MinerU TianshuCAUTION
天枢 - 企业级 AI 一站式数据预处理平台 | PDF/Office转Markdown | 支持MCP协议AI助手集成 | Vue3+FastAPI全栈方案 | 文档解析 | 多模态信息提取
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
企业级 AI 数据预处理平台
支持文档、图片、音频等多模态数据处理 | GPU 加速 | MCP 协议
结合 Vue 3 前端 + FastAPI 后端 + LitServe GPU负载均衡
[](https://mseep.ai/app/819ff68b-5154-4717-9361-7db787d5a2f8)
English | 简体中文
如果这个项目对你有帮助,请点击右上角 ⭐ Star 支持一下,这是对开发者最大的鼓励!
📝 最新更新
2026-09-13 🚀 v2.1.0:Webhook 任务通知、审计日志与界面体系升级
- ✅ Webhook 任务终态通知:任务完成/失败时向对接方推送带 HMAC 签名的回调(仅任务元数据 + 结果查询地址,不含解析内容);调度器周期投递,失败指数退避重试直至死信,全程 SSRF 防护,投递记录可查询
- ✅ 按 API Key 维度配置回调:每个对接系统在「API Token 管理」中自助绑定回调地址、签名密钥与出站鉴权(Bearer/Basic/自定义头),支持测试投递;管理员可在系统设置统一查看与管理全部对接方;临时场景可在提交任务时按任务指定
webhook_url - ✅ 审计日志:登录、配置变
a797f136fde7OBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add frontend --env JWT_SECRET_KEY=${JWT_SECRET_KEY} --env MCP_API_KEYS=${MCP_API_KEYS} --env REDIS_PASSWORD=${REDIS_PASSWORD} --env REDIS_PROCESSING_KEY=${REDIS_PROCESSING_KEY} -- npx -y [email protected]{
"mcpServers": {
"frontend": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"JWT_SECRET_KEY": "${JWT_SECRET_KEY}",
"MCP_API_KEYS": "${MCP_API_KEYS}",
"REDIS_PASSWORD": "${REDIS_PASSWORD}",
"REDIS_PROCESSING_KEY": "${REDIS_PROCESSING_KEY}"
}
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_queue_stats | read | |
get_task_status | read | |
list_tasks | read | |
parse_document | read |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (15 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (22)
tianshu.difypkg
logger.info(f"🔑 API Key 长度: {len(api_key) if api_key else 0} 字符")# - 本地开发: http://127.0.0.1:9000(默认)
RUSTFS_PUBLIC_URL=http://127.0.0.1:9000
# - 局域网: RUSTFS_PUBLIC_URL=http://192.168.1.100/s3
# - 无 nginx 的本地开发: RUSTFS_PUBLIC_URL=http://127.0.0.1:9000
"http://127.0.0.1:*",
.env.cpu.example
.pre-commit-config.yaml
.difyignore
.env.development
.env.production
__import__(name)
("../../report.pdf", "report.pdf"),file_content = base64.b64decode(args["file_base64"])
scipy, pandas, opencv-python-headless, shapely, pyclipper, psutil, py-cpuinfo, biopython
dify_plugin, httpx, yarl
@scalar/api-reference, @tailwindcss/typography, @vitejs/plugin-vue, axios, dayjs, highlight.js, katex, lucide-vue-next
- JWT(Access + Refresh Token)或 API Key,由 `auth/dependencies.py::get_current_user` 解析(先试 Bearer Token,再试 API Key)。
JWT (access + refresh) or API key, resolved by `auth/dependencies.py::get_current_user`, which tries the
- ✅ **User Auth**: JWT authentication, role-based access, API key management
- **Webhook**:任务进入终态(completed/failed)时,`litserve_worker.py` 调用 `webhook.dispatcher.enqueue_task_event` 写入 `webhook_deliveries` 表(子任务不触发,父任务在合并完成后触发一次);`task_scheduler` 每约 30 秒扫描到期投递并投递(指数退避,上限由 `webh
Gates applied: no_behavioural_pass.
a797f136fde7full audit observations/trust-audit/mcp-server/magicyuan876__mineru-tianshu.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | a797f136fde7 | CAUTION | C | 79 | first audit |
Questions
What is the MinerU Tianshu MCP server?
天枢 - 企业级 AI 一站式数据预处理平台 | PDF/Office转Markdown | 支持MCP协议AI助手集成 | Vue3+FastAPI全栈方案 | 文档解析 | 多模态信息提取
What tools does MinerU Tianshu expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MinerU Tianshu safe to connect to an agent?
With care. The audit graded it C (79/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does MinerU Tianshu need?
It reads JWT_SECRET_KEY, MCP_API_KEYS, REDIS_PASSWORD, REDIS_PROCESSING_KEY, REDIS_QUEUE_KEY, RUSTFS_ACCESS_KEY, RUSTFS_SECRET_KEY, SSO_CLIENT_SECRET, TIANSHU_ADMIN_PASSWORD and TIANSHU_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MinerU Tianshu run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as frontend at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (a797f136fde7), read on 2026-09-27. The repository is watched and re-audited when it changes.