penpot-mcp — security grade SAFE, quality 71/100

Security audit verdict: SAFE · quality 71/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by penpot · MCP Server · ★ 411

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is penpot-mcp safe to install? View the security audit →

About penpot-mcp

[!IMPORTANT] This repository has been archived on 2026-02-03. Its contents have been fully integrated into the main Penpot repository: https://github.com/penpot/penpot/tree/develop/mcp Penpot's Official MCP Server Penpot integrates a LLM layer built on the Model Context Protocol (MCP) via Penpot's Plugin API to interact with a Penpot design file. Penpot's MCP server enables LLMs to perfom data queries, transformation and creation operations. Penpot's MCP Server is unlike any other you've seen. You get design-to- design, code-to-design and design-code supercharged workflows. Architecture The Penpot MCP Server exposes tools to AI clients (LLMs), which support the retrieval of design data as well as the modification and creation of design elements. The MCP server communicates with Penpot via the dedicated Penpot MCP Plugin, which connects to the MCP server via WebSocket. This enables the LLM to carry out tasks in the context of a design file by executing code that leverages the Penpot Plugin API. The LLM is free to write and execute arbitrary code snippets within the Penpot Plugin environment to accomplish its tasks. ![Architecture](resources/architectu

aidesignmcpplugin

Quick Facts

Stars411
Forks59
LanguageTypeScript
CategoryMCP Server
LicenseMPL-2.0
Quality Score70.5797741691618/100
Open Issues4
Last Updated2026-03-19
Created2025-10-07
Platformsmcp, node
Est. Tokens~31k

penpot-mcp alternative? Top 6 similar tools

Looking for a penpot-mcp alternative? If you're comparing penpot-mcp with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • MoltBrain by nhevers · ⭐ 253

    Long-term memory layer for OpenClaw & MoltBook agents that learns and recalls your project context automatical

  • claude-emporium by Vvkmnn · ⭐ 84

    🏛 [UNDER CONSTRUCTION] A (roman) claude plugin marketplace

  • typeui by bergside · ⭐ 1.9k

    Build better UI with AI

  • mcp by MicrosoftDocs · ⭐ 1.9k

    Official Microsoft Learn MCP Server and CLI tool – powering LLMs and AI agents with real-time, trusted Microso

  • pg-aiguide by timescale · ⭐ 1.8k

    MCP server and Claude plugin for Postgres skills and documentation. Helps AI coding tools generate better Post

  • zenfeed by glidea · ⭐ 1.7k

    Make RSS 📰 great again with AI 🧠✨!!

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is penpot-mcp?

penpot-mcp is Penpot's official MCP Server. It is categorized as a MCP Server with 411 GitHub stars.

What programming language is penpot-mcp written in?

penpot-mcp is primarily written in TypeScript. It covers topics such as ai, design, mcp.

How do I install or use penpot-mcp?

You can find installation instructions and usage details in the penpot-mcp GitHub repository at github.com/penpot/penpot-mcp. The project has 411 stars and 59 forks, indicating an active community.

What license does penpot-mcp use?

penpot-mcp is released under the MPL-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to penpot-mcp?

The top alternatives to penpot-mcp on Agent Skills Hub include MoltBrain, claude-emporium, typeui. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools