Atlas / MCP servers / todieornot / Xiaohongshu

XiaohongshuSAFE

mcp/todieornot/xiaohongshu-4

企业级小红书MCP Node.js重构 - 支持多账号矩阵管理、反风控、数据采集与发布

Verdict
SAFE
Grade
B
Trust score
87 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
—
Stars
79
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

基于现代化Node.js技术栈的小红书MCP(Model Context Protocol)服务器,提供企业级多账号矩阵管理和反风控功能。 暂停维护

🌟 核心特性

🔐 多账号管理

  • 无限账号支持:支持无限数量的小红书账号管理
  • 独立环境:每个账号使用独立的浏览器指纹和代理环境
  • 状态监控:实时监控账号登录状态和健康状况
  • Cookie管理:自动维护登录状态,支持Cookie持久化

🛡️ 反风控系统

  • 浏览器指纹伪造:完整的UA、硬件、地理位置模拟
  • 行为模拟:智能鼠标轨迹、键盘输入、页面滚动
  • 特征清理:移除WebDriver、CDP等自动化检测特征
  • 代理轮换:支持HTTP/SOCKS5代理池,智能轮换

🚀 任务调度

  • 并发执行:支持多任务并发执行,可配置并发数
  • 定时任务:基于Cron表达式的定时任务调度
  • 重试机制:智能重试和失败恢复
  • 任务监控:实时任务状态追踪和历史记录

📊 数据采集

  • 内容搜索:关键词搜索、话题搜索、用户搜索
  • 笔记详情:获取完整的笔记内容和互动数据
  • 用户信息:获取用户基本信息和统计数据
  • 评论采集:获取笔记评论和互动信息
  • 热门内容:获取各分类热门内容

🎛️ 管理后台

  • Web界面:基于Express.js的现代化管理界面
  • 实时监控:实时任务状态、系统资源监控
  • 数据可视化:图表展示账号数据、任务统计
  • 配置管理:可视化配置代理、指纹、任务参数

🏗️ 技术架构

┌─────────────────────────────────────────────────────────────────┐
│                        系统架构总览                              │
└─────────────────────────────────────────────────────────────────┘

┌─────────────────┐    ┌─────────────────┐    ┌─────────────────┐
│   AI客户端群    │    │   API网关层     │    │   小红书平台     │
│ Claude/Cursor   │◄──►│  Express+MCP    │◄──►│  多账号并发      │
│ VSCode/CLI工具  │    │  WebSocket      │    │  自动化操作      │
└─────────────────┘    └─────────────────┘    └─────────────────┘
│
┌───────────────┼───────────────┐
▼               ▼               ▼
┌─────────────┐ ┌─────────────┐ ┌─────────────┐
│ Directus    │ │   MySQL     │ │ 反风控引擎   │
│ 管理后台    │ │  数据中心   │ │ Stealth+    │
│ (零配置)    │ │ (统一前缀)  │ │ Fingerprint │
└─────────────┘ └─────────────┘ └─────────────┘
│               │               │
└───────────────┼───────────────┘
▼
┌─────────────────────────────────────────────────┐
│              浏览器实例池                        │
Read from source at commit 3795efa4b15eOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add xiaohongshu-mcp-nodejs --env CORS_CREDENTIALS=${CORS_CREDENTIALS} --env DB_PASSWORD=${DB_PASSWORD} --env EMAIL_PASS=${EMAIL_PASS} --env FILTER_EXCLUDE_KEYWORDS=${FILTER_EXCLUDE_KEYWORDS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "xiaohongshu-mcp-nodejs": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CORS_CREDENTIALS": "${CORS_CREDENTIALS}",
        "DB_PASSWORD": "${DB_PASSWORD}",
        "EMAIL_PASS": "${EMAIL_PASS}",
        "FILTER_EXCLUDE_KEYWORDS": "${FILTER_EXCLUDE_KEYWORDS}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
xiaohongshu-mcpread小红书多账号管理MCP服务器
04

Trust audit

SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/core/fingerprint-generator.js:201
const hash = crypto.createHash('md5');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/core/fingerprint-generator.js:216
const hash = crypto.createHash('md5');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/utils/file.js:466
const hash = crypto.createHash('md5');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/mcp-manager.js:838
version: require('../../package.json').version,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/utils/logger.js:44
this.logDir = join(__dirname, '../../logs');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/web/app.js:81
version: require('../../package.json').version
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/web/routes/admin.js:10
const logger = require('../../utils/logger');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/web/routes/admin.js:287
version: require('../../../package.json').version
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
express, socket.io, playwright, playwright-extra, puppeteer-extra-plugin-stealth, ghost-cursor, mysql2, redis
Why it matters. 48 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 3795efa4b15efull audit observations/trust-audit/mcp-server/todieornot__xiaohongshu-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-073795efa4b15eSAFEB87first audit
06

Questions

What is the Xiaohongshu MCP server?

企业级小红书MCP Node.js重构 - 支持多账号矩阵管理、反风控、数据采集与发布

What tools does Xiaohongshu expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Xiaohongshu safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Xiaohongshu need?

It reads CORS_CREDENTIALS, DB_PASSWORD, EMAIL_PASS, FILTER_EXCLUDE_KEYWORDS, FILTER_KEYWORDS, KEYBOARD_RANDOMNESS, KEYBOARD_SIMULATION, KEYBOARD_SPEED, MCP_AUTH_ENABLED, MCP_AUTH_SECRET, MCP_TOKEN_EXPIRY and OSS_ACCESS_KEY_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (3795efa4b15e), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement