Atlas / MCP servers / lzsheng / Yapi

YapiSAFE

mcp/lzsheng/yapi

yapi mcp server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
5 4r · 1w · 0d
Transport
sse · stdio
License
MIT
Stars
120
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

一个用于 YApi 的 Model Context Protocol (MCP) 服务器,让你能够在 Cursor 等 AI 编程工具中直接操作 YApi 接口文档。

项目简介

Yapi Auto MCP Server 是一个基于 Model Context Protocol 的服务器,专为 YApi 接口管理平台设计。它允许你在 Cursor、Claude Desktop 等支持 MCP 的 AI 工具中直接:

  • 🔍 搜索和查看 YApi 项目中的接口文档
  • ✏️ 创建和更新 接口定义
  • 📋 管理项目和分类 结构
  • 🔗 无缝集成 AI 编程工作流
  • 🛠 支持多个 YApi Project配置

通过 MCP 协议,AI 助手可以理解你的 YApi 接口结构,在编程过程中提供更准确的建议和代码生成。

主要功能

🔍 接口查询和搜索

  • yapi_search_apis: 按名称、路径、标签等条件搜索接口
  • yapi_get_api_desc: 获取特定接口的详细信息(请求/响应结构、参数等)
  • yapi_list_projects: 列出所有可访问的项目
  • yapi_get_categories: 获取项目下的接口分类和接口列表

✏️ 接口管理

  • yapi_save_api: 创建新接口或更新现有接口
  • 支持完整的接口定义(路径、方法、参数、请求体、响应等)
  • 支持 JSON Schema 和表单数据格式
  • 自动处理接口状态和分类管理

🎯 智能特性

  • 多项目支持: 同时管理多个 YApi 项目
  • 缓存机制: 提高查询响应速度
  • 详细日志: 便于调试和监控
  • 灵活配置: 支持环境变量和命令行参数

快速开始

推荐方式:使用 npx(无需安装)

  1. 获取 YApi Token:登录你的 YApi 平台,在项目设置中获取 Token
  2. 配置 Cursor:在 Cursor 设置中添加 MCP 服务器:
{
"mcpServers": {
"yapi-auto-mcp": {
"command": "npx",
"args": [
"-y",
"yapi-auto-mcp",
"--stdio",
"--yapi-base-url=https://your-yapi-domain.com",
"--yapi-token=projectId:your_token_here"
]
}
}
}
  1. 开始使用:重启 Cursor,你就可以在对话中直接操作 YApi 了!

安装配置

方式一:npx 直接使用(推荐)

无需本地安装,通过 npx 直接运行:

{
"mcpServers": {
"yapi-auto-mcp": {
"command": "npx",
"args": [
"-y",
"yapi-auto-mcp",
"--stdio",
"--yapi-base-url=https://yapi.example.com",
"--yapi-token=projectId:token1,projectId2:token2",
"--yapi-cache-ttl=10",
"--yapi-log-level=info"
]
}
}
}

方式二:使用环境变量

在 MCP 配置中定义环境变量:

{
"mcpServers": {
"yapi-auto-mcp": {
"command": "npx",
"args": [
"-y",
"yapi-auto-mcp",
"--stdio"
],
"env": {
"YAPI_BASE_URL": "https://yapi.example.com",
"YAPI_TOKEN"
Read from source at commit fa57c3d0aba9OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add yapi-auto-mcp --env YAPI_TOKEN=${YAPI_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "yapi-auto-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "YAPI_TOKEN": "${YAPI_TOKEN}"
      }
    }
  }
}
03

Exposed tools (5)

4 read · 1 write · 0 destructive.

ToolRiskDescription
yapi_get_api_descread获取YApi中特定接口的详细信息
yapi_get_categoriesread获取YApi项目下的接口分类列表,以及每个分类下的接口信息
yapi_list_projectsread列出YApi的项目ID(projectId)和项目名称
yapi_save_apiwrite新增或更新YApi中的接口信息
yapi_search_apisread搜索YApi中的接口
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/yapi/cache.ts:25
const projectRoot = path.resolve(__dirname, '../../..');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/yargs, axios, dotenv, express, remeda, yargs, zod
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fa57c3d0aba9full audit observations/trust-audit/mcp-server/lzsheng__yapi.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fa57c3d0aba9SAFEB89first audit
06

Questions

What is the Yapi MCP server?

yapi mcp server

What tools does Yapi expose?

5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Yapi safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Yapi need?

It reads YAPI_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Yapi run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as yapi-auto-mcp at 0.1.3.

How current is this page?

The grade is for one exact copy of the source (fa57c3d0aba9), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement