Atlas / MCP servers / shy2593666979 / AgentChat

AgentChatBLOCK

mcp/shy2593666979/agentchat

AgentChat 是一个基于 LLM 的智能体交流平台,内置默认 Agent 并支持用户自定义 Agent。通过多轮对话和任务协作,Agent 可以理解并协助完成复杂任务。项目集成 LangChain、Function Call、MCP 协议、RAG、Memory、HITL、Skill、Milvus 和 ElasticSearch 等技术,实现高效的知识检索与工具调用,使用 FastAPI 构建高性能后端服务。

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
902
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

一个基于大模型的现代化智能对话系统

快速开始 • 部署指南 • 在线文档 • 在线体验 • 加入微信交流群🌟

最新版本更新日志 (2026-4-12)

1. 基于人机协同(HITL)的OpenAPI信息对话式MCP Server生成

  • 支持将OpenAPI信息以人机协同方式进行对话式MCP Server生成。
  • 在生成MCP Server的过程中,关键决策节点支持人工介入与确认,实现动态配置与实时交互。
  • 提升了服务器的生成灵活性与系统可控性,让用户在自动化流程中保留充分的主动权。

2. 优化对话上下文管理

重构对话上下文管理策略,从简单的"最近5段对话"升级为智能三层记忆架构:

  • 短期记忆 (Short-Term Memory): 保持最近3000 tokens以内的对话内容,确保即时上下文连贯
  • 历史信息总结: 自动总结超过3000 tokens的历史对话,提取关键信息
  • 长期记忆 (Long-Term Memory): 持久化记录用户偏好、习惯和重要信息,实现个性化对话体验

3. 修复依赖冲突问题

解决了多个依赖包版本冲突问题,特别是 Pydantic、LangChain、FastAPI 等核心库的兼容性问题,提升系统稳定性。

4. 优化首次启动体验

修复首次启动时缺少模型配置导致的错误,新增配置检查和友好提示,引导用户完成初始化配置,降低使用门槛。

历史版本更新日志 (2026-3-8)

1. 支持MiniO本地对象存储

现在支持OSS和MiniO两种对象存储方式,参考文档: 本地安装MiniO,感谢提供

Read from source at commit 41b257874beaOBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add agentchat-frontend --env TAVILY_API_KEY=${TAVILY_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "agentchat-frontend": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "TAVILY_API_KEY": "${TAVILY_API_KEY}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
get_arxivread为用户提供Arxiv上的论文
get_weatherread帮助用户想要查询的天气
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (9 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/backend/agentchat/services/redis.py:98
return pickle.loads(value) if value else None
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/backend/agentchat/tools/send_email/action.py:45
logger.info(f"sender: {sender}, receiver: {receiver}, emailMessage: {email_message}, password: {password}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/backend/agentchat/utils/extract.py:35
# print(f"content: {token.content_blocks}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/frontend/src/apis/lingseek.ts:21
console.log('Token:', token ? `${token.substring(0, 20)}...` : '无')
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/frontend/src/utils/request.ts:22
// console.log('已添加Authorization头:', `Bearer ${token.substring(0, 10)}...`)
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/reference/agentchat.md:1147
- **连接地址**: `mysql://agentchat_user:123456@mysql:3306/agentchat`
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/reference/agentchat.md:1541
DATABASE_URL=mysql://agentchat_user:123456@mysql:3306/agentchat
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/reference/database.md:11
- **连接地址**: `mysql://agentchat_user:123456@mysql:3306/agentchat`
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/backend/agentchat/test/test_React.py:7
# client = ChatOpenAI(api_key="sk-ChtJNYJD1sm5FqwA7bE8EfFa3eE847Fa9758E5626d64Cc9a", base_url="http://70.182.56.16:11000/v1/", model="Qwen2-72B-Instruct")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/backend/agentchat/test/test_React.py:9
client = OpenAI(base_url='http://70.182.56.16:11000/v1/', api_key='sk-ChtJNYJD1sm5FqwA7bE8EfFa3eE847Fa9758E5626d64Cc9a')
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/backend/agentchat/utils/extract.py:15
model=ChatOpenAI(base_url = "https://dashscope.aliyuncs.com/compatible-mode/v1", api_key = "sk-fc40dd0604f04142a0730793ec74585f", model="qwen-plus"),
LOWInventory / provenance · inv.binary · CWE-1104
src/backend/requirements.txt
requirements.txt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/backend/agentchat/test/test_code.py:10
exec(compiled_code)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/backend/agentchat/api/services/wechat.py:61
tmp_str = hashlib.sha1(tmp_str.encode("utf-8")).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/backend/agentchat/services/memory/client.py:715
metadata["hash"] = hashlib.md5(data.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/backend/agentchat/services/memory/client.py:802
new_metadata["hash"] = hashlib.md5(data.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/backend/agentchat/services/memory/utils.py:127
encoded_ids["user_id"] = hashlib.md5(filters["user_id"].encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/backend/agentchat/services/memory/utils.py:129
encoded_ids["agent_id"] = hashlib.md5(filters["agent_id"].encode()).hexdigest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/frontend/src/store/history_chat_msg/index.ts:3
import { ChatMessage } from '../../type';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/frontend/src/store/history_chat_msg/index.ts:4
import { getHistoryMsgAPI } from '../../apis/history';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/frontend/src/store/history_list/index.ts:3
import { HistoryListType } from "../../type"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/frontend/src/store/history_list/index.ts:4
import { getDialogListAPI} from '../../apis/history';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/development/install_minio_win.md:54
http://127.0.0.1:9001/console/buckets/agentchat/admin/prefix
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/backend/agentchat/test/test_React.py:9
client = OpenAI(base_url='http://70.182.56.16:11000/v1/', api_key='sk-ChtJNYJD1sm5FqwA7bE8EfFa3eE847Fa9758E5626d64Cc9a')
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/frontend/DEBUGGING_GUIDE.md:24
前端应该运行在 `http://127.0.0.1:8090`

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha 41b257874beafull audit observations/trust-audit/mcp-server/shy2593666979__agentchat.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2741b257874beaBLOCKF55first audit
06

Questions

What is the AgentChat MCP server?

AgentChat 是一个基于 LLM 的智能体交流平台,内置默认 Agent 并支持用户自定义 Agent。通过多轮对话和任务协作,Agent 可以理解并协助完成复杂任务。项目集成 LangChain、Function Call、MCP 协议、RAG、Memory、HITL、Skill、Milvus 和 ElasticSearch 等技术,实现高效的知识检索与工具调用,使用 FastAPI 构建高性能后端服务。

What tools does AgentChat expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is AgentChat safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does AgentChat need?

It reads TAVILY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AgentChat run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as agentchat-frontend at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (41b257874bea), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement