Wildberries reviews MCP server
WildberriesToolsMCP
An MCP server that pulls Wildberries product reviews by link or SKU, up to 500 reviews in a single JSON response
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- It only reads public reviews, but the optional proxy rotation defaults to trusting a third-party public VLESS server source
- The remote HTTP transport has no auth by default unless host and origin allowlists are set
Install
Manual install
pip install -r requirements.txtInstalls dependencies after cloning the repo and creating a virtual environment.
This is third-party code. Review the repository files before installing.
What it does
The server exposes one tool, get_wb_reviews: it takes a Wildberries product link or SKU and returns product metadata together with up to 500 review texts. It runs over stdio for local clients like Claude Desktop and Cursor, or over Streamable HTTP for remote ones including ChatGPT. For cloud deployments where a direct connection to Wildberries may not work, an optional Xray-core component rotates VLESS connections from a subscription feed, validates each candidate with a real request to Wildberries, and keeps a working route on a local SOCKS port, refreshing it on a schedule.
Who it is for. For people analyzing Wildberries buyer reviews: product analytics, demand research, product reputation monitoring.
Good fit when
- You need to pull a product's reviews for sentiment analysis or common complaints
- The server runs in the cloud outside Russia and needs to route around Wildberries' geo-block
- You need a remote HTTP MCP for a client like ChatGPT
Not a fit when
- You need seller-dashboard data or actions: sales, prices, replying to reviews
- You do not want a cloud deployment to depend on a third-party public VLESS server list
Example request
Pull the reviews for this Wildberries product and find the common quality complaintsLimitations
Read-only review access, no seller dashboard. The optional VLESS rotation defaults to a third-party public proxy subscription; trust it only after review, or replace it with your own source via XRAY_SUBSCRIPTION_URL. The image pins Xray-core 26.3.27 instead of latest. No license is stated.
How to disable. Stop the server container or process, or run it with XRAY_ENABLED=false to disable proxy rotation.
MCP
- Transport
- stdio, http, sse
- Authentication
- not required
| Environment variables | |
|---|---|
| MCP_TRANSPORT | Server transport: stdio, streamable-http or sse |
| XRAY_ENABLED | Enables VLESS proxy rotation via Xray-core |
| XRAY_SUBSCRIPTION_URL | The VLESS subscription source, defaults to an external public list |
Security check
- It only reads public reviews, but the optional proxy rotation defaults to trusting a third-party public VLESS server source
- The remote HTTP transport has no auth by default unless host and origin allowlists are set
README in short
The README describes the single get_wb_reviews tool, the stdio and Streamable HTTP transports, the VLESS rotation architecture via Xray-core with a real-request check for each candidate, environment variable tables for MCP and for Xray, and a ready Render deployment path.
FAQ
Why does the server need VLESS proxy rotation?
For cloud hosting outside Russia, where the normal outbound IP may not be suitable for reaching Wildberries.
Can I skip Xray entirely?
Yes, run the container with XRAY_ENABLED=false or run python server.py directly.
Related
Official DataLens (Yandex) skills for Claude Code, Codex and OpenCode: SDK, HTML reports and RLS resolution
A Yandex Metrika MCP server generated from the API spec: 108 methods, 10 tools declared by default, transparent filters and response metadata
An open MCP server and agent skill set for SEO: keyword research, competitors, backlinks and site audits powered by DataForSEO
A Claude Code plugin for SEO audits: technical SEO, E-E-A-T, schema, local and AI search via parallel subagents