Atlas / MCP servers / ajhcs / Cameo Bridge

Cameo BridgeCAUTION

mcp/ajhcs/cameo-bridge

MCP server bridging AI assistants to CATIA Magic / Cameo Systems Modeler for SysML/UML model creation, querying, and manipulation

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
162 97r · 56w · 9d
Transport
stdio
License
MIT
Stars
42
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server that connects AI coding assistants to CATIA Magic / Cameo Systems Modeler -- the industry-standard MBSE tool for SysML and UML modeling.

This lets Claude Code (or any MCP-compatible client) query, create, modify, inspect, validate, and visualize SysML/UML models inside a running Cameo instance through 162 tools covering capability negotiation, methodology-aware OOSEM workflows, semantic validation, state-machine semantics, elements, relationships, native matrices and tables, Relation Maps, reports, requirements import/export, validation suites, Teamwork/DataHub probes, diagrams, reusable verification, specifications, and guarded macro execution.

Claude Code    Python MCP Server    Java Plugin (Cameo JVM)

Why This Exists

MBSE tools like Cameo are powerful but manual. With this bridge, an AI assistant can:

  • Build models from requirements -- "Create a state machine for ATM operations with idle, active, and maintenance states"
  • Query and navigate models -- "Show me all blocks with the > stereotype"
  • Generate diagrams -- Create sequence diagrams, BDDs, IBDs, state machines, and populate them with elements
  • Export diagram images -- Get PNG snapshots of any diagram as base64
  • Run Groovy scripts -- Escape hatch for anything the structured tools don't cover
  • Inspect and modify specifications -- Read/write any UML property, tagged value, or constraint

How Is This Different?

Read from source at commit 9e711523901bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add cameo-mcp-server -- uvx cameo-mcp-server
claude-desktop
{
  "mcpServers": {
    "cameo-mcp-server": {
      "command": "uvx",
      "args": [
        "cameo-mcp-server"
      ]
    }
  }
}
03

Exposed tools (162)

97 read · 56 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cameo_add_diagram_pathswriteAdd relationship lines (paths) to a diagram.
cameo_add_to_diagramwriteAdd a model element to a diagram canvas.
cameo_analyze_variants_previewreadPreview variant/product-line analysis without writes.
cameo_apply_criteria_templatewriteApply a criteria template after UI-diff verification.
cameo_apply_profilewriteApply a profile to a model/package so its stereotypes become usable.
cameo_apply_proofing_patch_planwriteApply a previously generated proofing patch plan to the live model.
cameo_apply_requirements_importwriteApply or dry-run a reviewed requirements import request.
cameo_apply_stereotypewriteApply a stereotype to an element.
cameo_assemble_ppt_pdfreadPlan or assemble a PPT/PDF package from methodology-required diagrams.
cameo_auto_layoutwriteApply automatic layout to a diagram.
cameo_build_criteria_expressionreadBuild a bridge-owned criteria expression preview.
cameo_build_cross_diagram_remediation_planreadBuild a previewable remediation plan from existing validation payloads.
cameo_capture_criteria_template_from_diffreadCapture a native criteria template from before/after snapshot evidence.
cameo_collapse_relation_mapreadTry to collapse native Relation Map nodes and report before/after counts.
cameo_compare_expected_artifact_listreadCompare discovered/current artifacts against an expected methodology artifact list.
cameo_compare_relation_mapsreadCompare two Relation Maps, usually a UI-created map and a bridge-created map.
cameo_configure_relation_mapwriteUpdate native graph settings for an existing Relation Map.
cameo_create_diagramwriteCreate a new SysML or UML diagram.
cameo_create_elementwriteCreate a new model element.
cameo_create_generic_tablewriteCreate and configure a native Generic Table artifact.
cameo_create_matrixwriteCreate a supported native matrix artifact.
cameo_create_relation_mapwriteCreate and configure a native Relation Map artifact.
cameo_create_relationshipwriteCreate a relationship between two elements.
cameo_create_snapshotwriteCapture an in-memory inspection snapshot for before/after UI diffs.
cameo_delete_elementdestructiveDelete a model element.
cameo_delete_shapesdestructiveDelete presentation elements (shapes/paths) from a diagram canvas.
cameo_delete_snapshotdestructiveDelete an in-memory snapshot without changing the CATIA model.
cameo_detect_cross_diagram_inconsistenciesreadDetect cross-diagram inconsistencies and return a previewable remediation plan.
cameo_diff_snapshotsreadDiff two snapshots to reveal what CATIA Magic UI actions changed.
cameo_dump_diagram_propertiesreadDump diagram settings and paged presentation property summaries.
cameo_dump_presentation_propertiesreadDump full properties for one selected diagram presentation element.
cameo_dump_relation_map_raw_settingsreadDump native Relation Map settings for UI-diff investigation.
cameo_execute_macrowriteExecute a Groovy script inside CATIA Magic
cameo_execute_methodology_recipewriteExecute a bounded OOSEM methodology recipe through structured bridge calls.
cameo_execute_probewriteExecute a controlled discovery probe.
cameo_expand_relation_mapreadTry to expand native Relation Map nodes and report before/after counts.
cameo_export_profile_summaryreadExport a summary of profile and stereotype elements in the open project.
cameo_export_required_diagramswritePlan or execute export of methodology-required diagrams.
cameo_export_requirementswriteExport requirement-like elements through the import/export route.
cameo_export_requirements_previewreadPreview requirement export without mutating the model.
cameo_export_variant_configurationreadPreview exporting a bridge-owned variant configuration evidence payload.
cameo_generate_reportreadGenerate a Report Wizard artifact from a real native template.
cameo_generate_report_previewreadPreview a guarded Report Wizard generation request.
cameo_generate_review_packetreadGenerate a compact methodology review packet without mutating the model.
cameo_get_active_diagramreadGet the currently active CATIA Magic diagram as a small payload.
cameo_get_capabilitiesreadGet machine-readable plugin capabilities and version-lockstep metadata.
cameo_get_containment_treereadBrowse the containment tree structure.
cameo_get_criteria_capabilitiesreadProbe generic criteria expression support.
cameo_get_datahub_capabilitiesreadProbe DataHub/DOORS integration availability.
cameo_get_diagram_imagereadExport a diagram as a base64-encoded PNG image.
cameo_get_elementreadGet full details of a model element.
cameo_get_extension_capabilitiesreadProbe safety/cyber extension availability.
cameo_get_generic_tablereadGet one native Generic Table with row, column, and cell data.
cameo_get_import_export_capabilitieswriteProbe bridge-owned CSV/JSON and native ReqIF import/export support.
cameo_get_matrixreadRead one supported native matrix with populated cell data.
cameo_get_methodology_guidancereadExplain what artifact work is missing next for a methodology pack.
cameo_get_methodology_packreadGet one methodology pack definition.
cameo_get_profile_capabilitiesreadProbe profile/DSL authoring support.
cameo_get_projectreadGet current project info: name, file path, and primary model ID.
cameo_get_relation_mapreadGet one native Relation Map with persisted graph settings.
cameo_get_relationshipsreadGet relationships for an element.
cameo_get_report_capabilitiesreadProbe Report Wizard API availability and plugin evidence.
cameo_get_report_jobreadFetch a Report Wizard generation job status.
cameo_get_requirements_capabilitiesreadProbe Requirements/ReqIF API availability and plugin evidence.
cameo_get_shape_propertiesreadRead the current property state for a specific diagram shape.
cameo_get_simulation_capabilitiesreadProbe Simulation Toolkit availability.
cameo_get_simulation_resultreadFetch simulation result status.
cameo_get_snapshotreadGet one in-memory bridge snapshot payload.
cameo_get_specificationreadGet the full specification of a model element — all UML properties, stereotype tagged values, and constraint fields.
cameo_get_state_behaviorsreadRead the structured entry/do/exit behavior payloads for a state.
cameo_get_teamwork_capabilitiesreadProbe Teamwork/Magic Collaboration Studio API availability.
cameo_get_teamwork_historyreadRead Teamwork history diagnostics when available.
cameo_get_teamwork_locksreadRead Teamwork lock diagnostics when available.
cameo_get_teamwork_projectreadRead Teamwork project metadata when native readback is promoted.
cameo_get_traceability_graphreadBuild a read-only relationship graph for traceability analysis.
cameo_get_transition_triggerswriteRead the structured trigger/event state for a transition.
cameo_get_typed_diagram_capabilitieswriteProbe typed diagram inspection and write-preview support.
cameo_get_ui_selectionreadGet selected browser elements and selected diagram presentation IDs.
cameo_get_ui_statereadInspect live CATIA Magic UI context.
cameo_get_validation_capabilitiesreadProbe whether CATIA native validation APIs are available through the bridge.
cameo_get_validation_resultwriteFetch a cached CATIA native validation run result by run ID.
cameo_get_variant_capabilitiesreadProbe native or bridge-owned variant support.
cameo_import_requirements_previewwritePreview requirement import/diff without writes.
cameo_inspect_typed_diagramreadInspect a diagram through the typed diagram route.
cameo_install_extension_pattern_previewwritePreview installing bridge-owned safety/cyber extension patterns.
cameo_install_variant_pattern_previewwritePreview installing bridge-owned variant stereotypes.
cameo_list_containment_childrenreadList a compact, paginated slice of the containment tree.
cameo_list_criteria_templatesreadList criteria templates for relation maps, matrices, tables, or legends.
cameo_list_datahub_sourcesreadList DataHub sources when native readback is promoted.
cameo_list_diagram_shapesreadList all shapes and relationship paths currently on a diagram.
cameo_list_diagram_typesreadList the validated diagram request tokens accepted by the MCP bridge.
cameo_list_diagramsreadList all diagrams in the current project.
cameo_list_extension_profilesreadList extension-related profiles and stereotypes.
cameo_list_generic_table_columnsreadList possible native Generic Table column ids for an element or type.
cameo_list_generic_tablesreadList native Generic Table artifacts in the current project.
cameo_list_matricesreadList supported native matrix artifacts in the current project.
cameo_list_matrix_kindsreadList the validated native matrix kinds and example type domains.
cameo_list_methodology_packsreadList built-in methodology packs available in the Phase 2 copilot layer.
cameo_list_probe_templatesreadList safe built-in CATIA API discovery probes.
cameo_list_relation_map_criteria_templatesreadList built-in Relation Map criteria templates.
cameo_list_relation_map_presentationsreadList loaded Relation Map presentation nodes, paths, and legend elements.
cameo_list_relation_mapsreadList native Relation Map artifacts in the current project.
cameo_list_report_templatesreadList Report Wizard templates when native readback is promoted.
cameo_list_simulation_configurationsreadList simulation configurations when native readback is promoted.
cameo_list_snapshotsreadList in-memory bridge snapshots available for diffing.
cameo_list_teamwork_branchesreadList Teamwork branches when available.
cameo_list_teamwork_descriptorsreadList Teamwork descriptors when the native client is authenticated.
cameo_list_typed_diagramsreadList diagrams with type metadata for typed handlers.
cameo_list_validation_suitesreadList candidate native validation suites and constraints in the open project.
cameo_modify_elementwriteModify an existing element name or documentation.
cameo_move_shapeswriteMove and/or resize shapes on a diagram canvas.
cameo_normalize_compartment_presetsreadNormalize compartment presets based on the diagram type.
cameo_parse_criteria_expressionreadParse a criteria expression into a diagnostic payload.
cameo_preview_datahub_syncwritePreview DataHub sync without writing to CATIA or external systems.
cameo_preview_profile_operationwritePreview a profile operation such as create-profile, create-stereotype, create-tag, apply-profile, or set-tags.
cameo_preview_requirements_importwritePreview requirements import through the import/export route.
cameo_preview_teamwork_commitwritePreview a Teamwork commit without changing the server project.
cameo_preview_teamwork_updatewritePreview a Teamwork update without changing the server project.
cameo_preview_typed_diagram_operationreadPreview a typed diagram operation such as sequence-message, state-transition, parametric-binding, or legend-apply.
cameo_probe_bridgereadProbe common local bridge endpoints and report the preferred health paths.
cameo_proof_model_textreadProof model text across requirements, comments, states, transitions, and diagram labels.
cameo_prune_diagram_presentationsdestructiveDelete unwanted diagram presentations using keep/drop rules.
cameo_prune_path_decorationsreadPrune child path decorations such as association end-role labels.
cameo_query_elementsreadSearch for model elements matching filters.
cameo_refresh_relation_mapreadRefresh a native Relation Map after model or settings changes.
cameo_refuse_compliance_claimreadReturn the bridge refusal contract for unsupported compliance claims.
cameo_render_relation_mapreadRender/export a Relation Map image; native refresh is opt-in because it can block CATIA.
cameo_repair_conveyed_item_labelsdestructiveForce conveyed-item labels and optional label resets on eligible paths.
cameo_repair_hidden_labelsreadAuto-show hidden labels using diagram-type-aware native repair defaults.
cameo_repair_label_positionsdestructiveReset likely-overlapping path labels to readable default positions.
cameo_reparent_shapeswriteMove existing presentation elements under new container shapes.
cameo_reset_sessiondestructiveForce-close any stuck model editing session in CATIA Magic.
cameo_route_pathsdestructiveUpdate routing and label reset behavior for existing diagram paths.
cameo_run_native_validationwriteRun CATIA native validation for a suite or explicit constraint IDs.
cameo_run_simulationwriteCall the guarded simulation run endpoint.
cameo_run_simulation_previewwritePreview a bounded simulation run request.
cameo_run_validationwriteRun or preview bounded native Cameo validation.
cameo_save_projectwriteSave the current project to disk.
cameo_scan_extensionsreadPreview a read-only safety/cyber extension model scan.
cameo_set_allocation_compartment_presentationwriteApply a high-level allocation/full-port display preset on one diagram.
cameo_set_item_flow_label_presentationwriteApply a high-level item-flow/information-flow label preset on one diagram.
cameo_set_relation_map_criteriawriteApply Relation Map criteria using templates or raw UI-derived expressions.
cameo_set_shape_compartmentswriteApply normalized compartment visibility controls to one diagram shape.
cameo_set_shape_propertieswriteSet display properties on a specific diagram shape.
cameo_set_specificationwriteSet properties and/or constraint fields on a model element
cameo_set_state_behaviorswriteSet structured entry/do/exit opaque behaviors for a state.
cameo_set_stereotype_metaclasseswriteSet the base metaclasses for a stereotype using Cameo
cameo_set_tagged_valueswriteSet tagged values on a stereotyped element.
cameo_set_transition_label_presentationwriteApply a high-level transition-label display preset on one diagram.
cameo_set_transition_triggerwriteCreate or replace one transition trigger with explicit semantics.
cameo_set_usecase_subjectwriteSet or append subject classifiers on a UseCase.
cameo_statusreadCheck if CATIA Magic is running and the CameoMCPBridge plugin is responsive.
cameo_terminate_simulationdestructiveTerminate an active simulation job when execution support is enabled.
cameo_validate_methodology_packagereadValidate a package or recipe scope against the methodology definition.
cameo_validate_methodology_recipewriteRun methodology conformance checks for an artifact recipe.
cameo_verify_activity_flow_semanticsreadValidate whether one activity diagram behaves like a coherent workflow.
cameo_verify_cross_diagram_traceabilityreadValidate traceability across activity, port, IBD, and requirement views.
cameo_verify_diagram_visualwriteRun reusable visual verification checks against one diagram.
cameo_verify_matrix_consistencywriteRun quantitative consistency checks against one native requirement matrix.
cameo_verify_port_boundary_consistencyreadValidate interface-block flow-property ownership and duplication.
cameo_verify_relation_mapreadVerify graph traversal, native settings validity, and rendered count separately.
cameo_verify_requirement_qualityreadValidate whether SysML requirements contain real requirement content.
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (16)

MEDIUMInventory / provenance · inv.binary · CWE-1104
plugin/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
cameo_delete_element, cameo_delete_shapes, cameo_delete_snapshot, cameo_prune_diagram_presentations, cameo_repair_conveyed_item_labels, cameo_repair_label_positions, cameo_reset_session, cameo_route_p
Why it matters. 9 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/development/build-and-live-validation.md:40
py -3 scripts\live_validate_autopilot_route_surface.py --base-url http://127.0.0.1:18740/api/v1 --timestamped --require-open-project
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/development/build-and-live-validation.md:59
$base = 'http://127.0.0.1:18740/api/v1'
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/cameo-ai-systems-engineer-autopilot-plan.md:6
**Primary live target**: CATIA Magic / Cameo Systems Modeler with `CameoMCPBridge` on `http://127.0.0.1:18740/api/v1`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/cameo-ai-systems-engineer-autopilot-plan.md:232
Invoke-RestMethod http://127.0.0.1:18740/api/v1/probes/execute -Method Post -ContentType 'application/json' -Body '{"language":"javaReflection","operation":"listMethods","className":"com.nomagic.magic
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/cameo-ai-systems-engineer-autopilot-plan.md:233
Invoke-RestMethod http://127.0.0.1:18740/api/v1/probes/execute -Method Post -ContentType 'application/json' -Body '{"language":"javaReflection","operation":"listMethods","className":"com.nomagic.magic
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/cameo_mcp/client.py:208
image_bytes = base64.b64decode(base64_image)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/cameo_mcp/methodology_workflows.py:602
return base64.b64decode(image)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/cameo_mcp/server.py:162
image_bytes = base64.b64decode(base64_image)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/cameo_mcp/verification.py:357
payload = base64.b64decode(image_b64) if image_b64 else b""
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
mcp-server/scripts/live_validate_relation_map_rendering.py:130
png_path.write_bytes(base64.b64decode(image["image"]))
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:31
This is the only open-source MCP server that integrates directly with a running Cameo instance, giving full access to SysML v1 models and the complete Cameo API surface.
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:441
The macro tool is an escape hatch for operations not covered by the structured tools. Scripts have full access to the Cameo OpenAPI, with `project`, `application`, `primaryModel`, and `ef` (ElementsFa
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:553
- The `cameo_execute_macro` tool executes **arbitrary Groovy code** inside the Cameo JVM with full access to the filesystem, network, and classloader
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/plans/cameo-ai-systems-engineer-autopilot-plan.md:702
- Do not collect or store credentials in the Java plugin. If credentialed REST is later needed, implement it in Python with explicit env-var configuration and redacted logging.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 9e711523901bfull audit observations/trust-audit/mcp-server/ajhcs__cameo-bridge.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-089e711523901bCAUTIONB87first audit
06

Questions

What is the Cameo Bridge MCP server?

MCP server bridging AI assistants to CATIA Magic / Cameo Systems Modeler for SysML/UML model creation, querying, and manipulation

What tools does Cameo Bridge expose?

162 in total: 97 read-only, 56 that write, and 9 that can delete or overwrite (cameo_delete_element, cameo_delete_shapes, cameo_delete_snapshot, cameo_prune_diagram_presentations, cameo_repair_conveyed_item_labels). Every one is listed on this page with its risk.

Is Cameo Bridge safe to connect to an agent?

With care. The audit graded it B (87/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Cameo Bridge need?

No credential environment variables were found in its source, so it appears to need none.

How does Cameo Bridge run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as cameo-mcp-server.

How current is this page?

The grade is for one exact copy of the source (9e711523901b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement