Atlas / MCP servers / arcadeai / Blueprint

BlueprintSAFE

mcp/arcadeai/blueprint-1

Diagram generation for understanding codebases and system architecture using Nano Banana Pro.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 0r · 2w · 0d
Transport
—
License
—
Stars
731
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Image generated using Blueprint MCP, Nano Banana Pro, and Arcade MCP server.

Diagram generation for understanding codebases and system architecture using Nano Banana Pro.

Works with Arcade's ecosystem: Combine with HubSpot, Google Drive, GitHub, and other Arcade tools to extract data from your systems and visualize it as diagrams.

Setup

1. Sign up for Arcade

https://arcade.dev

2. Install Dependencies

# Create virtual environment
python3 -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate

# Install Arcade CLI
pip install arcade-mcp

3. Login to Arcade

arcade-mcp login

4. Get Google AI Studio API Key

https://aistudio.google.com/ → Create API key

5. Store Secret in Arcade

arcade-mcp secret set GOOGLE_API_KEY="your_api_key_here"

6. Deploy Server

Clone this repo, then:

cd blueprint-mcp
arcade-mcp deploy

7. Create Gateway

  1. Go to https://api.arcade.dev/dashboard
  2. Click "Gateways" → "Create Gateway"
  3. Add your deployed architect_mcp server to the gateway

8. Configure Cursor

  1. In Cursor: Settings → MCP
  2. Add your Arcade gateway URL
  3. Restart Cursor

Usage

Tools

  • start_diagram_job - Start generation, returns job ID
  • check_job_status - Check if complete
  • download_diagram - Download PNG as base64

Example Prompts

Visualize code architecture:

Analyze the authentication module in src/auth/ and create an 
architecture diagram showing the components and their relationships.

Document API flows:

Create a sequence diagram showing the OAuth login flow based on 
the code in src/auth/oauth.py

Explain processes:

Generate a flowchart explaining how our payment processing works,
showing the steps from checkout to confirmation.

Understand data pipelines:

Create a data flow diagram for our ETL pipeline showing sources,
transformati
Read from source at commit c9179dc6d51fOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add blueprint-mcp -- uvx blueprint-mcp
claude-desktop
{
  "mcpServers": {
    "blueprint-mcp": {
      "command": "uvx",
      "args": [
        "blueprint-mcp"
      ]
    }
  }
}
03

Exposed tools (2)

0 read · 2 write · 0 destructive.

ToolRiskDescription
edit_diagramwriteEdit a previously generated diagram. Pass the file_uri from download_diagram. The file_uri references the image stored in Google
start_diagram_jobwriteStart async diagram generation on the server. Returns a job ID. Poll with check_job_status, then retrieve the image with download_diagram.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/generator.py:116
return base64.b64decode(img_data)
INFOInventory / provenance · inv.oversize · CWE-1104
images/arcade_enterprise_banking.png
images/arcade_enterprise_banking.png
Why it matters. 4297337 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
images/blueprint-mcp.png
images/blueprint-mcp.png
Why it matters. 5620149 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
images/langgraph_architecture_learning_card.png
images/langgraph_architecture_learning_card.png
Why it matters. 5002901 bytes not read

Gates applied: no_behavioural_pass, no_license.

Audited 2026-09-28 · audit v0.4.1 · source sha c9179dc6d51ffull audit observations/trust-audit/mcp-server/arcadeai__blueprint-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28c9179dc6d51fSAFEB89first audit
06

Questions

What is the Blueprint MCP server?

Diagram generation for understanding codebases and system architecture using Nano Banana Pro.

What tools does Blueprint expose?

2 in total: 0 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Blueprint safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Blueprint need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (c9179dc6d51f), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement