XueqiuSAFE
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
基于雪球API的MCP服务,让您通过Claude或其他AI助手轻松获取股票数据。
项目简介
本项目基于pysnowball封装了雪球API,并通过MCP协议提供服务,使您能够在Claude等AI助手中直接查询股票数据。
安装方法
本项目使用uv进行依赖管理。请按照以下步骤进行安装:
# 克隆仓库 git clone https://github.com/liqiongyu/xueqiu_mcp.git cd xueqiu_mcp # 使用uv安装依赖 uv venv && uv pip install -e .
配置
配置雪球Token
- 在项目根目录创建
.env文件 - 添加以下内容:
XUEQIU_TOKEN=您的雪球token
- 快捷方式:
echo 'XUEQIU_TOKEN="xq_a_token=xxxxx;u=xxxx"' > .env
关于如何获取雪球token,请参考pysnowball文档。
运行服务
使用以下命令启动MCP服务:
uv --directory /path/to/xueqiu_mcp run main.py
或者,如果您已经配置了Claude Desktop:
"xueqiu-mcp": {
"args": [
"--directory",
"/path/to/xueqiu_mcp",
"run",
"main.py"
],
"command": "uv"
}功能特性
- 获取股票实时行情
- 查询指数收益
- 获取深港通/沪港通北向数据
- 基金相关数据查询
- 关键词搜索股票代码
展示图
致谢
- pysnowball - 雪球股票数据接口的Python版本
- fastmcp - MCP服务框架
许可证
MIT License
701a7997596dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add xueqiu-mcp --env XUEQIU_TOKEN=${XUEQIU_TOKEN} -- uvx xueqiu-mcp{
"mcpServers": {
"xueqiu-mcp": {
"command": "uvx",
"args": [
"xueqiu-mcp"
],
"env": {
"XUEQIU_TOKEN": "${XUEQIU_TOKEN}"
}
}
}
}Exposed tools (45)
45 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
balance | read | 获取资产负债表数据 |
blocktrans | read | 获取大宗交易数据 |
bonus | read | 获取F10分红融资数据 |
business | read | 获取主营业务构成数据 |
capital_assort | read | 获取资金成交分布数据 |
capital_flow | read | 获取当日资金流如流出数据,每分钟数据 |
capital_history | read | 获取历史资金流如流出数据,每日数据 |
cash_flow | read | 获取现金流量表数据 |
convertible_bond | read | 获取可转债信息 |
earningforecast | read | 按年度获取业绩预告数据 |
fund_achievement | read | 获取基金业绩表现数据 |
fund_asset | read | 获取基金资产配置数据 |
fund_derived | read | 获取基金衍生数据 |
fund_detail | read | 获取基金详细信息 |
fund_growth | read | 获取基金增长数据 |
fund_info | read | 获取基金基本信息 |
fund_manager | read | 获取基金经理信息 |
fund_nav_history | read | 获取基金历史净值数据 |
fund_trade_date | read | 获取基金交易日期信息 |
holders | read | 获取F10股东人数数据 |
income | read | 获取利润表数据 |
index_basic_info | read | 获取指数基本信息 |
index_details_data | read | 获取指数详细信息 |
index_perf_30 | read | 获取指数最近30天收益数据 |
index_perf_7 | read | 获取指数最近7天收益数据 |
index_perf_90 | read | 获取指数最近90天收益数据 |
index_weight_top10 | read | 获取指数权重股前十 |
indicator | read | 按年度、季度获取业绩报表数据 |
industry_compare | read | 获取F10行业对比数据 |
kline | read | 获取K线数据。第二参数可制定从现在到N天前,默认100 |
main_indicator | read | 获取F10主要指标数据 |
margin | read | 获取融资融券数据 |
nav_daily | read | 获取组合净值数据 |
northbound_shareholding_sh | read | 获取深港通北向数据 |
northbound_shareholding_sz | read | 获取沪港通北向数据 |
org_holding_change | read | 获取F10机构持仓数据 |
pankou | read | 获取实时分笔数据,可以实时取得股票当前报价和成交信息 |
quote_detail | read | 获取某支股票的行情数据-详细 |
quotec | read | 获取某支股票的行情数据 |
rebalancing_history | read | 获取组合历史交易信息 |
report | read | 获取机构评级数据 |
suggest_stock | read | 关键词搜索股票代码 |
top_holders | read | 获取十大股东数据 |
watch_list | read | 获取用户自选列表 |
watch_stock | read | 获取用户自选列表详情 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
701a7997596dfull audit observations/trust-audit/mcp-server/liqiongyu__xueqiu.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 701a7997596d | SAFE | B | 89 | first audit |
Questions
What tools does Xueqiu expose?
45 in total: 45 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Xueqiu safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Xueqiu need?
It reads XUEQIU_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (701a7997596d), read on 2026-10-07. The repository is watched and re-audited when it changes.