WeChat DevToolsBLOCK
微信开发者工具 MCP & Skills
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pypi.org/project/wechat-devtools-mcp/) [](https://modelcontextprotocol.io/docs/concepts/mcp-registry) [](https://opensource.org/licenses/MIT) [](./README_EN.md)
把微信开发者工具封装为 MCP 服务,让编辑器里的 AI 直接完成小程序的编译、预览、调试、自动化测试闭环。Windows / macOS,已上架官方 MCP Registry。
[!IMPORTANT] 「瘦 MCP + 胖 Skill」:MCP Server 只提供 7 个聚合工具,操作流程与最佳实践都在配套的 wechat-devtools Skill 里。两者必须一起装。
🤝 与官方能力的关系
微信开发者工具 2.x 自 2026-08-18 起为官方 Stable(1.06 已下架),IDE 内建 MCP Server(47 个原子工具)。两者互补,不是替代:
⚠ 官方 IDE 把自家 bridge 注册为 wechat-devtools。本文示例统一用 `wechat-devtools-mcp` 避免撞名;旧名配置仍可用,只在同一 agent 同时接入两者时才需区分。🚀 快速开始
Step 1 — 安装 MCP Server
pip install uv # 如已装可跳过 uv tool install wechat-devtools-mcp --force wechat-devtools-mcp --version # 确认实际运行版本
[!WARNING] 曾用pip install装过旧版的,先pip uninstall wechat-devtools-mcp,否则旧路径优先于 uv。 ≤0.9.10 与 mcp SDK ≥2.0 不兼容(报ModuleNotFoundError: mcp.server.fastmcp),请升到 ≥0.9.11。
升级前先停掉编辑器里正在跑的 MCP 进程,再 uv tool upgrade wechat-devtools-mcp。
Step 2 — 开启开发者工具服务端口
开发者工具 → 设置 → 安全设置 → 服务端口 → 开启。不开则所有操作报 CLI_TIMEOUT。
Step 3 — 准备两个绝对路径
311251985401OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add wechat-devtools-mcp -- uvx wechat-devtools-mcp==0.9.18
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
fn = new Function('return (' + args.fnSource + ')')();exprFn = new Function('return (' + args.code + '\n)');result.result = await miniProgram.evaluate(new Function(args.code));
开发者工具 2.x(2026-08-18 起为官方 Stable)在 `http://127.0.0.1:<ide_port>/mcp` 内建 MCP Server(47 个原子工具)。`official_mcp.available: true` 且官方 MCP 已接入当前 agent 时:
- `official_mcp`:对 `http://127.0.0.1:<ide_port>/mcp/heartbeat` 做一次只读探测,不发 `initialize`。1.06、IDE 未启动或端口漂移时 `available: false`。
只做一次只读 `GET http://127.0.0.1:<ide_port>/mcp/heartbeat`,不发 `initialize`(那会在 IDE 侧登记授权客户端)。
- `http://127.0.0.1:<port>/__pageframe__/pages/...` — 渲染层 WXML
- `http://127.0.0.1:<port>/appservice/mainframe` — 逻辑层 appService
jimp, miniprogram-automator, puppeteer-core, @vercel/ncc
src/wechat_devtools_mcp/scripts/dist/daemon.bundle.js
Gates applied: no_behavioural_pass.
311251985401full audit observations/trust-audit/mcp-server/watertian__wechat-devtools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 311251985401 | BLOCK | D | 66 | first audit |
Questions
What is the WeChat DevTools MCP server?
微信开发者工具 MCP & Skills
Is WeChat DevTools safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does WeChat DevTools need?
No credential environment variables were found in its source, so it appears to need none.
How does WeChat DevTools run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as wechat-devtools-mcp-scripts at 0.1.4.
How current is this page?
The grade is for one exact copy of the source (311251985401), read on 2026-10-07. The repository is watched and re-audited when it changes.