Line SummarySAFE
在 Windows 上用 Claude Code 讀本機 LINE 電腦版聊天記錄、產生每日摘要的 MCP server(wxSQLite3/aes128cbc 解密)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
用 Claude Code 讀取本機 LINE 電腦版已儲存的聊天記錄,整理指定聊天室與時間範圍的摘要。適用於 Windows;不是完整聊天備份,也不能證明 LINE 雲端訊息已全部同步。
先了解資料會去哪裡
LINE 程序記憶體 → 本機金鑰提取 → 以唯讀模式解密本機 LINE 資料庫 ↓ MCP 工具結果 ↓ Claude Code → 所選模型供應商 → 摘要
- MCP server 不主動把金鑰寫入檔案、log 或工具回傳值;程式會在存活期間把它保留在記憶體。這不等於「金鑰絕不落地」:作業系統分頁檔、休眠檔、程序或系統傾印仍可能包含記憶體資料,也不保證 Python 記憶體被安全抹除。
- 本機資料庫唯讀,只描述 MCP 的資料存取方式,不代表整個摘要流程離線。聊天室名稱、發言者、訊息、連結及其他工具結果會進入 Claude Code 上下文,依你的模型與服務設定,可能傳送至模型供應商並保留在其紀錄或工作階段中。使用前確認供應商的資料使用與保留政策。
- MCP 的讀取不操作 LINE 畫面、不把對話標為已讀,也不透過 LINE API 送出已讀回條。這項說明不適用於自行打開 LINE 對話或下方的選用捲動工具。
- 只處理自己有權存取及使用的資料。群組裡其他人的訊息不因你能讀取就適合公開、轉寄或上傳。
需要什麼
- Windows,以及正在執行、已登入的 LINE 電腦版。讀取 LINE 程序記憶體使用 Windows API。
- Python 3.11 以上與 Claude Code。
- 對本機資料庫的讀取權限,以及可用的 SQLite3MultipleCiphers 引擎。
原專案曾在 LINE 電腦版 26.3(wxSQLite3 aes128cbc)上測試。LINE 更新後可能需要重新驗證;本次安全修補沒有執行 Windows/真實帳號整合測試。
安裝
建議使用獨立虛擬環境,在一般使用者權限的 PowerShell 執行:
git clone https://github.com/yung13yubabie/line-summary.git cd line-summary py -3 -m venv .venv .\.venv\Scripts\python.exe -m pip install --require-hashes --only-binary=:all: -r requirements.txt
Runtime 相依套件含版本與 hash 鎖定;若目前 Python/Windows 組合沒有對應 wheel,安裝會停止,請先確認支援情況,不要直接關閉 hash 檢查或改從未審閱來源建置。這次修補未驗證 Windows binary 相容性。
將專案 .mcp.json 的 command 改為這個虛擬環境 Python 的絕對路徑;全域註冊時,Python 與 server 都使用絕對路徑。不要因讀取失敗就直接改用系統管理員權限。
先設定最小資料範圍
Server 的本機權限設定在 line_mcp_server.py 同目錄的 settings.json,不是 Claude Code 的 .claude/settings.json。由使用者複製 settings.example.json 並自行編輯;settings.json 已被 Git 忽略,不要加入版本控制或公開分享。
預設 enabled: false、allowed_chat_ids: []、allow_chat_discovery: false、allow_contacts: false,不讀取資料。啟用前:
- 填入自己帳號資料庫的
db_path,建議使用絕對路徑。Server 不再從多個.edb中自動挑選最大檔案,以免讀錯帳號。 - 將
enabled改為true,只在allowed_chat_ids放入需要的明確 ID。允許清單最多 100 個 ID,沒有「全部聊天室」萬用值。 - 若不知道 ID,可暫時開啟
allow_chat_discovery,查找聊天室中繼資料,再加入選定 ID 並關閉探索。探索會把回傳的名稱、I
1af938337f75OBSERVED · 2026-10-08Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
line_get_contacts | read | Paginated contact lookup, disabled unless explicitly enabled locally. |
line_get_history | read | Page local history in [since, until), both ISO 8601 with explicit timezone. |
line_get_unread | read | Unread counts with approximate latest local messages from allowed chats. |
line_list_chats | read | Page through allowed chat metadata; cursor must use the same filters. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
.coveragerc
exec(compile(source, "test_integration.py", "exec"), namespace)
raw = base64.b64decode(token, altchars=b"-_", validate=True)
Gates applied: no_behavioural_pass, no_license.
1af938337f75full audit observations/trust-audit/mcp-server/yung13yubabie__line-summary.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 1af938337f75 | SAFE | B | 89 | first audit |
Questions
What is the Line Summary MCP server?
在 Windows 上用 Claude Code 讀本機 LINE 電腦版聊天記錄、產生每日摘要的 MCP server(wxSQLite3/aes128cbc 解密)
What tools does Line Summary expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Line Summary safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Line Summary need?
No credential environment variables were found in its source, so it appears to need none.
How does Line Summary run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (1af938337f75), read on 2026-10-08. The repository is watched and re-audited when it changes.