bm.mdSAFE
更好用的 Markdown 排版助手|专为微信公众号与多平台排版设计,支持富文本复制、图片生成与矢量 PDF 导出。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/miantiao-me/bm.md/actions/workflows/ci.yml) [](https://www.npmjs.com/package/bmmd) [](https://github.com/miantiao-me/bm.md/blob/master/LICENSE) [](https://tanstack.com/start/latest) [](https://ui.shadcn.com/)
Markdown 排版工具,专为微信公众号与多平台排版设计,支持富文本复制、图片生成与矢量 PDF 导出。
✨ 核心特性
- 专门适配微信排版:一键复制带内联样式的富文本,自动处理链接转脚注、代码块空格保护及移动端表格横向滚动;同时支持复制通用 HTML。
- 丰富的样式系统:内置 16 款经过细致调校的 Markdown 排版样式(涵盖经典纸质、现代报章、终端、学术等风格)与 14 款代码高亮主题,支持追加自定义 CSS。
- 图表与信息图集成:支持 Mermaid 流程图与 AntV Infographic 信息图,渲染产物自动进行安全清理并无缝内嵌。
- 多样化导出能力:基于 snapDOM 生成 PNG/JPEG 图片;集成 Takumi PDF WASM 引擎,直接在浏览器端按 A4 规范分页排版并导出矢量 PDF,支持字体子集下载与缺字降级。
- 多文件与格式导入:基于 IndexedDB 实现多标签页事务化持久存储;支持直接打开 Markdown,借助 AnyDoc WASM 引擎转换各类文档,并支持在图片导入时调用端侧 PaddleOCR.js 识别并提取纯文本。
- 三位一体的能力入口:除 Web 交互界面外,所有 Markdown 处理能力均通过统一 Registry 派生为命令行工具(CLI)、REST API 与 MCP(Model Context Protocol)服务。
🚀 快速开始
环境要求
- 本地开发、构建和应用部署使用 Node.js 24(见
.node-version);npm 发布的 CLI 支持 Node.js >= 20。 - Node.js 20 已结束维护,建议 CLI 用户也使用 Node.js 24。
- pnpm 11.26.0
本地运行
# 克隆仓库 git clone https://github.com/miantiao-me/bm.md.git cd bm.md # 安装依赖 pnpm install # 启动本地开发服务(默认端口 2663) pnpm dev
启动后在浏览器中访问 http://localhost:2663。
生产构建与本地预览:
pnpm build pnpm preview
环境变量
环境变量均为可选配置,具体可参考 .env.example:
VITE_APP_URL、VITE_API_URL:客户端访问的应用基地址与 API 地址。ANALYTICS_SCRIPT_URL、ANALYTICS_SITE_ID:统计分析脚本配置(服务端注入)。S3_ENDPOINT、S3_ACCESS_KEY_ID、S3_SECRET_ACCESS_KEY:三者齐备时启用 S3 兼容对象
6ec2c3b29970OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add bmmd --env S3_ACCESS_KEY_ID=${S3_ACCESS_KEY_ID} --env S3_SECRET_ACCESS_KEY=${S3_SECRET_ACCESS_KEY} -- npx -y [email protected]{
"mcpServers": {
"bmmd": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"S3_ACCESS_KEY_ID": "${S3_ACCESS_KEY_ID}",
"S3_SECRET_ACCESS_KEY": "${S3_SECRET_ACCESS_KEY}"
}
}
}
}Exposed tools (24)
24 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Bauhaus | read | 包豪斯风格,几何与功能主义 |
Blueprint | read | 蓝图技术文档风格 |
Botanical | read | 植物园风格,自然柔和 |
Kami | read | 简洁的纸张阅读风格(默认) |
Newsprint | read | 报纸印刷风格 |
Retro | read | 复古怀旧风格 |
Sketch | read | 手绘素描风格 |
Terminal | read | 终端/命令行风格 |
bm.md | read | 更好用的 Markdown 排版助手|一键适配微信公众号、网页与图片。 |
breaks | read | 将段落内的软换行转换为 HTML 换行 |
codeTheme | read | 代码块高亮主题 ID |
customCss | read | 追加自定义 CSS |
customCssFile | read | 从文件追加自定义 CSS |
enableFootnoteLinks | read | 关闭文中链接脚注转换 |
fix | read | 将修复结果写回输入文件;不能与 --output 同时使用 |
footnoteLabel | read | GFM 脚注区域标题 |
infographicPalette | read | Infographic 信息图配色 ID |
infographicTheme | read | Infographic 信息图主题 ID |
markdownStyle | read | Markdown 排版样式 ID |
mermaidTheme | read | Mermaid 流程图主题 ID,留空表示使用默认主题 |
openLinksInNewWindow | read | 关闭外部链接新窗口打开 |
output | read | 输出文件,默认输出到 stdout |
platform | read | 目标发布平台 |
referenceTitle | read | 外部链接参考区域标题 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
.cta.json
.ignore
.node-version
CLAUDE.md
import remarkHighlight from '../../src/lib/markdown/render/plugins/remark-highlight.ts'
import remarkImageDimensions from '../../src/lib/markdown/render/plugins/remark-image-dimensions.ts'
import { sanitizeSchema } from '../../src/lib/markdown/render/sanitize-schema.ts'import { description, version } from '../../package.json'expect(() => replaceGraphemes('👨👩👧👦', new Set([0x1F468]), null))@antfu/eslint-config, @antv/infographic, @base-ui/react, @catppuccin/highlightjs, @codemirror/commands, @codemirror/lang-markdown, @codemirror/language, @codemirror/language-data
Gates applied: no_behavioural_pass.
6ec2c3b29970full audit observations/trust-audit/mcp-server/miantiao-me__bm-md.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 6ec2c3b29970 | SAFE | B | 89 | first audit |
Questions
What is the Bm.md MCP server?
更好用的 Markdown 排版助手|专为微信公众号与多平台排版设计,支持富文本复制、图片生成与矢量 PDF 导出。
What tools does Bm.md expose?
24 in total: 24 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Bm.md safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Bm.md need?
It reads S3_ACCESS_KEY_ID and S3_SECRET_ACCESS_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (6ec2c3b29970), read on 2026-09-29. The repository is watched and re-audited when it changes.