BlueprintSAFE
Diagram generation for understanding codebases and system architecture using Nano Banana Pro.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Image generated using Blueprint MCP, Nano Banana Pro, and Arcade MCP server.
Diagram generation for understanding codebases and system architecture using Nano Banana Pro.
Works with Arcade's ecosystem: Combine with HubSpot, Google Drive, GitHub, and other Arcade tools to extract data from your systems and visualize it as diagrams.
Setup
1. Sign up for Arcade
https://arcade.dev
2. Install Dependencies
# Create virtual environment python3 -m venv venv source venv/bin/activate # On Windows: venv\Scripts\activate # Install Arcade CLI pip install arcade-mcp
3. Login to Arcade
arcade-mcp login
4. Get Google AI Studio API Key
https://aistudio.google.com/ → Create API key
5. Store Secret in Arcade
arcade-mcp secret set GOOGLE_API_KEY="your_api_key_here"
6. Deploy Server
Clone this repo, then:
cd blueprint-mcp arcade-mcp deploy
7. Create Gateway
- Go to https://api.arcade.dev/dashboard
- Click "Gateways" → "Create Gateway"
- Add your deployed
architect_mcpserver to the gateway
8. Configure Cursor
- In Cursor: Settings → MCP
- Add your Arcade gateway URL
- Restart Cursor
Usage
Tools
start_diagram_job- Start generation, returns job IDcheck_job_status- Check if completedownload_diagram- Download PNG as base64
Example Prompts
Visualize code architecture:
Analyze the authentication module in src/auth/ and create an architecture diagram showing the components and their relationships.
Document API flows:
Create a sequence diagram showing the OAuth login flow based on the code in src/auth/oauth.py
Explain processes:
Generate a flowchart explaining how our payment processing works, showing the steps from checkout to confirmation.
Understand data pipelines:
Create a data flow diagram for our ETL pipeline showing sources, transformati
c9179dc6d51fOBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add blueprint-mcp -- uvx blueprint-mcp
{
"mcpServers": {
"blueprint-mcp": {
"command": "uvx",
"args": [
"blueprint-mcp"
]
}
}
}Exposed tools (2)
0 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
edit_diagram | write | Edit a previously generated diagram. Pass the file_uri from download_diagram. The file_uri references the image stored in Google |
start_diagram_job | write | Start async diagram generation on the server. Returns a job ID. Poll with check_job_status, then retrieve the image with download_diagram. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
return base64.b64decode(img_data)
images/arcade_enterprise_banking.png
images/blueprint-mcp.png
images/langgraph_architecture_learning_card.png
Gates applied: no_behavioural_pass, no_license.
c9179dc6d51ffull audit observations/trust-audit/mcp-server/arcadeai__blueprint-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | c9179dc6d51f | SAFE | B | 89 | first audit |
Questions
What is the Blueprint MCP server?
Diagram generation for understanding codebases and system architecture using Nano Banana Pro.
What tools does Blueprint expose?
2 in total: 0 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Blueprint safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Blueprint need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (c9179dc6d51f), read on 2026-09-28. The repository is watched and re-audited when it changes.