Atlas / MCP servers / miantiao-me / bm.md

bm.mdSAFE

mcp/miantiao-me/bm-md

更好用的 Markdown 排版助手|专为微信公众号与多平台排版设计,支持富文本复制、图片生成与矢量 PDF 导出。

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
24 24r · 0w · 0d
Transport
—
License
LGPL-3.0
Stars
618
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/miantiao-me/bm.md/actions/workflows/ci.yml) [](https://www.npmjs.com/package/bmmd) [](https://github.com/miantiao-me/bm.md/blob/master/LICENSE) [](https://tanstack.com/start/latest) [](https://ui.shadcn.com/)

Markdown 排版工具,专为微信公众号与多平台排版设计,支持富文本复制、图片生成与矢量 PDF 导出。

✨ 核心特性

  • 专门适配微信排版:一键复制带内联样式的富文本,自动处理链接转脚注、代码块空格保护及移动端表格横向滚动;同时支持复制通用 HTML。
  • 丰富的样式系统:内置 16 款经过细致调校的 Markdown 排版样式(涵盖经典纸质、现代报章、终端、学术等风格)与 14 款代码高亮主题,支持追加自定义 CSS。
  • 图表与信息图集成:支持 Mermaid 流程图与 AntV Infographic 信息图,渲染产物自动进行安全清理并无缝内嵌。
  • 多样化导出能力:基于 snapDOM 生成 PNG/JPEG 图片;集成 Takumi PDF WASM 引擎,直接在浏览器端按 A4 规范分页排版并导出矢量 PDF,支持字体子集下载与缺字降级。
  • 多文件与格式导入:基于 IndexedDB 实现多标签页事务化持久存储;支持直接打开 Markdown,借助 AnyDoc WASM 引擎转换各类文档,并支持在图片导入时调用端侧 PaddleOCR.js 识别并提取纯文本。
  • 三位一体的能力入口:除 Web 交互界面外,所有 Markdown 处理能力均通过统一 Registry 派生为命令行工具(CLI)、REST API 与 MCP(Model Context Protocol)服务。

🚀 快速开始

环境要求

  • 本地开发、构建和应用部署使用 Node.js 24(见 .node-version);npm 发布的 CLI 支持 Node.js >= 20。
  • Node.js 20 已结束维护,建议 CLI 用户也使用 Node.js 24。
  • pnpm 11.26.0

本地运行

# 克隆仓库
git clone https://github.com/miantiao-me/bm.md.git
cd bm.md

# 安装依赖
pnpm install

# 启动本地开发服务(默认端口 2663)
pnpm dev

启动后在浏览器中访问 http://localhost:2663。

生产构建与本地预览:

pnpm build
pnpm preview

环境变量

环境变量均为可选配置,具体可参考 .env.example:

  • VITE_APP_URL、VITE_API_URL:客户端访问的应用基地址与 API 地址。
  • ANALYTICS_SCRIPT_URL、ANALYTICS_SITE_ID:统计分析脚本配置(服务端注入)。
  • S3_ENDPOINT、S3_ACCESS_KEY_ID、S3_SECRET_ACCESS_KEY:三者齐备时启用 S3 兼容对象
Read from source at commit 6ec2c3b29970OBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add bmmd --env S3_ACCESS_KEY_ID=${S3_ACCESS_KEY_ID} --env S3_SECRET_ACCESS_KEY=${S3_SECRET_ACCESS_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "bmmd": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "S3_ACCESS_KEY_ID": "${S3_ACCESS_KEY_ID}",
        "S3_SECRET_ACCESS_KEY": "${S3_SECRET_ACCESS_KEY}"
      }
    }
  }
}
03

Exposed tools (24)

24 read · 0 write · 0 destructive.

ToolRiskDescription
Bauhausread包豪斯风格,几何与功能主义
Blueprintread蓝图技术文档风格
Botanicalread植物园风格,自然柔和
Kamiread简洁的纸张阅读风格(默认)
Newsprintread报纸印刷风格
Retroread复古怀旧风格
Sketchread手绘素描风格
Terminalread终端/命令行风格
bm.mdread更好用的 Markdown 排版助手|一键适配微信公众号、网页与图片。
breaksread将段落内的软换行转换为 HTML 换行
codeThemeread代码块高亮主题 ID
customCssread追加自定义 CSS
customCssFileread从文件追加自定义 CSS
enableFootnoteLinksread关闭文中链接脚注转换
fixread将修复结果写回输入文件;不能与 --output 同时使用
footnoteLabelreadGFM 脚注区域标题
infographicPalettereadInfographic 信息图配色 ID
infographicThemereadInfographic 信息图主题 ID
markdownStylereadMarkdown 排版样式 ID
mermaidThemereadMermaid 流程图主题 ID,留空表示使用默认主题
openLinksInNewWindowread关闭外部链接新窗口打开
outputread输出文件,默认输出到 stdout
platformread目标发布平台
referenceTitleread外部链接参考区域标题
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.cta.json
.cta.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ignore
.ignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/vite/markdown-plugin.ts:9
import remarkHighlight from '../../src/lib/markdown/render/plugins/remark-highlight.ts'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/vite/markdown-plugin.ts:10
import remarkImageDimensions from '../../src/lib/markdown/render/plugins/remark-image-dimensions.ts'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/vite/markdown-plugin.ts:11
import { sanitizeSchema } from '../../src/lib/markdown/render/sanitize-schema.ts'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/index.ts:5
import { description, version } from '../../package.json'
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/lib/pdf/fonts.test.ts:72
expect(() => replaceGraphemes('👨👩👧👦', new Set([0x1F468]), null))
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@antfu/eslint-config, @antv/infographic, @base-ui/react, @catppuccin/highlightjs, @codemirror/commands, @codemirror/lang-markdown, @codemirror/language, @codemirror/language-data
Why it matters. 130 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 6ec2c3b29970full audit observations/trust-audit/mcp-server/miantiao-me__bm-md.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-296ec2c3b29970SAFEB89first audit
06

Questions

What is the Bm.md MCP server?

更好用的 Markdown 排版助手|专为微信公众号与多平台排版设计,支持富文本复制、图片生成与矢量 PDF 导出。

What tools does Bm.md expose?

24 in total: 24 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Bm.md safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Bm.md need?

It reads S3_ACCESS_KEY_ID and S3_SECRET_ACCESS_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (6ec2c3b29970), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement