
additive | read | Represents “sign-value” numbering systems, which, rather than using reusing digits in different positions to change their value, define additional digits with much larger values, so that the value of the number can be obtained by adding all the digits together. |
after | read | The ruby text appears after the base. This is a relatively rare setting used in ideographic East Asian writing systems, most easily found in educational text. |
alias | read | Indicates an alias of/shortcut to something is to be created. Often rendered as an arrow with a small curved arrow next to it. |
align | read | Sets the alignment of the rule on the page. If no value is specified, the default value is |
alink | read | Color of text for hyperlinks when selected. _This method is non-conforming, use CSS [ |
all | read | The element spans across all columns. Content in the normal flow that appears before the element is automatically balanced across all columns before the element appear. |
all-petite-caps | read | Enables display of petite capitals for both upper and lowercase letters. |
all-scroll | read | Indicates that the something can be scrolled in any direction. Often rendered as arrows pointing up, down, left, and right with a dot in the middle. |
all-small-caps | read | Enables display of small capitals for both upper and lowercase letters. |
allow | read | Specifies a [feature policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/Feature_Policy) for the |
allowpaymentrequest | write | Set to |
alpha | read | Alpha values of the mask layer image should be used as the mask values. |
alphabetic | read | The underline is aligned with the alphabetic baseline. In this case the underline is likely to cross some descenders. |
alternate | read | The animation cycle iterations that are odd counts are played in the normal direction, and the animation cycle iterations that are even counts are played in a reverse direction. |
alternate-reverse | read | The animation cycle iterations that are odd counts are played in the reverse direction, and the animation cycle iterations that are even counts are played in a normal direction. |
always | destructive | Always force a page break before/after the generated box. |
archive | read | A space-separated list of URIs for archives of resources for the object. |
armenian | read | Traditional uppercase Armenian numbering. |
as | read | This attribute is only used when |
auto | read | Computes to the value of |
autocapitalize | read | This is a nonstandard attribute used by iOS Safari Mobile which controls whether and how the text value for textual form control descendants should be automatically capitalized as it is entered/edited by the user. If the |
autocomplete | read | The use of this attribute on a [ |
avoid | read | Avoid a break before/after the principal box. |
avoid-column | read | Avoid a column break before/after the principal box. |
avoid-page | read | Avoid a page break before/after the principal box. |
axis | read | This attribute contains a list of space-separated strings. Each string is the |
background | read | URI of a image to use as a background. _This method is non-conforming, use CSS [ |
backwards | read | The beginning property value (as defined in the first @keyframes at-rule) is applied before the animation is displayed, during the period defined by |
balance | read | Balance content equally between columns, if possible. |
baseline | read | If the flex item’s inline axis is the same as the cross axis, this value is identical to |
before | read | The ruby text appears before the base. This is the most common setting used in ideographic East Asian writing systems. |
below | read | The underline is aligned with the under edge of the element’s content box. |
bevel | read | Indicates that a bevelled corner is to be used to join path segments. |
bgcolor | read | Background color for the document. _This method is non-conforming, use CSS [ |
bidi-override | read | Inside the element, reordering is strictly in sequence according to the |
block | read | The element generates a block-level box |
block-axis | read | Elements are oriented along the box |
bold | read | Same as 700 |
bolder | read | Specifies the weight of the face bolder than the inherited value. |
border | read | The width of a border around the control, in pixels. |
border-box | read | The specified width and height (and respective min/max properties) on this element determine the border box of the element. |
both | read | Both forwards and backwards fill modes are applied. |
bottom | read | Equivalent to |
bottommargin | read | The margin of the bottom of the body. _This method is non-conforming, use CSS [ |
break | read | If the content fits within the CSS Region, then this property has no effect. |
break-all | read | Lines may break between any two grapheme clusters for non-CJK scripts. |
break-word | read | An unbreakable |
bt | read | Bottom-to-top block flow. Layout is horizontal. |
butt | read | Indicates that the stroke for each subpath does not extend beyond its two endpoints. |
capitalize | read | Puts the first typographic letter unit of each word in titlecase. |
caption | destructive | The font used for captioned controls (e.g., buttons, drop-downs, etc.). |
cell | write | Indicates that a cell or set of cells may be selected. Often rendered as a thick plus-sign with a dot in the middle. |
center | read | Lines are packed toward the center of the flex container. |
chained | read | The nearest zoomable parent element begins zooming when the user hits a zoom limit during a manipulation. No bounce effect is shown. |
char | read | Any of the range of character values available to the -ms-layout-grid-char property. |
circle | read | A hollow circle. |
cite | read | This attribute defines the URI of a resource that explains the change, such as a link to meeting minutes or a ticket in a troubleshooting system. |
classid | read | The URI of the object |
clear | destructive | Inline flow content can only wrap on top and bottom of the exclusion and must leave the areas to the start and end edges of the exclusion box empty. |
clip | read | Clip inline content that overflows. Characters may be only partially rendered. |
clone | read | Each box is independently wrapped with the border and padding. |
codebase | read | The base path used to resolve relative URIs specified by **classid**, **data**, or **archive**. If not specified, the default is the base URI of the current document. |
codetype | read | The content type of the data specified by **classid**. |
col-resize | read | Indicates that the item/column can be resized horizontally. Often rendered as arrows pointing left and right with a vertical bar separating them. |
collapse | read | Selects the collapsing borders model. |
color | read | Sets the color of the rule through color name or hexadecimal value. |
color-burn | read | Darkens the backdrop color to reflect the source color. |
color-dodge | read | Brightens the backdrop color to reflect the source color. |
cols | read | Contains the _preferred_ count of characters that a line should have. It was a non-standard synonym of [ |
column | destructive | Always force a column break before/after the principal box. |
column-reverse | read | Same as |
common-ligatures | read | Enables display of common ligatures. |
compact | read | This Boolean attribute hints that the list should be rendered in a compact style. The interpretation of this attribute depends on the user agent and it doesn\ |
contain | read | Scale the image, while preserving its intrinsic aspect ratio (if any), to the largest size such that both its width and its height can fit inside the background positioning area. |
content | read | All containment rules except size are applied to the element. |
content-box | read | Behavior of width and height as specified by CSS2.1. The specified width and height (and respective min/max properties) apply to the width and height respectively of the content box of the element. |
contents | read | The element itself does not generate any boxes, but its children and pseudo-elements still generate boxes as normal. |
context-menu | read | A context menu is available for the object under the cursor. Often rendered as an arrow with a small menu-like graphic next to it. |
copy | read | Indicates something is to be copied. Often rendered as an arrow with a small plus sign next to it. |
cover | read | Scale the image, while preserving its intrinsic aspect ratio (if any), to the smallest size such that both its width and its height can completely cover the background positioning area. |
crisp-edges | read | The image must be scaled with an algorithm that preserves contrast and edges in the image, and which does not smooth colors or introduce blur to the image in the process. |
crispEdges | read | Emphasize the contrast between clean edges of artwork over rendering speed and geometric precision. |
crosshair | read | A simple crosshair (e.g., short line segments resembling a |
csp | read | A [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) enforced for the embedded resource. See [ |
current | read | Indicates that the user agent should target the frame that the element is in. |
cyclic | read | Cycles repeatedly through its provided symbols, looping back to the beginning when it reaches the end of the list. |
darken | read | Selects the darker of the backdrop and source colors. |
dashed | read | Produces a dashed line style. |
decimal | read | Western decimal numbers. |
decimal-leading-zero | read | Decimal numbers padded by initial zeros. |
declare | read | The presence of this Boolean attribute makes this element a declaration only. The object must be instantiated by a subsequent |
decoding | read | Provides an image decoding hint to the browser. The allowed values are: |
default | read | The platform-dependent default cursor. Often rendered as an arrow. |
dense | read | If specified, the auto-placement algorithm uses a “dense” packing algorithm, which attempts to fill in holes earlier in the grid if smaller items come up later. |
diagonal-fractions | read | Enables display of lining diagonal fractions. |
difference | read | Subtracts the darker of the two constituent colors from the lighter color.. |
digits | read | Attempt to typeset horizontally each maximal sequence of consecutive ASCII digits (U+0030–U+0039) that has as many or fewer characters than the specified integer such that it takes up the space of a single character within the vertical line box. |
dir | read | The direction in which text should be rendered in this element |
disabled | read | The input method editor is disabled and may not be activated by the user. |
disc | read | A filled circle. |
discretionary-ligatures | read | Enables display of discretionary ligatures. |
distribute | read | Lines are evenly distributed in the flex container, with half-size spaces on either end. |
dotted | read | Produces a dotted line. |
double | read | Produces a double line. |
double-tap-zoom | read | The element will zoom on double-tap. |
e-resize | read | Indicates that east edge is to be moved. |
ellipsis | read | Render an ellipsis character (U+2026) to represent clipped inline content. |
embed | read | If the element is inline-level, this value opens an additional level of embedding with respect to the bidirectional algorithm. The direction of this embedding level is given by the |
end | read | The items are packed flush to each other toward the end edge of the alignment container in the main axis. |
evenodd | read | Determines the ‘insideness’ of a point on the canvas by drawing a ray from that point to infinity in any direction and counting the number of path segments from the given shape that the ray crosses. |
ew-resize | read | Indicates a bidirectional east-west resize cursor. |
exclusion | read | Produces an effect similar to that of the Difference mode but lower in contrast. |
extends | read | Use the algorithm of another counter style, but alter other aspects. |
false | read | The element does not contain an accelerator key sequence. |
fill | read | Causes the middle part of the border-image to be preserved. |
fit-content | read | Use the fit-content inline size or fit-content block size, as appropriate to the writing mode. |
fixed | read | The background is fixed with regard to the viewport. In paged media where there is no viewport, a |
flat | read | All children of this element are rendered flattened into the 2D plane of the element. |
flex | read | The element generates a principal flex container box and establishes a flex formatting context. |
flex-end | read | Lines are packed toward the end of the flex container. |
flex-start | write | Lines are packed toward the start of the flex container. |
flexbox | read | The element lays out its contents using flow layout (block-and-inline layout). Standardized as |
flip | read | After rotating by the precededing angle, the image is flipped horizontally. Defaults to 0deg if the angle is ommitted. |
flow-root | read | The element generates a block container box, and lays out its contents using flow layout. |
form | read | This attribute associates the element with a |
forwards | read | The final property value (as defined in the last @keyframes at-rule) is maintained after the animation completes. |
from-image | read | If the image has an orientation specified in its metadata, such as EXIF, this value computes to the angle that the metadata specifies is necessary to correctly orient the image. |
full-width | read | Enables rendering of full-width variants. |
geometricPrecision | read | Emphasize geometric precision over speed and crisp edges. |
georgian | read | Traditional Georgian numbering. |
grab | read | Indicates that something can be grabbed. |
grabbing | read | Indicates that something is being grabbed. |
grid | read | The element generates a principal grid container box, and establishes a grid formatting context. |
grippers | read | Grippers are always on. |
hard-light | read | Multiplies or screens the colors, depending on the source color value. |
help | read | Help is available for the object under the cursor. Often rendered as a question mark or a balloon. |
hidden | read | Back side is hidden. |
hide | read | No borders or backgrounds are drawn around/behind empty cells. |
historical-forms | read | Enables display of historical forms. |
historical-ligatures | read | Enables display of historical ligatures. |
horizontal | read | The box displays its children from left to right in a horizontal line. |
horizontal-tb | read | Top-to-bottom block flow direction. The writing mode is horizontal. |
icon | read | The (pseudo-)element is replaced in its entirety by the resource referenced by its |
ideograph-alpha | read | Creates 1/4em extra spacing between runs of ideographic letters and non-ideographic letters, such as Latin-based, Cyrillic, Greek, Arabic or Hebrew. |
ideograph-numeric | read | Creates 1/4em extra spacing between runs of ideographic letters and numeric glyphs. |
ideograph-parenthesis | read | Creates extra spacing between normal (non wide) parenthesis and ideographs. |
ideograph-space | read | Extends the width of the space character while surrounded by ideographs. |
importance | read | Indicates the relative importance of the resource. Priority hints are delegated using the values: |
inactive | read | The input method editor is initially inactive, but the user may activate it if they wish. |
infinite | read | Causes the animation to repeat forever. |
inline | read | The element generates an inline-level box. |
inline-axis | read | Elements are oriented vertically. |
inline-block | read | A block box, which itself is flowed as a single inline box, similar to a replaced element. The inside of an inline-block is formatted as a block box, and the box itself is formatted as an inline box. |
inline-end | read | A keyword indicating that the element must float on the end side of its containing block. That is the right side with ltr scripts, and the left side with rtl scripts. |
inline-flex | read | Inline-level flex container. |
inline-flexbox | read | Inline-level flex container. Standardized as |
inline-start | write | A keyword indicating that the element must float on the start side of its containing block. That is the left side with ltr scripts, and the right side with rtl scripts. |
inline-table | read | Inline-level table wrapper box containing table box. |
inset | destructive | Changes the drop shadow from an outer shadow (one that shadows the box onto the canvas, as if it were lifted above the canvas) to an inner shadow (one that shadows the canvas onto the box, as if the box were cut out of the canvas and shifted behind it). |
inside | read | The marker box is outside the principal block box, as described in the section on the ::marker pseudo-element below. |
integrity | read | This attribute contains inline metadata that a user agent can use to verify that a fetched resource has been delivered free of unexpected manipulation. See [Subresource Integrity](https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity). |
inter-cluster | read | Justification primarily changes spacing at word separators and at grapheme cluster boundaries in clustered scripts. This value is typically used for Southeast Asian scripts such as Thai. |
Trust audit
BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
atob( ... new Function(
rules.push(`{ pattern: ${eval(item.pattern)}, message: '${item.message}', trigger: '${trigger[conf.tag]}' }`)item.pattern && (item.pattern = eval(item.pattern))
(window["webpackJsonp"]=window["webpackJsonp"]||[]).push([["chunk-53dbcb75"],{"00fd":function(e,t,n){var i=n("9e69"),r=Object.prototype,s=r.hasOwnProperty,o=r.toString,a=i?i.toStringTag:void 0;functiorules.push(`{ pattern: ${eval(item.pattern)}, message: '${item.message}', trigger: '${trigger[conf.tag]}' }`)item.pattern && (item.pattern = eval(item.pattern))
.node-version
.node-version
ie.html.gz
index.html.gz
workerMain.js.gz
target: `http://127.0.0.1:5010`,
target: `http://127.0.0.1:6880`,
privateKey: 12MIGTAgEAMBMGByqGSM49AgEGCCqBHM9VAYItBHkwdwIBAQQgElDjS1Gg6QjpSbfDe0Envb05XEDU9n1fx7wd8ezlnI6gCgYIKoEcz1UBgi2hRANCAAQw/nkFKApgqpwNXLhbjQP6T9vAM4NI86jiKPREJnGwStnLqg3Yx6e3ToBxRA+I4/In8DyIft
privateKey: MIGTAgEAMBMGByqGSM49AgEGCCqBHM9VAYItBHkwdwIBAQQgElDjS1Gg6QjpSbfDe0Envb05XEDU9n1fx7wd8ezlnI6gCgYIKoEcz1UBgi2hRANCAAQw/nkFKApgqpwNXLhbjQP6T9vAM4NI86jiKPREJnGwStnLqg3Yx6e3ToBxRA+I4/In8DyIftO9
background: url('data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iNDAiIGhlaWdodD0iNDAiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyI+PGRlZnM+PHBhdHRlcm4gaWQ9ImEiIHdpZHRoPSI0MCIgaGVpZ2h0PSI0MCIgcGF0dGVyblVuapublic final static String SECRET = "abcdefghijklmnopqrstuvwxyzabcdefghijklmnopqrstuvwxyzabcdefghijklmnopqrstuvwxyzabcdefghijklmnopqrstuvwxyz";
define("vs/basic-languages/bat/bat",["require","exports"],(function(e,s){"use strict";Object.defineProperty(s,"__esModule",{value:!0}),s.language=s.conf=void 0,s.conf={comments:{lineComment:"REM"},bradefine("vs/basic-languages/cameligo/cameligo",["require","exports"],(function(e,o){"use strict";Object.defineProperty(o,"__esModule",{value:!0}),o.language=o.conf=void 0,o.conf={comments:{lineComment:define("vs/basic-languages/clojure/clojure",["require","exports"],(function(e,t){"use strict";Object.defineProperty(t,"__esModule",{value:!0}),t.language=t.conf=void 0,t.conf={comments:{lineComment:";define("vs/basic-languages/coffee/coffee",["require","exports"],(function(e,n){"use strict";Object.defineProperty(n,"__esModule",{value:!0}),n.language=n.conf=void 0,n.conf={wordPattern:/(-?\d*\.\d\w*always, caption, clear, column, inset, no-drop, page
.env.development
.env.production
.env.staging
Gates applied: critical_finding, no_behavioural_pass.
f9ecf83f9402full audit observations/trust-audit/mcp-server/laigeoffer__pmhub.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | f9ecf83f9402 | BLOCK | F | 42 | first audit |
Questions
What is the PmHub MCP server?
PmHub,一个基于 SpringCloud & LLM 的智能项目管理系统,该项目旨在帮助小伙伴们快速掌握微服务/分布式项目的架构设计和开发流程。如果你想在校招或者社招中拿到一个满意的 offer,PmHub 将是一个非常 nice 的选择😄。
What tools does PmHub expose?
200 in total: 405 read-only, 16 that write, and 7 that can delete or overwrite (always, caption, clear, column, inset). Every one is listed on this page with its risk.
Is PmHub safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (42/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does PmHub need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (f9ecf83f9402), read on 2026-09-29. The repository is watched and re-audited when it changes.