Atlas / MCP servers / maa-ai / Maa

MaaSAFE

mcp/maa-ai/maa

基于 MaaFramework 的 MCP 服务器 为 AI 助手提供 Android 设备和 Windows 桌面自动化能力

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 5r · 1w · 0d
Transport
—
License
AGPL-3.0
Stars
387
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/MaaXYZ/MaaFramework) [](https://pypi.org/project/maa-mcp/)

基于 MaaFramework 的 MCP 服务器 为 AI 助手提供 Android 设备和 Windows 桌面自动化能力

English | 中文

简介

MaaMCP 是一个 MCP 服务器,将 MaaFramework 的强大自动化能力通过标准化的 MCP 接口暴露给 AI 助手(如 Claude)。通过本服务器,AI 助手可以:

  • 🤖 Android 自动化 - 通过 ADB 连接并控制 Android 设备/模拟器
  • 🖥️ Windows 自动化 - 控制 Windows 桌面应用程序
  • 🎯 后台操作 - Windows 上的截图与控制均在后台运行,不占用鼠标键盘,您可以继续使用电脑做其他事情
  • 🔗 多设备协同 - 同时控制多个设备/窗口,实现跨设备自动化
  • ⚡ 双模式运行 - 串行模式(同步执行)和流水线模式(后台持续截图),适应不同场景需求
  • 👁️ 智能识别 - 使用 OCR 识别屏幕文字内容
  • 🎯 精准操作 - 执行点击、滑动、文本输入、按键等操作
  • 📸 屏幕截图 - 获取实时屏幕截图进行视觉分析

Talk is cheap, 请看: [🎞️ Bilibili 视频演示](https://www.bilibili.com/video/BV1eGmhBaEZz/)

功能特性

🔍 设备发现与连接

  • find_adb_device_list - 扫描可用的 ADB 设备
  • find_window_list - 扫描可用的 Windows 窗口
  • connect_adb_device - 连接到 Android 设备
  • connect_window - 连接到 Windows 窗口

👀 屏幕识别

  • ocr - 光学字符识别(高效,推荐优先使用)
  • screencap - 屏幕截图(按需使用,token 开销大)

截图与坐标约定

Win32 和 ADB 连接默认使用 target_short_side=720,保持画面比例。OCR 的 region、 返回框、点击、滑动和 Pipeline 均使用该控制器的完整截图坐标,不一定是设备物理坐标。 screencap 默认 resolution=None,不再额外缩放,整图坐标可直接用于操作。

连接时可传 target_short_side=1080 等正整数,或传 None 使用原尺寸。该选项会改变 整个控制器的坐标基准,模板和 Pipeline ROI 必须使用匹配的尺度;现有 720p 资源应保留 默认连接设置。依赖旧版 Win32 1080p 坐标的调用方可显式选择 1080。

screencap 默认仍返回路径字符串。裁图或显式设置 `r

Read from source at commit 2534af4c93adOBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add maa-mcp -- uvx maa-mcp
claude-desktop
{
  "mcpServers": {
    "maa-mcp": {
      "command": "uvx",
      "args": [
        "maa-mcp"
      ]
    }
  }
}
03

Exposed tools (6)

5 read · 1 write · 0 destructive.

ToolRiskDescription
find_adb_device_listreaddevice_list = Toolkit.find_adb_devices()
find_window_listreadwindow_list = Toolkit.find_desktop_windows()
get_current_datetimereadnow = datetime.now()
get_pipeline_statusreadreturn _get_pipeline_status_impl()
save_pipelinewrite# 验证 JSON 格式
waitreadMAX_WAIT = 60.0
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_pipeline_path_safety.py:58
ensure_within_pipelines_dir("../../etc/owned.json")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_pipeline_path_safety.py:109
result = save_pipeline(self.PIPELINE_JSON, output_path="../../etc/owned.json")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_pipeline_path_safety.py:151
out = load_pipeline("../../etc/owned.json")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_vision.py:341
_validate_path_segment("../../etc/passwd", "name")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_vision.py:443
_save_captured_image(str(src), bundle_root, "UI", "../../etc/passwd")

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha 2534af4c93adfull audit observations/trust-audit/mcp-server/maa-ai__maa.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-022534af4c93adSAFEB89first audit
06

Questions

What is the Maa MCP server?

基于 MaaFramework 的 MCP 服务器 为 AI 助手提供 Android 设备和 Windows 桌面自动化能力

What tools does Maa expose?

6 in total: 5 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Maa safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Maa need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (2534af4c93ad), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement