Atlas / MCP servers / magicyuan876 / MinerU Tianshu

MinerU TianshuCAUTION

mcp/magicyuan876/mineru-tianshu

天枢 - 企业级 AI 一站式数据预处理平台 | PDF/Office转Markdown | 支持MCP协议AI助手集成 | Vue3+FastAPI全栈方案 | 文档解析 | 多模态信息提取

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
4 4r · 0w · 0d
Transport
streamable-http
License
Apache-2.0
Stars
821
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

企业级 AI 数据预处理平台

支持文档、图片、音频等多模态数据处理 | GPU 加速 | MCP 协议

结合 Vue 3 前端 + FastAPI 后端 + LitServe GPU负载均衡

[](https://mseep.ai/app/819ff68b-5154-4717-9361-7db787d5a2f8)

English | 简体中文

如果这个项目对你有帮助,请点击右上角 ⭐ Star 支持一下,这是对开发者最大的鼓励!

📝 最新更新

2026-09-13 🚀 v2.1.0:Webhook 任务通知、审计日志与界面体系升级

  • ✅ Webhook 任务终态通知:任务完成/失败时向对接方推送带 HMAC 签名的回调(仅任务元数据 + 结果查询地址,不含解析内容);调度器周期投递,失败指数退避重试直至死信,全程 SSRF 防护,投递记录可查询
  • ✅ 按 API Key 维度配置回调:每个对接系统在「API Token 管理」中自助绑定回调地址、签名密钥与出站鉴权(Bearer/Basic/自定义头),支持测试投递;管理员可在系统设置统一查看与管理全部对接方;临时场景可在提交任务时按任务指定 webhook_url
  • ✅ 审计日志:登录、配置变
Read from source at commit a797f136fde7OBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add frontend --env JWT_SECRET_KEY=${JWT_SECRET_KEY} --env MCP_API_KEYS=${MCP_API_KEYS} --env REDIS_PASSWORD=${REDIS_PASSWORD} --env REDIS_PROCESSING_KEY=${REDIS_PROCESSING_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "frontend": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "JWT_SECRET_KEY": "${JWT_SECRET_KEY}",
        "MCP_API_KEYS": "${MCP_API_KEYS}",
        "REDIS_PASSWORD": "${REDIS_PASSWORD}",
        "REDIS_PROCESSING_KEY": "${REDIS_PROCESSING_KEY}"
      }
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
get_queue_statsread
get_task_statusread
list_tasksread
parse_documentread
04

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (15 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (22)

MEDIUMInventory / provenance · inv.binary · CWE-1104
dify_plugin/tianshu/tianshu.difypkg
tianshu.difypkg
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
dify_plugin/tianshu/provider/tianshu.py:44
logger.info(f"🔑 API Key 长度: {len(api_key) if api_key else 0} 字符")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.cpu.example:148
#   - 本地开发: http://127.0.0.1:9000(默认)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.cpu.example:152
RUSTFS_PUBLIC_URL=http://127.0.0.1:9000
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:209
#   - 局域网: RUSTFS_PUBLIC_URL=http://192.168.1.100/s3
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:211
#   - 无 nginx 的本地开发: RUSTFS_PUBLIC_URL=http://127.0.0.1:9000
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
backend/mcp_server.py:791
"http://127.0.0.1:*",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.cpu.example
.env.cpu.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
dify_plugin/tianshu/.difyignore
.difyignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
frontend/.env.development
.env.development
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
frontend/.env.production
.env.production
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
backend/tests/unit/mineru_pipeline/test_content_list.py:21
__import__(name)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
backend/tests/unit/test_file_utils.py:10
("../../report.pdf", "report.pdf"),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
backend/mcp_server.py:328
file_content = base64.b64decode(args["file_base64"])
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
backend/requirements.txt
scipy, pandas, opencv-python-headless, shapely, pyclipper, psutil, py-cpuinfo, biopython
Why it matters. 60 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
dify_plugin/tianshu/requirements.txt
dify_plugin, httpx, yarl
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
frontend/package.json
@scalar/api-reference, @tailwindcss/typography, @vitejs/plugin-vue, axios, dayjs, highlight.js, katex, lucide-vue-next
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
AGENTS.md:187
- JWT(Access + Refresh Token)或 API Key,由 `auth/dependencies.py::get_current_user` 解析(先试 Bearer Token,再试 API Key)。
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:152
JWT (access + refresh) or API key, resolved by `auth/dependencies.py::get_current_user`, which tries the
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README_EN.md:255
- ✅ **User Auth**: JWT authentication, role-based access, API key management
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
AGENTS.md:182
- **Webhook**:任务进入终态(completed/failed)时,`litserve_worker.py` 调用 `webhook.dispatcher.enqueue_task_event` 写入 `webhook_deliveries` 表(子任务不触发,父任务在合并完成后触发一次);`task_scheduler` 每约 30 秒扫描到期投递并投递(指数退避,上限由 `webh
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha a797f136fde7full audit observations/trust-audit/mcp-server/magicyuan876__mineru-tianshu.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-27a797f136fde7CAUTIONC79first audit
06

Questions

What is the MinerU Tianshu MCP server?

天枢 - 企业级 AI 一站式数据预处理平台 | PDF/Office转Markdown | 支持MCP协议AI助手集成 | Vue3+FastAPI全栈方案 | 文档解析 | 多模态信息提取

What tools does MinerU Tianshu expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is MinerU Tianshu safe to connect to an agent?

With care. The audit graded it C (79/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does MinerU Tianshu need?

It reads JWT_SECRET_KEY, MCP_API_KEYS, REDIS_PASSWORD, REDIS_PROCESSING_KEY, REDIS_QUEUE_KEY, RUSTFS_ACCESS_KEY, RUSTFS_SECRET_KEY, SSO_CLIENT_SECRET, TIANSHU_ADMIN_PASSWORD and TIANSHU_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MinerU Tianshu run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as frontend at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (a797f136fde7), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement