# io.github.glqff/huaweicloud-devkit

Community preview of HuaweiCloud DevKit MCP server (official: io.github.huaweicloud)

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.1.1
- **Author:** io.github.glqff
- **License:** Unknown
- **Endpoints:** streamable-http https://erx5uqu4-8931.cn-north-4-bridge.myhuaweicloud.com/mcp
- **Source:** https://github.com/huaweicloud/huaweicloud-devkit
- **Endpoint health:** unreachable (last checked 2026-10-01T21:48:13.412Z, 3 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 24 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-11T09:37:30.364Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

39 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `huaweicloud_check_cli` — Check whether Huawei Cloud KooCLI hcloud is installed and whether its version matches the plugin paired version. Returns redacted output.
- `huaweicloud_plan_cli_command` — Classify and plan a Huawei Cloud hcloud command without executing it.
- `huaweicloud_run_readonly_command` — Run a read-only hcloud command through the toolkit safety policy and redact output.
- `huaweicloud_list_operations` — List KooCLI operations for a Huawei Cloud service by running local/read-only hcloud <Service> --help.
- `huaweicloud_run_approved_command` — Run a write-capable hcloud command only after the exact command has been shown and explicitly approved by the user.
- `huaweicloud_show_profile_redacted` — Inspect a KooCLI profile through hcloud configure show and return only redacted output.
- `huaweicloud_hook_check_command` — Check a planned shell or hcloud command against Huawei Cloud hook risk rules without executing it.
- `huaweicloud_hook_check_artifacts` — Check generated code, IaC, policy, or config artifacts against Huawei Cloud hook risk rules.
- `huaweicloud_hook_check_deploy_plan` — Check a structured or textual deployment plan for Huawei Cloud sandbox, exposure, IAM, and cost risks.
- `huaweicloud_service_catalog` — Return the recommended capability sources for Huawei Cloud agent tasks.
- `huaweicloud_explain_error` — Explain a Huawei Cloud CLI, API, SDK, or agent workflow error and suggest next diagnostic steps.
- `huaweicloud_search_docs` — Search across Huawei Cloud SKILL.md files and local documentation. Returns top 10 relevant results with source, name, snippet, and relevance score. Use when the
- `huaweicloud_retrieve_skill` — Retrieve a full SKILL.md by skill name. Returns the complete skill content plus list of reference files. Use when the agent has identified which skill to load a
- `huaweicloud_list_regions` — List available Huawei Cloud regions. Returns region IDs, display names, and endpoints. Use when the agent needs to discover available regions before creating re
- `huaweicloud_get_regional_availability` — Check if a specific Huawei Cloud service is available in a target region. Use before creating resources to prevent failures from regional unavailability.
- `huaweicloud_search_marketplace` — Search the Huawei Cloud agent skill marketplace for available skills. Returns scored results with names, categories, and descriptions. Use when built-in skills 
- `huaweicloud_get_service_icon` — Find the official Huawei Cloud service logo from the Huawei Cloud Icons library (open.huaweicloud.com/openplatform/icons.html). Returns top 5 matches with CDN l
- `huaweicloud_detect_framework` — Scan a local project directory to identify the web framework (React/Vue/Angular/Next.js/Nuxt/VitePress/Docusaurus/Hugo/Hexo/Taro/uni-app), package manager, and 
- `huaweicloud_setup_obs_config` — Synchronize KooCLI credentials to OBS config (~/.obsutilconfig). KooCLI and OBS use separate credential stores — hcloud commands work fine but OBS commands fail
- `huaweicloud_auth_status` — Check unified Huawei Cloud authentication status across the global credential vault, OBS, KooCLI, and all supported agent MCP registrations. Returns only redact
- `huaweicloud_auth_sync` — Synchronize credentials from the global Huawei Cloud credential vault to OBS and report agent registration status. Does not write secrets into any agent config.
- `huaweicloud_auth_init` — Set or clear runtime Huawei Cloud credentials (AK/SK) for this MCP session. Runtime credentials take highest priority over environment variables and config file
- `huaweicloud_auth_switch`
- `huaweicloud_auth_confirm` — Confirm a pending credential reconciliation choice returned by auth_switch persist when S1 already holds a different account (R2). decision=s1 keeps S1 as sourc
- `huaweicloud_sandbox_exec_with_session` — Execute a command on a workspace terminal with session reuse (state persists across calls). Shell state (cd, env vars, aliases) carries over between calls. Use 
- `huaweicloud_sandbox_exec_one_shot` — Execute a command on a workspace terminal with a fresh connection per call (no session state carries over). Each invocation opens a new WebSocket connection, ex
- `huaweicloud_sandbox_close_session` — Close the persistent terminal session for a workspace.
- `huaweicloud_sandbox_upload_file` — Upload a local file into the sandbox workspace. Base64-encodes the file, writes it in small chunks through the terminal session (the exec channel is fragile for
- `huaweicloud_sandbox_upload_project` — Package a local project directory and upload it to a sandbox workspace via HTTP tunnel. Falls back to base64 chunking if tunnel fails. Creates a tar.gz archive,
- `huaweicloud_sandbox_deploy_nginx` — Deploy an nginx configuration on the sandbox and reload. Takes nginxType, port, project, outputDir from framework detection and writes the correct template (SPA
- `huaweicloud_sandbox_deploy_check` — Run a deployment completeness check on the sandbox. Verifies nginx is serving, output directory exists, DevBridge tunnel is active and accessible, and QR code e
- `huaweicloud_sandbox_check_user` — Check if the current user has completed real-name verification and signed the required agreements. Returns 200 {realnameVerified, agreementSigned} when all good
- `huaweicloud_sandbox_sign_agreement`
- `huaweicloud_sandbox_connect`
- `huaweicloud_sandbox_credentials`
- `huaweicloud_voucher_status`
- `huaweicloud_voucher_claim`
- `huaweicloud_check_update`
- `huaweicloud_upgrade`

## Install

**Verdict: review** — Installable, but 3 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
- The hosted endpoint has been failing its liveness check — an install may connect to nothing. — Last checked 2026-10-01T21:48:13.412Z
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"huaweicloud-devkit\": {\n      \"type\": \"http\",\n      \"url\": \"https://erx5uqu4-8931.cn-north-4-bridge.myhuaweicloud.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs commands; 8 privileged tools.
- Floor 46, ceiling 74 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.glqff%2Fhuaweicloud-devkit
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.glqff%2Fhuaweicloud-devkit/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.glqff%2Fhuaweicloud-devkit
- HTML page: https://forgeregistry.com/registry/io.github.glqff%2Fhuaweicloud-devkit
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
