Atlas / MCP servers / watertian / WeChat DevTools

WeChat DevToolsBLOCK

mcp/watertian/wechat-devtools

微信开发者工具 MCP & Skills

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
150
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/wechat-devtools-mcp/) [](https://modelcontextprotocol.io/docs/concepts/mcp-registry) [](https://opensource.org/licenses/MIT) [](./README_EN.md)

把微信开发者工具封装为 MCP 服务,让编辑器里的 AI 直接完成小程序的编译、预览、调试、自动化测试闭环。Windows / macOS,已上架官方 MCP Registry。
[!IMPORTANT] 「瘦 MCP + 胖 Skill」:MCP Server 只提供 7 个聚合工具,操作流程与最佳实践都在配套的 wechat-devtools Skill 里。两者必须一起装。

🤝 与官方能力的关系

微信开发者工具 2.x 自 2026-08-18 起为官方 Stable(1.06 已下架),IDE 内建 MCP Server(47 个原子工具)。两者互补,不是替代:

⚠ 官方 IDE 把自家 bridge 注册为 wechat-devtools。本文示例统一用 `wechat-devtools-mcp` 避免撞名;旧名配置仍可用,只在同一 agent 同时接入两者时才需区分。

🚀 快速开始

Step 1 — 安装 MCP Server

pip install uv                                  # 如已装可跳过
uv tool install wechat-devtools-mcp --force
wechat-devtools-mcp --version                   # 确认实际运行版本
[!WARNING] 曾用 pip install 装过旧版的,先 pip uninstall wechat-devtools-mcp,否则旧路径优先于 uv。 ≤0.9.10 与 mcp SDK ≥2.0 不兼容(报 ModuleNotFoundError: mcp.server.fastmcp),请升到 ≥0.9.11。

升级前先停掉编辑器里正在跑的 MCP 进程,再 uv tool upgrade wechat-devtools-mcp。

Step 2 — 开启开发者工具服务端口

开发者工具 → 设置 → 安全设置 → 服务端口 → 开启。不开则所有操作报 CLI_TIMEOUT。

Step 3 — 准备两个绝对路径

Read from source at commit 311251985401OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add wechat-devtools-mcp -- uvx wechat-devtools-mcp==0.9.18
03

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (7 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/wechat_devtools_mcp/scripts/ui_debug.js:154
fn = new Function('return (' + args.fnSource + ')')();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/wechat_devtools_mcp/scripts/ui_debug.js:187
exprFn = new Function('return (' + args.code + '\n)');
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/wechat_devtools_mcp/scripts/ui_debug.js:195
result.result = await miniProgram.evaluate(new Function(args.code));
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.agents/skills/wechat-devtools/SKILL.md:52
开发者工具 2.x(2026-08-18 起为官方 Stable)在 `http://127.0.0.1:<ide_port>/mcp` 内建 MCP Server(47 个原子工具)。`official_mcp.available: true` 且官方 MCP 已接入当前 agent 时:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.agents/skills/wechat-devtools/references/tool_reference.md:86
- `official_mcp`:对 `http://127.0.0.1:<ide_port>/mcp/heartbeat` 做一次只读探测,不发 `initialize`。1.06、IDE 未启动或端口漂移时 `available: false`。
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
MCP_DOC.md:70
只做一次只读 `GET http://127.0.0.1:<ide_port>/mcp/heartbeat`,不发 `initialize`(那会在 IDE 侧登记授权客户端)。
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/macos-internals.md:53
- `http://127.0.0.1:<port>/__pageframe__/pages/...` — 渲染层 WXML
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/macos-internals.md:54
- `http://127.0.0.1:<port>/appservice/mainframe` — 逻辑层 appService
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/wechat_devtools_mcp/scripts/package.json
jimp, miniprogram-automator, puppeteer-core, @vercel/ncc
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
src/wechat_devtools_mcp/scripts/dist/daemon.bundle.js
src/wechat_devtools_mcp/scripts/dist/daemon.bundle.js
Why it matters. 2474316 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 311251985401full audit observations/trust-audit/mcp-server/watertian__wechat-devtools.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07311251985401BLOCKD66first audit
05

Questions

What is the WeChat DevTools MCP server?

微信开发者工具 MCP & Skills

Is WeChat DevTools safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does WeChat DevTools need?

No credential environment variables were found in its source, so it appears to need none.

How does WeChat DevTools run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as wechat-devtools-mcp-scripts at 0.1.4.

How current is this page?

The grade is for one exact copy of the source (311251985401), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement