Atlas / MCP servers / yfmeii / WeApp Dev

WeApp DevBLOCK

mcp/yfmeii/weapp-dev

FastMCP server for automating WeChat Mini Program developer tooling

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
35 35r · 0w · 0d
Transport
—
License
—
Stars
174
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

基于 FastMCP 的服务器,通过 `miniprogram-automator` 自动化微信开发者工具。该服务器提供 MCP 工具,让 AI 助手能够导航、检查和操作小程序页面——类似于 playwright-mcp,但专为微信生态系统定制。

⚠️ 官方已下场:建议迁移到微信开发者工具 Skill

微信官方已正式推出「微信开发者工具 Skill」并开启公测,可在 Cursor / Claude 等 AI Agent 环境中直接操作开发者工具:打开项目、编译、模拟器、日志排查、预览上传、云开发等,无需在 IDE 与开发者工具之间反复横跳。

为什么建议迁移?

  • 官方维护与版本同步:Skill 随开发者工具 Nightly 发布,与工具能力对齐,不必再维护一套第三方 MCP。
  • 覆盖面更广:不止页面自动化,还包括项目导入、编译构建、真机预览、上传、云环境等。
  • 更贴近真实工作流:Agent 可直接驱动开发者工具完成「写代码 → 编译 → 看模拟器 / 日志 → 预览」闭环。

官方接入(两步)

  1. 升级开发者工具

下载 Nightly Electron Build **2.02.2607032** 及以上。

  1. 安装 Skill(二选一)
  2. 命令行(推荐):终端执行 wechatide,把输出的 Skill 目录交给你的 AI Agent 安装。
  3. 图形界面:开发者工具菜单 → 「导出开发者工具 Skill」 → 导入到 Agent。

macOS 上 Skill 常见路径示例:

/Applications/wechatwebdevtools.app/Contents/Resources/app.asar.unpacked/miniprogram-dev-skill

调用示例(具体以 wechatide / Skill 文档为准):

wechatide                                    # 查看 Skill 路径与可用工具
wechatide -c Cursor -t check_devtools_status # 检查登录与环境

相关链接

前置要求

  • 已安装微信开发者工具,支持命令行访问(cli / cli.bat)
  • 本地已安装 Node.js 18+ 和 npm
  • 有可以在开发者工具中打开的小程序项目

快速开始(npm 包)

@yfme/weapp-dev-mcp 已发布到 npm,普通使用者无需克隆仓库或手动执行 node dist/index.js。

使用 npx 运行

npx -y @yfme/weapp-dev-mcp

安装到项目/全局

npm install -g @yfme/weapp-dev-mcp
weapp-dev-mcp

或作为项目依赖:

npm install --save-dev @yfme/weapp-dev-mcp
npx weapp-dev-mcp
只有在本仓库内开发时,才建议直接运行 node dist/index.js。一般用户请按照以上 npm 包方式启动。

MCP 客户端集成

配置

要在 Claude Desktop 或其他 MCP 客户端中使用此服务器,请在配置文件中添加:

{
"mcpServers": {
"weapp-dev": {
"command": "npx",
"args": [
"-y",
Read from source at commit b1140cd53199OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add weapp-dev-mcp -- npx -y @yfme/[email protected]
claude-desktop
{
  "mcpServers": {
    "weapp-dev-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@yfme/[email protected]"
      ]
    }
  }
}
03

Exposed tools (35)

35 read · 0 write · 0 destructive.

ToolRiskDescription
connect-and-inspect-homereadConnect to the mini program, confirm the current page, then inspect the home page UI.
connect-and-screenshotreadConnect first, then capture a screenshot from the active mini program page.
element_callMethodread调用组件实例指定方法,仅自定义组件可以使用。
element_getAttributesread获取元素的特性值。names 为特性名数组(如 [
element_getBoundingClientRectread获取元素相对于视口的边界矩形信息(left、top、width、height、right、bottom)。此方法返回的是考虑 CSS transform 变换后的实际渲染尺寸和位置。仅支持 ID 选择器、类选择器。若目标元素位于自定义组件内部,selector 必须指向当前页面 WXML 源码中直接引用的那一层自定义组件,而不是渲染后的组件树;innerSelector 可在 selector 所指组件的整个子树内匹配。
element_getDataread获取组件实例渲染数据,仅自定义组件可以使用。
element_getInnerElementread在元素范围内获取元素,相当于 element.$(selector)。设置 withWxml 为 true 可额外返回每个元素的完整 outerWxml。
element_getInnerElementsread在元素范围内获取元素数组,相当于 element.$$(selector)。设置 withWxml 为 true 可额外返回每个元素的完整 outerWxml。
element_getStylesread获取元素的样式值。names 为样式名数组(如 [
element_getWxmlread获取元素 WXML。默认获取内部 WXML(element.wxml()),设置 outer 为 true 可获取包含元素本身的 WXML(element.outerWxml())。
element_inputread向指定元素输入文本。
element_scrollToread滚动 scroll-view 组件到指定位置。仅适用于 scroll-view 组件。
element_setDataread设置组件实例渲染数据,仅自定义组件可以使用。
element_tapread通过 CSS 选择器模拟点击 WXML 元素。支持 [index=N] 语法选择第 N 个元素。如需点击自定义组件内部的元素,请使用 innerSelector 参数:selector 设为组件 ID 选择器(如 #my-component)或标签选择器,innerSelector 设为组件内部元素的选择器。
focusreadOptional UI area to inspect after connecting.
lastErrorreadExact error message returned by the MCP client.
mp_callWxread调用微信小程序 API 方法,(如
mp_currentPageread获取当前页面的信息,包括路径、查询参数、尺寸、滚动位置、当前页面真实渲染器 renderer,以及 wx.getSkylineInfoSync() 的 Skyline 诊断信息 skylineInfo。通常在 mp_ensureConnection 成功后立即调用,用于确认当前页面;可通过 renderer 区分 webview/skyline,skylineInfo 仅用于判断运行环境能力。withData 为 true 时额外返回页面数据。
mp_ensureConnectionread检查小程序自动化会话是否就绪。先调用这个工具,再调用 mp_screenshot、page_* 或 element_* 工具。若失败,优先用 reconnect=true 重试一次;若返回项目选择提示,则传 projectSelection。
mp_getLogsread获取小程序控制台日志。可选择在获取后清空日志。
mp_listProjectsread列出微信开发者工具中的最近项目,方便在 mp_ensureConnection 返回项目选择提示后继续选择项目。
mp_mockWxMethodread有限 mock wx 方法能力。当前仅支持 method=request:action=mock 时按 requestRules mock wx.request 成功响应;action=restore 时恢复 wx.request。未匹配请求默认透传原始 wx.request。
mp_navigateread在小程序内导航,支持 navigateTo、redirectTo、reLaunch、switchTab 和 navigateBack。
mp_screenshotread截取当前小程序视口的截图。需要已有活动会话;若提示没有活动会话,请先调用 mp_ensureConnection。默认返回内联图片,或保存到文件路径。
mp_setDefaultProjectread设置默认的小程序项目路径,设置后下次连接会优先使用该项目。通常用于修复项目选择失败后的后续重试。
page_callMethodread调用当前页面实例上暴露的方法。参数可以作为数组提供。
page_getDataread获取当前页面的数据对象,可选择指定子数据路径。
page_getElementread通过选择器获取页面元素,相当于 page.$(selector)。返回每个元素的摘要信息(tagName、text、value、size、offset);设置 withWxml 为 true 可额外返回元素的完整 outerWxml。支持 [index=N] 语法选择第 N 个元素。
page_getElementByXpathread通过 XPath 获取页面第一个匹配元素,相当于 page.getElementByXpath(xpath) / page.xpath(xpath)。适合按文本、层级关系、ancestor/following 等 XPath 表达式定位元素;设置 withWxml 为 true 可额外返回完整 outerWxml。
page_getElementsread通过选择器获取页面元素数组,相当于 page.$$(selector)。返回每个元素的摘要信息(tagName、text、value、size、offset);设置 withWxml 为 true 可额外返回每个元素的完整 outerWxml。支持 [index=N] 语法选择第 N 个元素。
page_getElementsByXpathread通过 XPath 获取页面匹配元素数组,相当于 page.getElementsByXpath(xpath)。适合按文本、属性、层级关系、位置函数等 XPath 表达式批量定位元素;设置 withWxml 为 true 可额外返回每个元素的完整 outerWxml。
page_setDataread使用 setData 更新当前页面的数据。
page_waitElementread等待指定选择器的元素出现在页面上。支持 [index=N] 语法选择第 N 个元素。增强版:增加了超时和重试间隔参数。
page_waitTimeoutread等待指定的毫秒数。
recover-connectionreadRecover a failed mini program connection using the MCP
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/tools/common.ts:275
const fn = new Function(`return (${source});`)();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, fastmcp, miniprogram-automator, zod, @modelcontextprotocol/inspector, @types/node, tsx, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha b1140cd53199full audit observations/trust-audit/mcp-server/yfmeii__weapp-dev.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06b1140cd53199BLOCKD69first audit
06

Questions

What is the WeApp Dev MCP server?

FastMCP server for automating WeChat Mini Program developer tooling

What tools does WeApp Dev expose?

35 in total: 35 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is WeApp Dev safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does WeApp Dev need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (b1140cd53199), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement