CosSAFE
基于 MCP 协议的腾讯云 COS MCP Server,无需编码即可让大模型快速接入腾讯云存储 (COS) 和数据万象 (CI) 能力。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
中文 | English
[](https://www.npmjs.com/package/cos-mcp) [](License.txt)
基于 MCP 协议的腾讯云 COS MCP Server,无需编码即可让大模型快速接入腾讯云存储 (COS) 和数据万象 (CI) 能力。
✨ 核心功能
云端存储能力
- ⬆️ 文件上传到云端
- ⬇️ 文件从云端下载
- 📋 获取云端文件列表
云端处理能力
- 🖼️ 获取图片信息
- 🔍 图片超分辨率
- ✂️ 图片裁剪
- 📲 二维码识别
- 🏆 图片质量评估
- 🅰️ 文字水印
- 🎬 元数据/自然语言检索 (MateInsight)
- 📄 文档转 PDF
- 🎥 视频封面
💡 典型应用场景
- 使用其他 MCP 能力获取的文本/图片/视频/音频等数据,可直接上传到 COS 云端存储。
- 本地数据快速通过大模型转存到 COS 云端存储/备份。
- 通过大模型实现自动化:将网页里的视频/图片/音频/文本等数据批量转存到 COS 云端存储。
- 自动化将视频/图片/音频/文本等数据在云端处理,并转存到 COS 云端存储。
🌟 功能示例
- 上传文件到 COS
- 图片质量评估
- 自然语言检索图片
- 视频截帧
🔧 安装使用
参数说明
为了保护您的数据私密性,请准备以下参数:
1. SecretId / SecretKey
- 说明: 腾讯云 COS 的密钥,用于身份认证,请妥善保管,切勿泄露。
- 获取方式:
- 访问 腾讯云密钥管理。
- 新建密钥并复制生成的 SecretId 和 SecretKey。
2. Bucket
- 示例:
mybucket-123456 - 说明: 存储桶名称,用于存放数据,相当于您的个人存储空间。
- 获取方式:
- 访问 存储桶列表。
- 复制存储桶名称。如果没有存储桶,可点击“创建存储桶”,一般选择默认配置即可快速完成创建。
3. Region
- 示例:
ap-beijing - 说明: 存储桶所在的地域。
- 获取方式:
- 在 存储桶列表 中找到存储桶。
- 在存储桶名称一行查看所属地域并复制,例如:
ap-beijing。
4. DatasetName
- 说明: 非必填参数,数据智能检索操作需要此参数。
- 获取方式:
- 访问 [数据集管理](ht
afc6fe65d1d2OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add cos-mcp -- npx -y [email protected]
{
"mcpServers": {
"cos-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (21)
21 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
aiPicMatting | read | 图片处理-抠图 |
aiQrcode | read | 图片处理-二维码识别-识别存储桶内二维码图片内容 |
aiSuperResolution | read | 图片处理-超分辨率 |
assessQuality | read | 图片处理-图片质量评估 |
createDocToPdfJob | read | 创建文档转 pdf 处理任务 |
createMediaSmartCoverJob | read | 创建媒体智能封面任务 |
describeDocProcessJob | read | 根据 jobid 查询指定的文档转码任务结果 |
describeMediaJob | read | 根据 jobid 查询指定的媒体智能封面任务结果 |
getBucket | read | 查询存储桶内的文件列表 |
getCosConfig | read | 获取COS配置, 腾讯云配置 |
getObject | read | 下载存储桶内的文件 |
getObjectUrl | read | 获取存储桶内的文件的带签名的下载链接 |
imageInfo | read | 图片处理-获取图片信息 |
imageSearchPic | read | 根据输入的图片,从数据集中检索出与输入的图片内容相似的图片 |
imageSearchText | read | 根据输入的文本内容,从数据集中检索出与输入的文本内容相符的图片 |
putBase64 | read | 上传base64编码内容到存储桶 |
putBuffer | read | 上传buffer内容到存储桶 |
putObject | read | 上传本地文件到存储桶 |
putObjectSourceUrl | read | 通过 url下载文件并将文件上传到存储桶 |
putString | read | 上传字符串内容到存储桶 |
waterMarkFont | read | 生成带文字水印的图片 |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
.envTemplate
.eslintrc.js
@modelcontextprotocol/sdk, cos-nodejs-sdk-v5, dotenv, express, yargs, zod, axios, @types/electron
Gates applied: no_behavioural_pass.
afc6fe65d1d2full audit observations/trust-audit/mcp-server/tencent__cos.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | afc6fe65d1d2 | SAFE | B | 89 | first audit |
Questions
What is the Cos MCP server?
基于 MCP 协议的腾讯云 COS MCP Server,无需编码即可让大模型快速接入腾讯云存储 (COS) 和数据万象 (CI) 能力。
What tools does Cos expose?
21 in total: 21 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Cos safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Cos need?
No credential environment variables were found in its source, so it appears to need none.
How does Cos run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as cos-mcp at 1.0.13.
How current is this page?
The grade is for one exact copy of the source (afc6fe65d1d2), read on 2026-10-08. The repository is watched and re-audited when it changes.