AgentChatBLOCK
AgentChat 是一个基于 LLM 的智能体交流平台,内置默认 Agent 并支持用户自定义 Agent。通过多轮对话和任务协作,Agent 可以理解并协助完成复杂任务。项目集成 LangChain、Function Call、MCP 协议、RAG、Memory、HITL、Skill、Milvus 和 ElasticSearch 等技术,实现高效的知识检索与工具调用,使用 FastAPI 构建高性能后端服务。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
一个基于大模型的现代化智能对话系统
快速开始 • 部署指南 • 在线文档 • 在线体验 • 加入微信交流群🌟
最新版本更新日志 (2026-4-12)
1. 基于人机协同(HITL)的OpenAPI信息对话式MCP Server生成
- 支持将OpenAPI信息以人机协同方式进行对话式MCP Server生成。
- 在生成MCP Server的过程中,关键决策节点支持人工介入与确认,实现动态配置与实时交互。
- 提升了服务器的生成灵活性与系统可控性,让用户在自动化流程中保留充分的主动权。
2. 优化对话上下文管理
重构对话上下文管理策略,从简单的"最近5段对话"升级为智能三层记忆架构:
- 短期记忆 (Short-Term Memory): 保持最近3000 tokens以内的对话内容,确保即时上下文连贯
- 历史信息总结: 自动总结超过3000 tokens的历史对话,提取关键信息
- 长期记忆 (Long-Term Memory): 持久化记录用户偏好、习惯和重要信息,实现个性化对话体验
3. 修复依赖冲突问题
解决了多个依赖包版本冲突问题,特别是 Pydantic、LangChain、FastAPI 等核心库的兼容性问题,提升系统稳定性。
4. 优化首次启动体验
修复首次启动时缺少模型配置导致的错误,新增配置检查和友好提示,引导用户完成初始化配置,降低使用门槛。
历史版本更新日志 (2026-3-8)
1. 支持MiniO本地对象存储
现在支持OSS和MiniO两种对象存储方式,参考文档: 本地安装MiniO,感谢提供
41b257874beaOBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add agentchat-frontend --env TAVILY_API_KEY=${TAVILY_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"agentchat-frontend": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"TAVILY_API_KEY": "${TAVILY_API_KEY}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_arxiv | read | 为用户提供Arxiv上的论文 |
get_weather | read | 帮助用户想要查询的天气 |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
return pickle.loads(value) if value else None
logger.info(f"sender: {sender}, receiver: {receiver}, emailMessage: {email_message}, password: {password}")# print(f"content: {token.content_blocks}")console.log('Token:', token ? `${token.substring(0, 20)}...` : '无')// console.log('已添加Authorization头:', `Bearer ${token.substring(0, 10)}...`)- **连接地址**: `mysql://agentchat_user:123456@mysql:3306/agentchat`
DATABASE_URL=mysql://agentchat_user:123456@mysql:3306/agentchat
- **连接地址**: `mysql://agentchat_user:123456@mysql:3306/agentchat`
# client = ChatOpenAI(api_key="sk-ChtJNYJD1sm5FqwA7bE8EfFa3eE847Fa9758E5626d64Cc9a", base_url="http://70.182.56.16:11000/v1/", model="Qwen2-72B-Instruct")
client = OpenAI(base_url='http://70.182.56.16:11000/v1/', api_key='sk-ChtJNYJD1sm5FqwA7bE8EfFa3eE847Fa9758E5626d64Cc9a')
model=ChatOpenAI(base_url = "https://dashscope.aliyuncs.com/compatible-mode/v1", api_key = "sk-fc40dd0604f04142a0730793ec74585f", model="qwen-plus"),
requirements.txt
exec(compiled_code)
tmp_str = hashlib.sha1(tmp_str.encode("utf-8")).hexdigest()metadata["hash"] = hashlib.md5(data.encode()).hexdigest()
new_metadata["hash"] = hashlib.md5(data.encode()).hexdigest()
encoded_ids["user_id"] = hashlib.md5(filters["user_id"].encode()).hexdigest()
encoded_ids["agent_id"] = hashlib.md5(filters["agent_id"].encode()).hexdigest()
import { ChatMessage } from '../../type';import { getHistoryMsgAPI } from '../../apis/history';import { HistoryListType } from "../../type"import { getDialogListAPI} from '../../apis/history';http://127.0.0.1:9001/console/buckets/agentchat/admin/prefix
client = OpenAI(base_url='http://70.182.56.16:11000/v1/', api_key='sk-ChtJNYJD1sm5FqwA7bE8EfFa3eE847Fa9758E5626d64Cc9a')
前端应该运行在 `http://127.0.0.1:8090`
Gates applied: no_behavioural_pass.
41b257874beafull audit observations/trust-audit/mcp-server/shy2593666979__agentchat.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | 41b257874bea | BLOCK | F | 55 | first audit |
Questions
What is the AgentChat MCP server?
AgentChat 是一个基于 LLM 的智能体交流平台,内置默认 Agent 并支持用户自定义 Agent。通过多轮对话和任务协作,Agent 可以理解并协助完成复杂任务。项目集成 LangChain、Function Call、MCP 协议、RAG、Memory、HITL、Skill、Milvus 和 ElasticSearch 等技术,实现高效的知识检索与工具调用,使用 FastAPI 构建高性能后端服务。
What tools does AgentChat expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is AgentChat safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does AgentChat need?
It reads TAVILY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does AgentChat run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as agentchat-frontend at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (41b257874bea), read on 2026-09-27. The repository is watched and re-audited when it changes.