MaaSAFE
基于 MaaFramework 的 MCP 服务器 为 AI 助手提供 Android 设备和 Windows 桌面自动化能力
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/MaaXYZ/MaaFramework) [](https://pypi.org/project/maa-mcp/)
基于 MaaFramework 的 MCP 服务器 为 AI 助手提供 Android 设备和 Windows 桌面自动化能力
English | 中文
简介
MaaMCP 是一个 MCP 服务器,将 MaaFramework 的强大自动化能力通过标准化的 MCP 接口暴露给 AI 助手(如 Claude)。通过本服务器,AI 助手可以:
- 🤖 Android 自动化 - 通过 ADB 连接并控制 Android 设备/模拟器
- 🖥️ Windows 自动化 - 控制 Windows 桌面应用程序
- 🎯 后台操作 - Windows 上的截图与控制均在后台运行,不占用鼠标键盘,您可以继续使用电脑做其他事情
- 🔗 多设备协同 - 同时控制多个设备/窗口,实现跨设备自动化
- ⚡ 双模式运行 - 串行模式(同步执行)和流水线模式(后台持续截图),适应不同场景需求
- 👁️ 智能识别 - 使用 OCR 识别屏幕文字内容
- 🎯 精准操作 - 执行点击、滑动、文本输入、按键等操作
- 📸 屏幕截图 - 获取实时屏幕截图进行视觉分析
Talk is cheap, 请看: [🎞️ Bilibili 视频演示](https://www.bilibili.com/video/BV1eGmhBaEZz/)
功能特性
🔍 设备发现与连接
find_adb_device_list- 扫描可用的 ADB 设备find_window_list- 扫描可用的 Windows 窗口connect_adb_device- 连接到 Android 设备connect_window- 连接到 Windows 窗口
👀 屏幕识别
ocr- 光学字符识别(高效,推荐优先使用)screencap- 屏幕截图(按需使用,token 开销大)
截图与坐标约定
Win32 和 ADB 连接默认使用 target_short_side=720,保持画面比例。OCR 的 region、 返回框、点击、滑动和 Pipeline 均使用该控制器的完整截图坐标,不一定是设备物理坐标。 screencap 默认 resolution=None,不再额外缩放,整图坐标可直接用于操作。
连接时可传 target_short_side=1080 等正整数,或传 None 使用原尺寸。该选项会改变 整个控制器的坐标基准,模板和 Pipeline ROI 必须使用匹配的尺度;现有 720p 资源应保留 默认连接设置。依赖旧版 Win32 1080p 坐标的调用方可显式选择 1080。
screencap 默认仍返回路径字符串。裁图或显式设置 `r
2534af4c93adOBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add maa-mcp -- uvx maa-mcp
{
"mcpServers": {
"maa-mcp": {
"command": "uvx",
"args": [
"maa-mcp"
]
}
}
}Exposed tools (6)
5 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
find_adb_device_list | read | device_list = Toolkit.find_adb_devices() |
find_window_list | read | window_list = Toolkit.find_desktop_windows() |
get_current_datetime | read | now = datetime.now() |
get_pipeline_status | read | return _get_pipeline_status_impl() |
save_pipeline | write | # 验证 JSON 格式 |
wait | read | MAX_WAIT = 60.0 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
ensure_within_pipelines_dir("../../etc/owned.json")result = save_pipeline(self.PIPELINE_JSON, output_path="../../etc/owned.json")
out = load_pipeline("../../etc/owned.json")_validate_path_segment("../../etc/passwd", "name")_save_captured_image(str(src), bundle_root, "UI", "../../etc/passwd")
Gates applied: no_behavioural_pass.
2534af4c93adfull audit observations/trust-audit/mcp-server/maa-ai__maa.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | 2534af4c93ad | SAFE | B | 89 | first audit |
Questions
What is the Maa MCP server?
基于 MaaFramework 的 MCP 服务器 为 AI 助手提供 Android 设备和 Windows 桌面自动化能力
What tools does Maa expose?
6 in total: 5 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Maa safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Maa need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (2534af4c93ad), read on 2026-10-02. The repository is watched and re-audited when it changes.