Atlas / MCP servers / xvhuan / Xiaoi

XiaoiCAUTION

mcp/xvhuan/xiaoi

小爱音箱语音通知工具:提供 CLI/TUI/MCP/Webhook 一键播报与控制音量,支持 PM2 常驻部署,支持docker部署。

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
5 4r · 1w · 0d
Transport
stdio
License
MIT
Stars
204
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

██╗  ██╗██╗ █████╗  ██████╗ ██╗
╚██╗██╔╝██║██╔══██╗██╔═══██╗██║
╚███╔╝ ██║███████║██║   ██║██║
██╔██╗ ██║██╔══██║██║   ██║██║
██╔╝ ██╗██║██║  ██║╚██████╔╝██║
╚═╝  ╚═╝╚═╝╚═╝  ╚═╝ ╚═════╝ ╚═╝

小爱音箱语音通知工具

通过 CLI / TUI / MCP / Webhook 向小爱音箱发送语音通知

[](https://nodejs.org/) [](LICENSE) [](https://www.npmjs.com/package/xiaoii)

功能

  • TUI 交互界面:配置账号、发送通知、管理 Webhook/PM2
  • CLI 命令:适合脚本/自动化场景
  • MCP Server:供 Codex/Cursor/VS Code 等 AI 编程助手调用
  • Webhook 服务:提供 HTTP 接口,方便第三方系统集成
  • 多音箱路由:支持维护音箱列表、设置默认音箱、按请求 did 临时覆盖
  • PM2 常驻:一键后台运行 Webhook(不需要挂着终端)

更新日志

v1.0.10 (2026-02-14)

  • 新增多音箱路由能力:支持 speaker.defaultDid 与 speaker.speakers,并兼容旧 speaker.did
  • Webhook 四个接口支持 body 传 did(tts/audio/volume/command),不传按默认优先级路由
  • 新增 TUI「音箱列表管理」:支持添加设备、设置默认、启用/禁用、删除
  • 新增 CLI MiOT 能力:xiaoi command(动作)与 xiaoi getprop(属性读取)
  • 新增 MCP 工具:do_action 与 get_property,并统一支持可选 did
  • Docker/文档更新:新增 XIAOI_DEFAULT_DID 与 OH2P(xiaomi.wifispeaker.oh2p)简单 cmd 用例

v1.0.9 (2026-02-14)

  • 修复 .mi.json(登录凭证缓存)在任意目录执行 CLI 时被写到当前目录的问题,现在固定写入 ~/.xiaoi/ 目录

v1.0.8 (2026-02-12)

  • 修复 Docker 容器启动失败:移除 pm2-runtime 不支持的 --log-date-format 参数
  • 修复 Docker 构建失败:npm ci 改为 npm install(兼容 pnpm 项目)
  • 文档补充 XIAOI_TOKEN 环境变量示例,方便用户自定义 Webhook 鉴权 Token

v1.0.7 (2026-02-12)

  • 新增 Docker 容器化部署:支持通过环境变量配置,无需手动编辑配置文件,一行命令即可启动 Webhook 服务
  • 新增 GitHub Actions CI/CD:打 tag 自动发布 npm 包 + 构建推送 Docker 镜像(Docker Hub + GHCR,支持 amd64/arm64 双架构)
  • 新增 .env.example 环境变量模板,降低 Docker 部署门槛
  • 容器内使用 PM2(pm2-runtime)管理进程,自动健康检查与重启

v1.0.6 (2026-02-12)

  • 修复 ttscmd 输入解析错误:[7,3] 不再被误解析为 [0,7]
  • 优化账号设置显示:默认 ttscmd 未设置时,自动显示当前 did 解析出的设备命令(自动映射)

v1.0.5 (2026-02-12)

  • 新增 ttscmd 自动映射日志输出:显示 model / match / source / command
  • 详细日志统一增加 [XIAOI]
Read from source at commit db3cd6cd8f34OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add xiaoii --env XIAOI_WEBHOOK_TOKEN=${XIAOI_WEBHOOK_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "xiaoii": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "XIAOI_WEBHOOK_TOKEN": "${XIAOI_WEBHOOK_TOKEN}"
      }
    }
  }
}
03

Exposed tools (5)

4 read · 1 write · 0 destructive.

ToolRiskDescription
do_actionread向小爱音箱发送 MiOT 指令。
get_propertyread读取小爱音箱 MiOT 属性值。
notifyread向小爱音箱发送语音通知。适用于任务完成通知、提醒、警告等场景。音箱会用 TTS 播报传入的文字内容。
play_audioread让小爱音箱播放指定的音频链接。
set_volumewrite设置小爱音箱的音量。
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
bin/xiaoi.js:313
console.log(`🔐 已生成 webhook.token: ${config.webhook.token}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
docker-entrypoint.sh:139
console.log('║  Webhook Token: ' + (cfg.webhook.token ? cfg.webhook.token.substring(0, 8) + '...' : '无').padEnd(28) + '║');
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
lib/tui.js:636
print(`\n  ${c.red}❌ 请先填写 userId 和 passToken(或 password)${c.reset}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
lib/tui.js:1746
print(`\n  ${c.bold}🔐 Webhook Token${c.reset}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
lib/tui.js:1747
print(`  ${c.dim}用于 Webhook 鉴权:Authorization: Bearer <token> 或 X-Xiaoi-Token${c.reset}`);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@mi-gpt/next, @modelcontextprotocol/sdk, zod
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha db3cd6cd8f34full audit observations/trust-audit/mcp-server/xvhuan__xiaoi.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06db3cd6cd8f34CAUTIONB88first audit
06

Questions

What is the Xiaoi MCP server?

小爱音箱语音通知工具:提供 CLI/TUI/MCP/Webhook 一键播报与控制音量,支持 PM2 常驻部署,支持docker部署。

What tools does Xiaoi expose?

5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Xiaoi safe to connect to an agent?

With care. The audit graded it B (88/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Xiaoi need?

It reads XIAOI_WEBHOOK_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Xiaoi run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as xiaoii at 1.0.10.

How current is this page?

The grade is for one exact copy of the source (db3cd6cd8f34), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement