v1.8 · Python 3.10+ · React 18 · SQLite WAL · MCP 13 tools · GPL-3.0
SecNews(开发代号
hotspot)是面向 AI + 安全从业者 的单人本地工作站。 把每天的「热点聚合 → 知识沉淀 → 项目管理 → AI 协作」合并到一台机器, 通过 MCP 协议 开放 13 个工具 给 Cursor / Claude Desktop / Trae 等外部 AI Agent。一个人 · 一台电脑 · 零外部服务。
| # | 子系统 | 解决什么 | 入口 |
|---|---|---|---|
| 01 | SecNews 热点聚合 | 7 大领域 · 30+ 数据源 · 13 质量门禁 | / |
| 02 | Knowledge LLM-Wiki | 4 层金字塔 (items → concepts → learning → content) | /knowledge |
| 03 | CodeGarden | 项目全生命周期 + 服务网格 + 资源中枢 + 联动引擎 | /codegarden |
| 04 | Security Graph | MITRE ATT&CK · NVD CVE · 等保 2.0 / 关基 / 数安法 | /security |
| 05 | MCP Server | 13 个标准工具 · stdio / SSE · 零状态 | python -m backend.mcp_stdio_main |
git clone https://github.com/anyeduke11/secnews.git && cd secnews
# 后端
python -m venv .venv && source .venv/bin/activate
pip install -r backend/requirements.txt
python run.py # http://127.0.0.1:8000
# 前端 (另一个终端)
cd frontend && npm install && npm run dev # http://localhost:8898首装必做:编辑 backend/proxy_config.json 把 127.0.0.1:7897 改成你的代理端口(默认模式 off)。
security_collector 和 github_collector 走代理才能拿到数据;可不改,前端设置页可运行时改。
13 个标准工具,外部 AI Agent 自动发现:
| 读 (5) | 写 (8) |
|---|---|
search_hotspots · get_hotspot · list_favorites |
add_favorite · remove_favorite · add_annotation |
search_knowledge · get_personal_profile |
update_knowledge_item · trigger_extract_tags · trigger_cubox_sync |
create_alert_rule · mark_digest_read |
stdio 配置(粘到你的 AI Agent 配置文件):
{
"mcpServers": {
"hotspot": {
"command": "python",
"args": ["-m", "backend.mcp_stdio_main"],
"cwd": "/绝对路径/secnews"
}
}
}| AI Agent | 配置文件路径 |
|---|---|
| Claude Desktop | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Trae | ~/.trae/mcp_config.json |
| Cursor | ~/.cursor/mcp.json |
| Claude Code | 项目根目录 .mcp.json |
启动 AI Agent 后直接说「给我列最近 24h 的安全热点」即可。
| 组件 | 选型 | 理由 |
|---|---|---|
| Web 框架 | FastAPI | async + OpenAPI 生态成熟 |
| 主存储 | SQLite WAL + .md 文件 |
零部署 · FTS5 · git 友好 · LLM 可直读 |
| 调度 | APScheduler · 17 jobs | 单进程内调度,无外部 MQ |
| MCP | fastapi-mcp | OpenAPI → MCP 自动转换 |
| 前端 | React 18 + Vite 5 + TypeScript | 60+ 组件 · 类型安全 · 热重载 |
| 图表 | echarts + recharts | 看板风格 |
| 加密 | Fernet (PBKDF2 派生) | secrets · 同步包 |
| 跨端同步 | WebDAV (坚果云) · zip 容器 | 加密包最小化 · 不依赖云服务 |
| 领域 | 来源 | 数量 |
|---|---|---|
| 科技 / AI | aihot.virxact.com | 1 |
| 网络安全 | 阿里云漏洞库 · CNNVD · 安全客 · FreeBuf · THN · 奇安信 · 绿盟 · Sogou 微信 | 17+ |
| 金融 / 投资 | 新浪财经 · 腾讯证券 | 2 |
| 独立开发 / 创业 | Hacker News · Product Hunt | 2 |
| GitHub | GitHub Trending + 搜索 | 1 |
| 标讯 | 政府采购网 (代理爬取) | 1 |
| 知识 | Cubox · 浏览器书签 · SecNews 收藏 | 3 |
完整列表见 backend/collectors/。
# 后端 (67 个 pytest 文件)
.venv/bin/python3 -m pytest backend/tests/ -v
.venv/bin/python3 -m pytest backend/tests/ -k "merge"
.venv/bin/python3 -m py_compile backend/services/sync_merge.py
# 前端 (Vitest + jsdom)
cd frontend
npx vitest run
npx tsc --noEmit
npm run buildCI: .github/workflows/ci.yml — Python compile + pytest + tsc + vitest + vite build。
Q: 为什么不内置 LLM 推理? A: 让用户在自己已配好的 AI Agent 环境(Cursor / Claude Desktop / Trae)中推理,避免重复配置和 API key 管理。hotspot 只负责数据存储 + 13 工具暴露。
Q: 能多用户吗?
A: 当前是单用户本地工作站,无多用户/权限隔离。SQLite WAL 模式下 WORKERS=1 是约束条件。
Q: 数据怎么备份? A: 3 选 1:
backend/data/backup_*.db(24h 滚动,APScheduler 自动)- WebDAV 同步包(坚果云 · zip + Fernet 加密)
- git 跟踪
knowledge/目录
Q: 端口冲突怎么办?
A: 后端改 PORT=8001 启动;前端改 vite --port 8899。8898 是受保护端口(CodeGarden 资源中枢),禁止释放。
新源 → 继承 BaseCollector + 测试
新门禁 → 继承 BaseGate + 进 pipeline.py
新 MCP tool → mcp_types.py 加 Pydantic + mcp_config.py 加 operation_id
详细:AGENTS.md · CLAUDE.md · docs/IMPROVEMENT_PLAN.md
禁止:
- 提交
.env/ 真实 proxy 配置 / 个人数据 - 引入 Redis / PostgreSQL / Celery(违反「简单胜过复杂」原则)
- 多 worker(SQLite WAL 锁限制)
LICENSE — GNU GPL-3.0
- Anthropic MCP — 协议规范
- fastapi-mcp — MCP 集成
- MITRE ATT&CK — 攻击技术本体(CC-BY-4.0)
- NVD — CVE 数据源
SecNews (codename hotspot) is a single-user local workstation for AI + security practitioners.
It unifies three daily workflows — news aggregation, knowledge capture, project lifecycle — into one local
machine and exposes them to external AI Agents (Cursor / Claude Desktop / Trae) via the standard
MCP protocol with 13 tools.
One person · one machine · zero external services.
| # | Subsystem | What |
|---|---|---|
| 01 | SecNews | 7 domains · 30+ sources · 13 quality gates |
| 02 | Knowledge LLM-Wiki | 4-layer pyramid (items → concepts → learning → content) |
| 03 | CodeGarden | project lifecycle + service mesh + resource hub + orchestration |
| 04 | Security Graph | MITRE ATT&CK · NVD CVE · compliance (等保 2.0 / 关基 / 数安法) |
| 05 | MCP Server | 13 standard tools · stdio / SSE · zero session state |
git clone https://github.com/anyeduke11/secnews.git && cd secnews
python -m venv .venv && source .venv/bin/activate
pip install -r backend/requirements.txt
python run.py # http://127.0.0.1:8000
cd frontend && npm install && npm run dev # http://localhost:8898Configure backend/proxy_config.json (set your proxy port, default mode off).
{
"mcpServers": {
"hotspot": {
"command": "python",
"args": ["-m", "backend.mcp_stdio_main"],
"cwd": "/absolute/path/to/secnews"
}
}
}Works with Claude Desktop, Trae, Cursor, and Claude Code.
Python 3.10+ · FastAPI · SQLite (WAL) · APScheduler · fastapi-mcp · loguru
React 18 · Vite 5 · TypeScript · Tailwind 3 · echarts · recharts
Fernet (PBKDF2-derived) · WebDAV (Nutstore) with zip + Fernet envelope
LICENSE — GNU GPL-3.0