WeLinkCAUTION
🔍微信聊天数据分析的本地化AI-agent(Docker/Windows/MacOS) · AI分身 / 大模型分析 / 好友排行 / 词云 / 情感趋势 / 群聊画像
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
WeLink
AI 驱动的微信聊天数据分析平台
官方文档 · 在线 Demo
你的微信聊天记录里,藏着你和每个人关系最真实的样子。WeLink 把这些数据交给 AI 来读——不只是统计图表,而是能让你直接提问、得到洞察:
「我和 XXX 的关系在哪个阶段最好?后来发生了什么?」 「这个群里真正活跃的人是谁?他们通常聊什么?」 「我今年和哪些朋友聊得越来越少了?」
所有数据留在本地,不上传任何服务器。
功能示例
点击可放大查看
aaa379b7adedOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add welink-frontend -- npx -y [email protected]
{
"mcpServers": {
"welink-frontend": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
关系剧本 | read | 把一段关系浓缩成 3-5 个剧情节点的时间线 |
关系报告 | read | 分析两人关系的发展阶段、沟通特点和关键数字 |
风格画像 | read | 提炼联系人的性格标签、口头禅和聊天习惯 |
Trust audit
CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (18)
AppIcon.icns
return "http://127.0.0.1:" + port
"private_key": "-----BEGIN PRIVATE KEY-----\nMIIE...\n-----END PRIVATE KEY-----\n",
<div id="video-overlay" onclick="this.style.display='none';this.querySelector('video').src=''" style="display:none;position:fixed;inset:0;z-index:999;background:rgba(0,0,0,.85);cursor:zoom-out;justify.mailmap
import type { ContactStats, DetectedEvent, FriendMilestone, CustomAnniversary, AnniversaryResponse } from '../../types';import { anniversaryApi } from '../../services/api';import { usePrivacyMode } from '../../contexts/PrivacyModeContext';import { avatarSrc } from '../../utils/avatar';import { calendarApi } from '../../services/api';{"169.254.169.254", true},proxy_pass http://127.0.0.1:8080;
proxy_pass http://127.0.0.1:8080;
| `WELINK_PUBLIC_URL` | — | 反代场景下显式指定公网 base URL(如 `https://welink.example.com`),用于构造 Google Drive / OneDrive OAuth 回调地址。**不设置时默认用 `http://127.0.0.1:<PORT>`**,反代部署时不设就会拿不到 token。不再读取 `X-Forwarded-*` 请
proxy_pass http://127.0.0.1:3418;
medium-zoom, vitepress
@tailwindcss/typography, @types/marked, axios, html2canvas, lucide-react, marked, qrcode, react
curl -fsSL https://ollama.com/install.sh | sh
Gates applied: no_behavioural_pass.
aaa379b7adedfull audit observations/trust-audit/mcp-server/runzhliu__welink.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | aaa379b7aded | CAUTION | B | 84 | first audit |
Questions
What is the WeLink MCP server?
🔍微信聊天数据分析的本地化AI-agent(Docker/Windows/MacOS) · AI分身 / 大模型分析 / 好友排行 / 词云 / 情感趋势 / 群聊画像
What tools does WeLink expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is WeLink safe to connect to an agent?
With care. The audit graded it B (84/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does WeLink need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (aaa379b7aded), read on 2026-10-06. The repository is watched and re-audited when it changes.