drawio-mcp-server — security grade SAFE, quality 69/100

Security audit verdict: SAFE · quality 69/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by lgazo · MCP Server · ★ 1.5k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is drawio-mcp-server safe to install? View the security audit →

About drawio-mcp-server

Draw.io MCP server Let's do some Vibe Diagramming with the most wide-spread diagramming tool called Draw.io (Diagrams.net). Key Highlights Edge geometry control with waypoints and automatic self-connector routing Parent-child relationships for nested shapes and grouping Built-in Draw.io editor - no browser extension required MCP server that lets AI agents control Draw.io diagrams Programmatic diagram creation, inspection, and modification via MCP tools Layer management for complex diagrams Works with any MCP client (Claude Desktop, Claude Code, Zed, Codex, etc.) Introduction The Draw.io MCP server brings Draw.io diagramming capabilities to AI agents. It provides MCP tools that can create, read, update, and delete diagram elements - letting AI assistants build archit

Quick Facts

Stars1,464
Forks131
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score68.7318086203298/100
Open Issues9
Last Updated2026-09-14
Created2025-04-21
Platformsmcp, node
Est. Tokens~15k

Compatible Skills

These tools work well together with drawio-mcp-server for enhanced workflows:

  • modelcontextprotocol — semantic(0.23)+complementary+same_lang+similar_pop+shared_platform (53%)
  • mcp-server — semantic(0.63)+same_lang+similar_pop+shared_platform (52%)
  • airtable-mcp-server — semantic(0.38)+same_lang+similar_pop+shared_platform (48%)
  • XcodeBuildMCP — semantic(0.38)+same_lang+similar_pop+shared_platform (48%)
  • raindrop-mcp — semantic(0.51)+same_lang+similar_pop+shared_platform (48%)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is drawio-mcp-server?

drawio-mcp-server is Draw.io Model Context Protocol (MCP) Server. It is categorized as a MCP Server with 1.5k GitHub stars.

What programming language is drawio-mcp-server written in?

drawio-mcp-server is primarily written in TypeScript.

How do I install or use drawio-mcp-server?

You can find installation instructions and usage details in the drawio-mcp-server GitHub repository at github.com/lgazo/drawio-mcp-server. The project has 1.5k stars and 131 forks, indicating an active community.

What license does drawio-mcp-server use?

drawio-mcp-server is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools