Atlas / MCP servers / tencent / Cos

CosSAFE

mcp/tencent/cos

基于 MCP 协议的腾讯云 COS MCP Server,无需编码即可让大模型快速接入腾讯云存储 (COS) 和数据万象 (CI) 能力。

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
21 21r · 0w · 0d
Transport
sse · stdio
License
NOASSERTION
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

中文 | English

[](https://www.npmjs.com/package/cos-mcp) [](License.txt)

基于 MCP 协议的腾讯云 COS MCP Server,无需编码即可让大模型快速接入腾讯云存储 (COS) 和数据万象 (CI) 能力。

✨ 核心功能

云端存储能力

  • ⬆️ 文件上传到云端
  • ⬇️ 文件从云端下载
  • 📋 获取云端文件列表

云端处理能力

  • 🖼️ 获取图片信息
  • 🔍 图片超分辨率
  • ✂️ 图片裁剪
  • 📲 二维码识别
  • 🏆 图片质量评估
  • 🅰️ 文字水印
  • 🎬 元数据/自然语言检索 (MateInsight)
  • 📄 文档转 PDF
  • 🎥 视频封面

💡 典型应用场景

  • 使用其他 MCP 能力获取的文本/图片/视频/音频等数据,可直接上传到 COS 云端存储。
  • 本地数据快速通过大模型转存到 COS 云端存储/备份。
  • 通过大模型实现自动化:将网页里的视频/图片/音频/文本等数据批量转存到 COS 云端存储。
  • 自动化将视频/图片/音频/文本等数据在云端处理,并转存到 COS 云端存储。

🌟 功能示例

  1. 上传文件到 COS

  1. 图片质量评估

  1. 自然语言检索图片

  1. 视频截帧

🔧 安装使用

参数说明

为了保护您的数据私密性,请准备以下参数:

1. SecretId / SecretKey

  • 说明: 腾讯云 COS 的密钥,用于身份认证,请妥善保管,切勿泄露。
  • 获取方式:
  • 访问 腾讯云密钥管理。
  • 新建密钥并复制生成的 SecretId 和 SecretKey。

2. Bucket

  • 示例: mybucket-123456
  • 说明: 存储桶名称,用于存放数据,相当于您的个人存储空间。
  • 获取方式:
  • 访问 存储桶列表。
  • 复制存储桶名称。如果没有存储桶,可点击“创建存储桶”,一般选择默认配置即可快速完成创建。

3. Region

  • 示例: ap-beijing
  • 说明: 存储桶所在的地域。
  • 获取方式:
  • 在 存储桶列表 中找到存储桶。
  • 在存储桶名称一行查看所属地域并复制,例如:ap-beijing。

4. DatasetName

  • 说明: 非必填参数,数据智能检索操作需要此参数。
  • 获取方式:
  • 访问 [数据集管理](ht
Read from source at commit afc6fe65d1d2OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add cos-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "cos-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (21)

21 read · 0 write · 0 destructive.

ToolRiskDescription
aiPicMattingread图片处理-抠图
aiQrcoderead图片处理-二维码识别-识别存储桶内二维码图片内容
aiSuperResolutionread图片处理-超分辨率
assessQualityread图片处理-图片质量评估
createDocToPdfJobread创建文档转 pdf 处理任务
createMediaSmartCoverJobread创建媒体智能封面任务
describeDocProcessJobread根据 jobid 查询指定的文档转码任务结果
describeMediaJobread根据 jobid 查询指定的媒体智能封面任务结果
getBucketread查询存储桶内的文件列表
getCosConfigread获取COS配置, 腾讯云配置
getObjectread下载存储桶内的文件
getObjectUrlread获取存储桶内的文件的带签名的下载链接
imageInforead图片处理-获取图片信息
imageSearchPicread根据输入的图片,从数据集中检索出与输入的图片内容相似的图片
imageSearchTextread根据输入的文本内容,从数据集中检索出与输入的文本内容相符的图片
putBase64read上传base64编码内容到存储桶
putBufferread上传buffer内容到存储桶
putObjectread上传本地文件到存储桶
putObjectSourceUrlread通过 url下载文件并将文件上传到存储桶
putStringread上传字符串内容到存储桶
waterMarkFontread生成带文字水印的图片
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.envTemplate
.envTemplate
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintrc.js
.eslintrc.js
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, cos-nodejs-sdk-v5, dotenv, express, yargs, zod, axios, @types/electron
Why it matters. 25 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha afc6fe65d1d2full audit observations/trust-audit/mcp-server/tencent__cos.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08afc6fe65d1d2SAFEB89first audit
06

Questions

What is the Cos MCP server?

基于 MCP 协议的腾讯云 COS MCP Server,无需编码即可让大模型快速接入腾讯云存储 (COS) 和数据万象 (CI) 能力。

What tools does Cos expose?

21 in total: 21 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Cos safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Cos need?

No credential environment variables were found in its source, so it appears to need none.

How does Cos run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as cos-mcp at 1.0.13.

How current is this page?

The grade is for one exact copy of the source (afc6fe65d1d2), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement