Yingdao RPACAUTION
影刀RPA MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
影刀RPA:一个RPA低代码平台,一款人人可用的RPA自动化产品,能够将人从重复的劳动中解放出来。
影刀AI Power:一个AI低代码平台,能够快速创建AI智能体、AI工作流,帮助用户把AI用起来。
影刀 RPA MCP Server 基于 Model Context Protocol (MCP) 实现,为影刀AI Power及其他可作为MCP Host的工具(如 Claude Desktop、Cursor 等)提供调用RPA的能力。
同时支持SSE Server与Stdio Server两种模式。
如何开始
支持两种方式来运行影刀RPA
本地模式
设置环境变量 注意:本地模式下,智能获取并运行“我获取的应用”并已经被至少执行过一次的应用
RPA_MODEL=local
SHADOWBOT_PATH={your_shadowbot_path} //影刀rpa的exe路径
USER_FOLDER={your_user_folder} //影刀rpa的用户文件夹路径影刀RPA的exe路径
Windows 注意:windows下在AI Power客户端中,路径要使用双斜杠
D://Program Files//{安装目录}//ShadowBot.exeMac
/Applications/影刀.app
影刀RPA的用户文件夹路径
在影刀RPA的设置中,找用户文件夹选项
开放API模式 (仅支持企业用户)
设置环境变量
RPA_MODEL=openApi
ACCESS_KEY_ID={your_access_key_id}
ACCESS_KEY_SECRET={your_access_key_secret}获取方式
企业管理员登录影刀RPA控制台获取,请参考影刀RPA帮助文档-鉴权
Stdio Server启动
在客户端中配置
{
"mcpServers": {
"YingDao RPA MCP Server": {
"command": "npx",
"args": ["-y", "yingdao-mcp-server"],
"env":{
"RPA_MODEL":"openApi",
"ACCESS_KEY_ID":"{your_access_key_id}",
"ACCESS_KEY_SECRET":"{your_access_key_secret}"
}
}
}
}SSE Server配置
构建
Clone the repository and build:
git clone https://github.com/ying-dao/yingdao_mcp_server.git cd yingdao_mcp_server npm install npm run build
配置
添加.env文件,配置项参考以上描述
启动
npm run start:server
客户端配置
AI Power 客户端配置
{
"mcpServers": {
"YingDao RPA MCP Server": {
"url": "http://localhost:3000/sse",
"description": "影刀 MCP Server"
}
}
}默认端口为3000
能力
本地模式
- queryRobotParam: 查询RPA应用的参数
- queryApplist: 查询RPA应用的列表
- runApp: 运行RPA应用
开放API模式
7df4a5eda546OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add yingdao-mcp-server --env ACCESS_KEY_ID=${ACCESS_KEY_ID} --env ACCESS_KEY_SECRET=${ACCESS_KEY_SECRET} -- npx -y [email protected]{
"mcpServers": {
"yingdao-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ACCESS_KEY_ID": "${ACCESS_KEY_ID}",
"ACCESS_KEY_SECRET": "${ACCESS_KEY_SECRET}"
}
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
queryApplist | read | |
queryClientList | read | |
queryJob | read | |
queryRobotParam | read | |
runApp | read | |
startJob | read | |
uploadFile | read |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (5)
.env
.DS_Store
.env
.DS_Store
@modelcontextprotocol/sdk, axios, cors, dotenv, express, i18next, react-i18next, uuid
Gates applied: no_behavioural_pass.
7df4a5eda546full audit observations/trust-audit/mcp-server/ying-dao__yingdao-rpa.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 7df4a5eda546 | CAUTION | B | 83 | first audit |
Questions
What is the Yingdao RPA MCP server?
影刀RPA MCP Server
What tools does Yingdao RPA expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Yingdao RPA safe to connect to an agent?
With care. The audit graded it B (83/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Yingdao RPA need?
It reads ACCESS_KEY_ID and ACCESS_KEY_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Yingdao RPA run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as yingdao-mcp-server at 0.0.2.
How current is this page?
The grade is for one exact copy of the source (7df4a5eda546), read on 2026-10-07. The repository is watched and re-audited when it changes.