Atlas / MCP servers / yzfly / Douyin

DouyinCAUTION

mcp/yzfly/douyin

提取抖音无水印视频链接,视频文案,douyin-mcp-server,mcp,claude skill,支持龙虾

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
5 5r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
1,273
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://badge.fury.io/py/douyin-mcp-server) [](https://pypi.org/project/douyin-mcp-server/) [](https://opensource.org/licenses/Apache-2.0)

从短视频分享链接下载无水印视频,AI 自动提取语音文案。

✨ 功能特性

  • 🎬 无水印视频 - 获取高质量无水印视频下载链接
  • 🎙️ AI 语音识别 - 使用硅基流动 SenseVoice 自动提取文案
  • 📑 大文件支持 - 自动分段处理超过 1 小时或 50MB 的音频
  • 🌐 WebUI - 现代化浏览器界面,无需命令行
  • 🔌 MCP 集成 - 支持 Claude Desktop 等 AI 应用

📦 使用方式

🌐 WebUI (推荐)

最简单的使用方式,打开浏览器即可使用。

快速开始

# 1. 克隆项目
git clone https://github.com/yzfly/douyin-mcp-server.git
cd douyin-mcp-server

# 2. 安装依赖
uv sync

# 3. 启动服务
uv run python web/app.py

打开浏览器访问 http://localhost:8080

配置 API Key

有两种方式配置 API Key:

方式一:浏览器内配置(推荐)

  1. 打开 WebUI 页面
  2. 点击顶部的「API 未配置」按钮
  3. 在弹窗中输入 API Key 并保存
  4. API Key 保存在浏览器本地,刷新页面后仍有效

方式二:环境变量

export API_KEY="sk-xxxxxxxxxxxxxxxx"
uv run python web/app.py
💡 获取免费 API Key:硅基流动(新用户有免费额度)

功能说明

使用步骤

  1. 粘贴链接 - 将分享链接粘贴到输入框
  2. 点击按钮 - 选择「获取信息」或「提取文案」
  3. 查看结果 - 右侧显示视频信息和提取的文案
  4. 导出 - 复制文案或下载 Markdown 文件

🚀 MCP Server

在 Claude Desktop、Cherry St

Read from source at commit 27832f597429OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add douyin-mcp-server --env API_KEY=${API_KEY} --env DASHSCOPE_API_KEY=${DASHSCOPE_API_KEY} --env DOUYIN_API_KEY=${DOUYIN_API_KEY} -- uvx douyin-mcp-server
claude-desktop
{
  "mcpServers": {
    "douyin-mcp-server": {
      "command": "uvx",
      "args": [
        "douyin-mcp-server"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "DASHSCOPE_API_KEY": "${DASHSCOPE_API_KEY}",
        "DOUYIN_API_KEY": "${DOUYIN_API_KEY}"
      }
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
extract_douyin_textread
get_douyin_download_linkread
parse_douyin_video_inforead
recognize_audio_fileread
recognize_audio_urlread
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (5)

MEDIUMInventory / provenance · inv.binary · CWE-1104
douyin-video.skill
douyin-video.skill
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
web/app.py:181
print(f"📝 API_KEY 配置状态: {'已配置' if os.getenv('API_KEY') else '未配置'}")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
douyin-video/SKILL.md:36
export API_KEY="your-siliconflow-api-key"
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
web/templates/index.html:646
// Load API key from localStorage
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:205
| uv | Python 包管理 | `curl -LsSf https://astral.sh/uv/install.sh \| sh` |

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 27832f597429full audit observations/trust-audit/mcp-server/yzfly__douyin.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2527832f597429CAUTIONB88first audit
06

Questions

What is the Douyin MCP server?

提取抖音无水印视频链接,视频文案,douyin-mcp-server,mcp,claude skill,支持龙虾

What tools does Douyin expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Douyin safe to connect to an agent?

With care. The audit graded it B (88/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Douyin need?

It reads API_KEY, DASHSCOPE_API_KEY and DOUYIN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (27832f597429), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement