Atlas / MCP servers / peterfei / AI Agent Team

AI Agent TeamBLOCK

mcp/peterfei/ai-agent-team

AI Agent Team-拥有24/7专业AI开发团队:产品经理、前端开发、后端开发、测试工程师、DevOps工程师、技术负责人。一键安装,支持中英文命令,大幅提升开发效率!

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
21 17r · 3w · 1d
Transport
stdio
License
MIT
Stars
440
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

💛 Sponsored by DolOffer — GPT & Claude 正版会员充值,输入优惠码 AI8888 享9折特惠

🚀 拥有24/7专业AI开发团队:产品经理、全栈开发、前端开发、后端开发、测试工程师、DevOps工程师、技术负责人

💾 Thread Manager 让 AI 拥有记忆! 语义搜索 | 任务线程管理 | 完整上下文恢复 | 自动 Git 版本控制

⚡ 只需 3 步完成安装 → 马上开始使用!

Agent Skills(独立安装)

这些 Skill 已发布为独立仓库,可通过 skills install 命令安装到任意项目中:

兼容 Claude Code / Cursor / Codex CLI / Gemini CLI / Windsurf 等 50+ 运行时。

🚀 快速开始

✨ 核心特性

  • 🎯 **八大
Read from source at commit 6ea3a1777623OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ai-agent-team --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "ai-agent-team": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GITHUB_TOKEN": "${GITHUB_TOKEN}"
      }
    }
  }
}
03

Exposed tools (21)

17 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
API接口模块read提供RESTful API接口供前端调用
add_messagewriteAdd a message to the current active thread. Use this to record conversation messages.
create_threadwriteCreate a new conversation thread to isolate context for a specific task.
delete_threaddestructiveDelete a thread and all associated data permanently.
get_current_threadreadGet information about the currently active thread.
get_threadreadGet detailed information about a specific thread, optionally including messages and file changes.
list_threadsreadList all conversation threads with filtering and sorting options.
search_messagesreadSemantically searches for relevant messages in the conversation history based on a natural language query.
switch_threadreadSwitch the active context to a specific thread.
track_file_changereadRecord a file change event for the current active thread. If stats are not provided, they will be auto-detected from git.
update_threadwriteUpdate the metadata (title, description, tags) of a thread.
业务逻辑模块read处理核心业务逻辑,实现系统的核心功能
报表统计模块read生成各类统计报表和数据可视化图表
数据处理模块read负责数据的增删改查和业务逻辑处理
数据访问模块read负责数据的存储、检索和管理,确保数据的一致性和完整性
文件管理模块read处理文件上传、下载和存储功能
日志监控模块read记录系统运行日志,提供系统监控和性能分析功能
消息通知模块read实现系统消息推送和邮件通知功能
用户界面模块read负责用户交互和界面展示,提供直观友好的操作界面
用户管理模块read实现用户注册、登录、权限管理等功能
系统配置模块read管理系统配置和参数设置,支持动态配置和热更新
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (8 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
.claude/skills/changelog-generator/src/utils/ConfigLoader.js:62
return yaml.load(content);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
.claude/skills/softcopyright/scripts/auto-print-pdf.js:24
const child = exec(`${command} "${htmlPath}"`, (error) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_thread
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.changelogrc.json
.changelogrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.claude/skills/changelog-generator/src/exporters/HTMLExporter.js:440
{{{prLink this ../../../config.template.prUrl}}}
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.claude/skills/changelog-generator/src/exporters/HTMLExporter.js:465
{{{prLink this ../../../config.template.prUrl}}}
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.claude/skills/changelog-generator/tests/unit/ChangelogGenerator.test.js:1
const ChangelogGenerator = require('../../src/core/ChangelogGenerator');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.claude/skills/changelog-generator/tests/unit/CommitClassifier.test.js:1
const CommitClassifier = require('../../src/core/CommitClassifier');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.claude/skills/changelog-generator/tests/unit/GitAnalyzer.test.js:1
const GitAnalyzer = require('../../src/core/GitAnalyzer');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.claude/skills/changelog-generator/package.json
@octokit/rest, chalk, commander, conventional-commits-parser, dotenv, handlebars, inquirer, js-yaml
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.claude/skills/drawnote/package.json
playwright
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.claude/skills/softcopyright/package.json
pdfkit, pdfkit-table, glob, commander, chalk, inquirer, fs-extra, path
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.claude/skills/thread-manager/package.json
@modelcontextprotocol/sdk, @xenova/transformers, better-sqlite3, date-fns, fs-extra, simple-git, uuid, zod
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.claude/skills/tidymydesktop/package.json
fs-extra, glob, semver, commander
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
.claude/skills/thread-manager/models/Xenova/all-MiniLM-L6-v2/onnx/model_quantized.onnx
.claude/skills/thread-manager/models/Xenova/all-MiniLM-L6-v2/onnx/model_quantized.onnx
Why it matters. 22972370 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
drawnote_20251111_172200_2x2.png
drawnote_20251111_172200_2x2.png
Why it matters. 2925958 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
drawnote_ai_agent_team_v1.0.2.png
drawnote_ai_agent_team_v1.0.2.png
Why it matters. 1692015 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
examples/softcopyright.gif
examples/softcopyright.gif
Why it matters. 5402520 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
examples/tidymydesktop.png
examples/tidymydesktop.png
Why it matters. 1044590 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 6ea3a1777623full audit observations/trust-audit/mcp-server/peterfei__ai-agent-team.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-016ea3a1777623BLOCKD69first audit
06

Questions

What is the AI Agent Team MCP server?

AI Agent Team-拥有24/7专业AI开发团队:产品经理、前端开发、后端开发、测试工程师、DevOps工程师、技术负责人。一键安装,支持中英文命令,大幅提升开发效率!

What tools does AI Agent Team expose?

21 in total: 17 read-only, 3 that write, and 1 that can delete or overwrite (delete_thread). Every one is listed on this page with its risk.

Is AI Agent Team safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does AI Agent Team need?

It reads GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AI Agent Team run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as ai-agent-team at 2.1.0.

How current is this page?

The grade is for one exact copy of the source (6ea3a1777623), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement