Atlas / MCP servers / abrinsmead / Mindpilot

MindpilotCAUTION

mcp/abrinsmead/mindpilot

See through your agent's eyes. Visualize legacy code, architect new systems, understand everything.

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/abrinsmead/mindpilot-mcp) [](https://www.npmjs.com/package/@mindpilot/mcp) [](https://github.com/abrinsmead/mindpilot-mcp/blob/main/LICENSE)

See through your agent's eyes. Visualize legacy code, inspect complex flows, understand everything.

[!TIP] Mindpilot is now available as a lightweight agent skill—no local MCP server needed. Ask your agent to diagram something and it builds a self-contained, interactive Mermaid viewer you can open in your browser or publish as a Claude artifact. Install with: npx skills add abrinsmead/skills/mermaid-viewer

Why Mindpilot?

  • Visualize Anything: Use your coding agent to generate on-demand architecture, code, and process diagrams to view your code from different perspectives.
  • Vibe Checks: AI-generated code can accumulate unused and redundant constructs. Use visualizations to spot areas that need cleanup.
  • Local Processing: Diagrams are never sent to the cloud. Everything stays between you, your agent, and your agent's LLM provider(s).
  • Export & Share: Export any diagram as a vector image.

Prerequisites

Node.js v20.0.0 or higher.

Quickstart

Claude Code

claude mcp add mindpilot -- npx @mindpilot/mcp@latest

Cursor

Under Settings > Cursor Settings > MCP > Click Add new global MCP server and configure mindpilot in the mcpServers object.

{
"mcpServers": {
"mindpilot": {
"command": "npx",
"args": ["@mindpilot/mcp@latest"]
}
}
}

VS Code

Follow the instructions here for enabling MCPs in VS Code: https://code.visua

Read from source at commit cdb17b1c8876OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add client -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "client": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
open_uireadOpen the Mindpilot UI application
render_mermaidreadRender a Mermaid diagram to SVG format. CRITICAL RULES: 1) Node IDs must be alphanumeric without spaces (use A1, nodeA, start_node). 2) For node labels with special characters, wrap in quotes: A[
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (10)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
src/client/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
LOWInventory / provenance · inv.hidden_file · CWE-1104
dxt/.dxtignore
.dxtignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/client/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/client/src/components/common/EmptyState.tsx:1
import { cn } from '../../lib/utils';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/client/src/components/common/LoadingSpinner.tsx:1
import { cn } from '../../lib/utils';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/client/src/components/common/StatusIndicator.tsx:1
import { cn } from '../../lib/utils';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/client/src/constants/app.ts:1
import packageJson from '../../../../package.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/client/src/lib/electron.ts:6
import type { ElectronAPI } from '../../../electron/preload.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@fastify/static, @modelcontextprotocol/sdk, fastify, open, posthog-js, @anthropic-ai/dxt, @types/node, @types/ws
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/client/package.json
@monaco-editor/react, @radix-ui/react-context-menu, @radix-ui/react-dialog, @radix-ui/react-dropdown-menu, @radix-ui/react-icons, @radix-ui/react-select, @radix-ui/react-separator, @radix-ui/react-slo
Why it matters. 25 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha cdb17b1c8876full audit observations/trust-audit/mcp-server/abrinsmead__mindpilot.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07cdb17b1c8876CAUTIONB85first audit
06

Questions

What is the Mindpilot MCP server?

See through your agent's eyes. Visualize legacy code, architect new systems, understand everything.

What tools does Mindpilot expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mindpilot safe to connect to an agent?

With care. The audit graded it B (85/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Mindpilot need?

No credential environment variables were found in its source, so it appears to need none.

How does Mindpilot run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as client at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (cdb17b1c8876), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement