Atlas / MCP servers / ying-dao / Yingdao RPA

Yingdao RPACAUTION

mcp/ying-dao/yingdao-rpa

影刀RPA MCP Server

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
7 7r · 0w · 0d
Transport
sse · stdio
License
MIT
Stars
107
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

影刀RPA:一个RPA低代码平台,一款人人可用的RPA自动化产品,能够将人从重复的劳动中解放出来。

影刀AI Power:一个AI低代码平台,能够快速创建AI智能体、AI工作流,帮助用户把AI用起来。

影刀 RPA MCP Server 基于 Model Context Protocol (MCP) 实现,为影刀AI Power及其他可作为MCP Host的工具(如 Claude Desktop、Cursor 等)提供调用RPA的能力。

同时支持SSE Server与Stdio Server两种模式。

如何开始

支持两种方式来运行影刀RPA

本地模式

设置环境变量 注意:本地模式下,智能获取并运行“我获取的应用”并已经被至少执行过一次的应用

RPA_MODEL=local
SHADOWBOT_PATH={your_shadowbot_path} //影刀rpa的exe路径
USER_FOLDER={your_user_folder}       //影刀rpa的用户文件夹路径

影刀RPA的exe路径

Windows 注意:windows下在AI Power客户端中,路径要使用双斜杠

D://Program Files//{安装目录}//ShadowBot.exe

Mac

/Applications/影刀.app

影刀RPA的用户文件夹路径

在影刀RPA的设置中,找用户文件夹选项

开放API模式 (仅支持企业用户)

设置环境变量

RPA_MODEL=openApi
ACCESS_KEY_ID={your_access_key_id}
ACCESS_KEY_SECRET={your_access_key_secret}

获取方式

企业管理员登录影刀RPA控制台获取,请参考影刀RPA帮助文档-鉴权

Stdio Server启动

在客户端中配置

{
"mcpServers": {
"YingDao RPA MCP Server": {
"command": "npx",
"args": ["-y", "yingdao-mcp-server"],
"env":{
"RPA_MODEL":"openApi",
"ACCESS_KEY_ID":"{your_access_key_id}",
"ACCESS_KEY_SECRET":"{your_access_key_secret}"
}
}
}
}

SSE Server配置

构建

Clone the repository and build:

git clone https://github.com/ying-dao/yingdao_mcp_server.git
cd yingdao_mcp_server
npm install
npm run build

配置

添加.env文件,配置项参考以上描述

启动

npm run start:server

客户端配置

AI Power 客户端配置

{
"mcpServers": {
"YingDao RPA MCP Server": {
"url": "http://localhost:3000/sse",
"description": "影刀 MCP Server"
}
}
}

默认端口为3000

能力

本地模式

  1. queryRobotParam: 查询RPA应用的参数
  2. queryApplist: 查询RPA应用的列表
  3. runApp: 运行RPA应用

开放API模式

Read from source at commit 7df4a5eda546OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add yingdao-mcp-server --env ACCESS_KEY_ID=${ACCESS_KEY_ID} --env ACCESS_KEY_SECRET=${ACCESS_KEY_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "yingdao-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ACCESS_KEY_ID": "${ACCESS_KEY_ID}",
        "ACCESS_KEY_SECRET": "${ACCESS_KEY_SECRET}"
      }
    }
  }
}
03

Exposed tools (7)

7 read · 0 write · 0 destructive.

ToolRiskDescription
queryApplistread
queryClientListread
queryJobread
queryRobotParamread
runAppread
startJobread
uploadFileread
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (5)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, cors, dotenv, express, i18next, react-i18next, uuid
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 7df4a5eda546full audit observations/trust-audit/mcp-server/ying-dao__yingdao-rpa.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-077df4a5eda546CAUTIONB83first audit
06

Questions

What is the Yingdao RPA MCP server?

影刀RPA MCP Server

What tools does Yingdao RPA expose?

7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Yingdao RPA safe to connect to an agent?

With care. The audit graded it B (83/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Yingdao RPA need?

It reads ACCESS_KEY_ID and ACCESS_KEY_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Yingdao RPA run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as yingdao-mcp-server at 0.0.2.

How current is this page?

The grade is for one exact copy of the source (7df4a5eda546), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement