Atlas / MCP servers / pyptt / PTT

PTTSAFE

mcp/pyptt/ptt

The best PTT MCP server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
29 22r · 7w · 0d
Transport
—
License
BSD-3-Clause
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English Version

PTT MCP Server

The best MCP server for Ptt. Proudly built by PyPtt developer.

📖 專案介紹 (Description)

本專案是一個 PTT MCP (Model Context Protocol) 伺服器,它基於功能強大的 `PyPtt` 函式庫。這使得您的 MCP 客戶端能夠真正登入 PTT 並透過 MCP 協定與 PTT 批踢踢實業坊進行實際互動,並實現自動化操作。

🚀 快速開始 (Quick Start)

使用 Docker 部署 PTT MCP Server 是最推薦的方式,它提供了環境隔離和簡化的設定。

  1. 安裝 Docker:

如果您的系統尚未安裝 Docker,請參考 Docker 官方文件 進行安裝。

  1. 設定 MCP 客戶端:

將以下設定加入您的 MCP 客戶端設定檔 (例如:~/.gemini/settings.json)。此配置會讓 MCP 客戶端在需要時自動拉取並運行 Docker 容器。

{
"mcpServers": {
"PTT": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e", "PTT_ID",
"-e", "PTT_PW",
"ghcr.io/pyptt/ptt_mcp_server:latest"
],
"env": {
"PTT_ID": "YOUR_PTT_ID", // 請換成您自己的 PTT 帳號
"PTT_PW": "YOUR_PTT_PW"  // 請換成您自己的 PTT 密碼
}
}
}
}

說明:

  • "command": "docker": 指示 MCP 客戶端使用 docker 命令來啟動伺服器。
  • "args": 包含 docker run 命令的參數。
  • -i: 保持標準輸入 (stdin) 開啟,以便 MCP 伺服器可以接收指令。
  • --rm: 容器停止後自動刪除,保持系統整潔。
  • -e PTT_ID 和 -e PTT_PW: 告訴 Docker 將 PTT_ID 和 PTT_PW 環境變數傳遞給容器。
  • ghcr.io/pyptt/ptt_mcp_server:latest: 指定要運行的 Docker 映像檔。
  • "env": 將 PTT_ID 和 PTT_PW 直接設定為環境變數。請務必替換為您自己的 PTT 帳號和密碼。

**多帳號設

Read from source at commit 7cd6cda7b334OBSERVED · 2026-10-08
02

Exposed tools (29)

22 read · 7 write · 0 destructive.

ToolRiskDescription
bucketread將指定使用者水桶。
change_pwread更改 PTT 登入密碼。
commentread對文章進行推文、噓文或箭頭。
del_mailread刪除信件。
del_postwrite刪除文章。
get_aid_from_urlread從 PTT 文章網址中解析出看板名稱與文章 AID。
get_all_boardsread取得 PTT 全站看板清單。
get_board_inforead取得看板資訊。
get_board_rulesread
get_bottom_post_listwrite取得看板置底文章清單。
get_favourite_boardsread取得我的最愛看板清單。
get_mailread取得信件。
get_newest_indexread取得最新文章或信箱編號。
get_postwrite從 PTT 取得指定文章。
get_post_index_rangewrite
get_timeread取得 PTT 系統時間。
get_userread取得使用者資訊。
get_versionread
give_moneyread轉帳 Ptt 幣給指定使用者。
list_accountsread列出已在環境變數設定的 PTT 帳號名稱(不含密碼),以及目前登入中的帳號名稱。
loginreadLogs into the PTT service using credentials from environment variables.
logoutreadLogs out from the PTT service.
mailread寄送站內信。
postwrite到看板發佈文章。
reply_postwrite到看板回覆文章。
search_userread搜尋使用者。
set_board_titlewrite設定看板標題。
switch_accountread切換到指定名稱的 PTT 帳號並登入。
whoamiread回傳目前登入中的 PTT 帳號資訊,實際登入狀態直接向 PyPtt 查詢。
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
black, flake8, mypy, flake8-pyproject, types-setuptools, types-requests
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
pyptt, fastmcp
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7cd6cda7b334full audit observations/trust-audit/mcp-server/pyptt__ptt.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087cd6cda7b334SAFEB89first audit
05

Questions

What is the PTT MCP server?

The best PTT MCP server

What tools does PTT expose?

29 in total: 22 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is PTT safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does PTT need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (7cd6cda7b334), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement