Atlas / MCP servers / codeofaxel / Kiln

KilnBLOCK

mcp/codeofaxel/kiln

Describe it or draw it — Kiln makes it real. The open-source MCP server for 3D printing: AI agents (Claude, Codex, Cursor, or any MCP client) design, generate, slice & print on Bambu Lab, Creality, Prusa, Elegoo, Klipper/Moonraker, OctoPrint, Duet/RepRapFirmware & any Marlin printer.

Verdict
BLOCK
Grade
F
Trust score
36 /100
Exposed tools
200 224r · 61w · 6d
Transport
stdio
License
AGPL-3.0
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The open-source MCP server for 3D printing.

Kiln lets AI agents (Claude Desktop, Claude Code, Codex, or any custom MCP client) drive real 3D printers end to end — Bambu Lab, Creality, Prusa, Elegoo, Voron, Sovol, AnkerMake, Artillery, FlashForge, QIDI, RatRig, and SparkX, over OctoPrint, Moonraker/Klipper, PrusaLink, and Direct USB.

In a single conversation, an agent can design a part, slice it, queue it on the right printer, monitor the camera, recover from failures, and ship the result. No human in the middle.

Reading this as an AI agent? **kiln3d.com/agents** is written for you rather than for the person running you: install, MCP config, the design-to-print loop, and exactly what Kiln will refuse to do and why.
pip install kiln3d
Read from source at commit 6b5e5ba35f29OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add kiln3d --env KILN_PRINTER_API_KEY=${KILN_PRINTER_API_KEY} -- uvx kiln3d==1.4.1.1 serve
03

Exposed tools (200)

224 read · 61 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
acquire_printer_lockreadAcquire an exclusive lock on a printer for safe concurrent access.
add_assembly_interfacewriteAdd a mating interface between two parts in an assembly.
add_assembly_partwriteAdd a part to an existing assembly.
add_mesh_chamferwriteBevel a part
add_mesh_filletwriteRound a part
analyze_design_requirementsreadAnalyze a functional requirement and return technical recommendations.
analyze_generation_feedbackreadAnalyze a generated model and get feedback for improvement.
analyze_non_manifold_edgesreadCount and classify non-manifold edges in a mesh.
analyze_print_failure_smartreadClassify a print failure and suggest recovery steps.
analyze_scad_codereadAnalyze the structure of OpenSCAD code.
analyze_structural_risksreadAnalyze an STL mesh for structural weak points.
analyze_warping_riskreadAnalyze warping risk for a 3D model based on geometry and material.
apply_decorationwriteApply a saved decoration to a new model — proven settings, one call.
apply_design_reinforcementswriteAnalyze a part for structural risks, then auto-apply fixes.
arrange_parts_on_platereadPack multiple STL files onto a virtual build plate.
assess_load_bearingreadAnalyze load-bearing characteristics of a mesh from its geometry.
audit_original_designwriteRun a ruthless audit of an original design before printing.
auto_arrange_parts_on_platereadCalculate non-overlapping XY positions for multiple parts on a print plate.
auto_color_by_heightreadSplit a 3D model into horizontal color zones by Z-height.
auto_color_by_regionreadSplit a 3D model into color zones by geometric region.
auto_orient_modelreadFind the optimal print orientation for a 3D model.
await_generationreadWait for a generation job to complete and return the final status.
backup_databasereadBack up the Kiln database with optional credential redaction.
boolean_mesh_opreadPerform a CSG boolean operation on two or more STL meshes.
build_generation_promptreadBuild a design-aware generation prompt for original 3D creation.
build_parametric_promptreadBuild a prompt optimized for parametric OpenSCAD code generation.
cache_designreadCache a 3D design file for faster access and version tracking.
cache_design_with_sourcereadCache a design file alongside its parametric source code.
cache_modelwriteAdd a 3D model file to the local cache for reuse across jobs.
can_askreadWhether this connection
cancel_print_recoveryreadCancel an active recovery session.
cancel_print_service_orderwriteCancel a print service order.
cancel_split_planreadCancel all pending/in-progress parts of a split plan.
center_model_on_bedreadCenter a mesh on the build plate and place at z=0.
check_assembly_clearancesreadCheck clearances between all mating parts in an assembly.
check_firmware_statusreadCheck firmware version for a specific printer by name (fleet-level, firmware manager).
check_material_environmentreadCheck whether a material is compatible with an environment, and
check_material_sufficiencyreadCheck if a printer has enough material for a print job.
check_multi_material_pairingreadCheck if two materials can be co-printed in dual extrusion.
check_my_tierreadCheck the user
check_print_healthreadPerform a single-shot health assessment of the current print.
check_print_readinessreadSingle-call print readiness check with optional auto-repair.
check_printer_material_compatibilityreadCheck if a specific printer can handle a material.
check_step_supportwriteCheck which STEP import backends are available on this system.
community_statsreadGet overall print-registry statistics.
compare_mesh_versionsreadCompare two mesh files and report geometric differences.
compile_scadreadCompile OpenSCAD source into a mesh.
complete_print_recoveryreadMark a recovery session as completed.
compose_assembly_partsreadCompose all assembly parts into a single output STL file.
compose_modelswriteMerge multiple mesh files into a single combined model.
compose_part_from_primitivesreadBuild a functional part by composing geometric primitives with booleans.
confirm_print_recoveryreadConfirm that a recovery plan should proceed.
connect_provider_accountreadConnect a local printer to a provider account (integration path).
consent_window_statusreadWhich standing consent windows are open, for what, until when.
consumer_onboardingreadGet the guided onboarding workflow for users without a 3D printer.
contribute_community_printreadContribute a print outcome to the community registry.
create_assemblywriteCreate a new empty assembly.
create_print_service_orderwriteCreate a Print-as-a-Service order and get a quote.
cross_section_viewreadCompute a 2D cross-section of a mesh at a cutting plane.
decoration_inforeadGet full details about a saved decoration.
decoration_quota_statusreadCheck your decoration quota — how many decorations you
delete_agent_notedestructiveRemove a stored note or preference.
delete_cached_modeldestructiveRemove a model from the local cache (file and metadata).
delete_shipping_profiledestructiveDelete a saved local shipping profile.
design_advisorreadAsk which generation method to use for a design idea (triage tool — call FIRST).
design_improvement_planreadGenerate a complete structural improvement plan for a design.
detect_mesh_pocketsreadDetect pockets and cavities in a mesh before multi-part composition.
detect_print_failurereadAnalyze printer telemetry to detect and classify a print failure.
diagnose_meshreadDeep mesh defect analysis — self-intersections, holes, normals, fragments (defect-focused).
diagnose_print_failure_livereadDiagnose a print failure using live printer state + model geometry.
diff_design_versionsreadCompute a unified diff between two design versions.
discover_printersreadScan the local network for 3D printers.
donate_inforeadGet crypto wallet addresses to tip/donate to the Kiln project.
download_generated_modelreadDownload a completed generated model, check it, and open it on the stage.
download_modelreadDownload model file(s) from a marketplace to local storage.
estimate_before_designreadEstimate print time, cost, and filament usage BEFORE generating a model.
estimate_costreadEstimate the cost of a print job from a G-code file (already-sliced only).
estimate_material_costreadEstimate material usage and cost for printing a mesh.
estimate_pricereadGet an instant price estimate before requesting a full quote.
estimate_print_progressreadEstimate print progress with phase-aware time prediction.
estimate_print_timereadEstimate print time and filament usage for a model.
estimate_structural_loadreadEstimate safe structural load for a cantilevered section.
estimate_support_materialreadEstimate support material needed for a mesh.
estimate_supportsreadEstimate support volume for a 3D model.
estimate_timelinewriteEstimate order-to-delivery timeline with per-stage breakdown.
export_model_3mfreadExport a mesh to 3MF format (preferred by modern slicers).
extract_model_from_3mfreadExtract the embedded 3D model from a .3mf or .gcode.3mf file to STL.
failure_historyreadView failure history for a printer or failure type.
find_material_matchreadFuzzy-match a catalog entry from spool metadata.
find_printers_with_materialreadFind printers that have a specific material loaded.
find_provider_capacityreadFind available provider capacity by material/location.
find_similar_printsreadFind similar models in the print DNA knowledge base.
find_slicerreadCheck if a slicer (PrusaSlicer/OrcaSlicer) is available on the system.
fingerprint_modelreadCompute a geometric fingerprint for a 3D model file.
firmware_statusreadCheck firmware updates on the default/connected printer (adapter-level, no name needed).
first_layer_statusreadCheck the status of a first-layer monitor.
forecast_material_consumptionwriteForecast when a material type will run out.
fulfillment_alertswriteCheck for fulfillment order alerts (stalled, failed, cancelled orders).
fulfillment_cancelwriteCancel a fulfillment order (if still cancellable).
fulfillment_materialsreadList available materials from external manufacturing services.
fulfillment_orderwritePlace a manufacturing order based on a previous quote.
fulfillment_order_statuswriteCheck the status of a fulfillment order.
fulfillment_quotereadGet a manufacturing quote for a 3D model from Craftcloud.
generate_and_printwriteFull pipeline: generate a model, validate, slice, and upload (preview).
generate_modelreadGenerate a 3D model from a text prompt via external AI API (Meshy/etc).
generate_model_from_imagereadMake a 3D model from a reference image.
generate_model_with_providerreadGenerate a printable design via an external AI provider.
generate_print_certificatereadGenerate a print
generate_template_variationsreadGenerate multiple variations of a parametric template.
generate_texturereadCloud AI texture generation (requires Meshy API key + internet).
generation_feedback_loop_statusreadCheck the status of a generation feedback loop.
generation_statusreadCheck the status of a model generation job.
get_active_materialreadGet the filament physically active in the AMS hardware right now (Bambu Lab).
get_cached_designreadRetrieve a cached design by ID.
get_cached_modelreadReturn details for a specific cached model.
get_community_insightreadGet aggregated print data for a model geometry.
get_design_sourcereadRetrieve the parametric source code for a cached design.
get_design_versionreadRetrieve a single design version by its ID.
get_fleet_material_summaryreadAggregate material inventory across all printers and spools.
get_joint_recommendationreadGet recommended clearance settings for a joint type and material pairing.
get_material_consumption_historyreadGet material consumption history from completed prints.
get_material_design_profilereadCompatibility lookup for a material
get_material_inforeadGet detailed information for a specific material by ID.
get_material_purchase_urlsreadGet purchase URLs for a material.
get_model_print_historyreadGet all print attempts for a model.
get_post_processing_guidewriteGet bounded public post-processing help for one goal.
get_print_diagnosticreadGet a comprehensive print diagnostic combining multiple knowledge sources.
get_printer_insightsreadQuery cross-printer learning insights for a specific printer.
get_recovery_gcode_stepsreadGet the G-code/commands for executing a recovery.
get_recovery_planreadGet a recovery plan for a specific failure type.
get_recovery_session_statusreadGet the current status of a recovery session.
get_recovery_statisticsreadGet historical recovery success rates and failure distribution.
get_restock_suggestionsreadFind materials running low and generate purchase links.
get_safety_profilereadGet the full safety profile for a specific printer model.
get_session_logreadReturn the full audit log for an agent session.
get_skill_manifestreadGet the Kiln skill manifest for agent self-discovery.
get_slicer_profilereadGet the full bundled slicer profile for a printer model.
get_startedwriteQuick-start guide for AI agents using Kiln.
give_print_codereadRelay the code the person typed after Kiln showed one on their screen.
hand_back_printerwriteTell Kiln you are taking a printer from here, so it can move on.
health_checkreadReturn system health information for monitoring.
hollow_mesh_modelwriteCreate a hollow version of a mesh to save material.
import_step_filewriteImport a STEP (.step/.stp) CAD file and convert it for Kiln
improve_generation_promptreadGenerate an improved prompt from feedback.
infer_print_settingsreadInfer optimal slicer settings from structural analysis.
insert_into_scadwriteInsert code into an OpenSCAD module without replacing it.
issue_shipping_confirmation_tokenreadIssue a single-use token after the user confirms shipping details.
iterate_designreadAutomated design iteration: generate -> validate -> improve -> regenerate.
job_historyreadGet history of completed, failed, and cancelled print jobs.
kiln_healthreadGet a health check for the Kiln system.
kiln_monitor_controlreadInternal support for Kiln
kiln_monitor_snapshotreadInternal support for Kiln
kiln_signinwriteStart a Kiln sign-in via OAuth.
kiln_signin_pollreadCheck whether a sign-in started by ``kiln_signin`` is done.
kiln_spend_caps_confirm_changereadConfirm a cap change with the person
kiln_spend_caps_confirm_order_approvalwriteConfirm a one-order approval with the person
kiln_spend_caps_request_changewriteAsk to raise the per-order and/or monthly spend cap (step 1 of 2).
kiln_spend_caps_request_order_approvalwriteAsk to approve ONE order over the cap (step 1 of 2).
kiln_spend_caps_showreadShow your current Kiln spend caps and whether chat may change them.
kiln_startup_diagnosiswriteWhy the Kiln server failed to start, in plain language, with the fix.
kiln_viewer_payloadreadInternal support for Kiln
list_available_materialsreadList all available 3D printing materials with properties.
list_cached_designsreadList cached designs, optionally filtered by material.
list_cached_modelsreadList all models in the local cache, newest first.
list_credentialsreadList all stored credentials (metadata only, no plaintext).
list_decorationsreadList all saved decorations in the library.
list_design_componentsreadList available pre-built OpenSCAD components from bundled libraries.
list_design_materialsreadList public material identifiers and safety/process summaries.
list_design_templates_catalogreadBrowse the whole design-template library, both kinds.
list_design_versionsreadList version history for a design, newest first.
list_generation_providersreadList available text-to-3D generation providers.
list_materialsreadreturn {
list_multi_material_addonswriteList available multi-material add-on systems for 3D printers.
list_print_pipelinesreadList all available pre-validated print pipelines.
list_printer_variantsreadShow the curated hardware variants available for a printer.
list_provider_capacityreadList printers registered with connected provider integrations.
list_published_modelsreadList models that have been published to marketplaces.
list_safety_profilesreadList all available printer safety profiles.
list_shipping_profilesreadList saved local shipping profiles.
list_slicer_profilesreadList all bundled slicer profiles for supported printers.
list_trusted_printersreadReturn the list of trusted printer hostnames/IPs.
marketplace_diagnosticswriteRun connectivity checks against all configured marketplaces.
marketplace_statusreadCheck which 3D model marketplaces are connected and available.
match_design_componentsreadFind pre-built library components matching a design description.
match_design_requirementswriteIdentify which functional requirements apply to a design task.
merge_mesh_fileswriteCombine multiple STL files into a single mesh file (simple concatenation).
mesh_quality_scorecardreadAssess a model — a graded scorecard for a mesh, an intake
mirror_mesh_modelreadMirror (reflect) a mesh along an axis.
model_filesreadList downloadable files for a Thingiverse model.
model_revenuereadGet revenue summary for a specific model.
modify_scad_modulewriteReplace a module in OpenSCAD code with new implementation.
monitor_printreadOne-shot print status report.
monitor_print_visionreadSnapshot + structured data for AI visual inspection of an in-progress print.
my_toolreadreturn {
optimize_fleet_assignmentreadAssign print jobs to printers by material availability.
optimize_print_orientationreadAuto-rotate a mesh to minimize overhangs and maximize bed contact.
optimize_template_paramsreadFind the structurally strongest version of a parametric template.
paint_decoration_facesreadPaint exactly the faces a decoration carve created (Pro-free).
parse_scad_parametersreadParse parameter variables from OpenSCAD code.
pipeline_abortreadAbort a running or paused pipeline.
04

Trust audit

BLOCKgrade F · trust 36/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (11 observation(s))
Shell
declared (10 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/audit_import_targets.py:522
exec(compile(Path(args.known_from).read_text(encoding="utf-8"), args.known_from, "exec"), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
kiln/src/kiln/bridge_client.py:586
session = self._session_verdict(verify=False)
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SKILL.md:80
- Never repeat a printer access code or an API key back in the conversation.
Why it matters. asks the agent to read credentials
MEDIUMInventory / provenance · inv.binary · CWE-1104
kiln/src/kiln/data/notifier/Kiln.app/Contents/MacOS/kiln-notifier
kiln-notifier
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
kiln/src/kiln/data/notifier/Kiln.app/Contents/Resources/Kiln.icns
Kiln.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
kiln/src/kiln/__init__.py:110
__import__(fqn)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
kiln/src/kiln/__init__.py:114
__import__(fqn)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
kiln/src/kiln/_pro_camera_bridge.py:124
camera_word = importlib.import_module(LOCAL_MODULE).camera_word
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
kiln/src/kiln/_pro_material_rules_bridge.py:42
check = importlib.import_module(LOCAL_MODULE).rule_check
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
kiln/src/kiln/generation/registry.py:104
mod = importlib.import_module(module_path)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
kiln/src/kiln/auth.py:348
logger.info("Revoked API key %r (id=%s)", api_key.name, key_id)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
kiln/src/kiln/auth.py:363
logger.info("Revoked API key %r (id=%s)", api_key.name, api_key.id)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
kiln/src/kiln/machine_motion.py:95
if any(_cfg_has_prefix(config, name) for name in ("probe_eddy_current", "beacon", "cartographer", "scanner")):
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
kiln/src/kiln/print_service.py:58
callback_url: str | None = None  # webhook for status updates
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
kiln/src/kiln/print_service.py:258
callback_url=request.callback_url,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
kiln/src/kiln/print_service.py:429
callback_url: str | None = None,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
kiln/src/kiln/print_service.py:459
callback_url,
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
kiln/src/kiln/ams_routing.py:549
+ (f" (nearest: {nearest[0].label}, ΔE {nearest[1]:.0f})" if nearest else "")
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
kiln/src/kiln/ams_routing.py:681
f" — nearest is {m['nearest']} (ΔE {m['delta_e']:.0f})"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
kiln/tests/test_agent_loop.py:55
cfg = AgentConfig(api_key="sk-or-very-secret-key-12345")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
kiln/tests/test_cloud_sync.py:59
c = SyncConfig(cloud_url="https://x.com", api_key="secret-key-here-long")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
kiln/tests/test_served_files.py:185
token = "QzN57tLRbyH2N-ZAHsJrK3vJX_k51thF"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
kiln/tests/test_served_makes.py:32
TOKEN = "QzN57tLRbyH2N-ZAHsJrK3vJX_k51thF"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_agent_note, delete_cached_model, delete_shipping_profile, remove_mesh_floating_regions, revoke_consent_window, untrust_printer
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clawignore
.clawignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6b5e5ba35f29full audit observations/trust-audit/mcp-server/codeofaxel__kiln.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086b5e5ba35f29BLOCKF36first audit
06

Questions

What is the Kiln MCP server?

Describe it or draw it — Kiln makes it real. The open-source MCP server for 3D printing: AI agents (Claude, Codex, Cursor, or any MCP client) design, generate, slice & print on Bambu Lab, Creality, Prusa, Elegoo, Klipper/Moonraker, OctoPrint, Duet/RepRapFirmware & any Marlin printer.

What tools does Kiln expose?

200 in total: 224 read-only, 61 that write, and 6 that can delete or overwrite (delete_agent_note, delete_cached_model, delete_shipping_profile). Every one is listed on this page with its risk.

Is Kiln safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (36/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Kiln need?

It reads KILN_3DOS_API_KEY, KILN_AUDIT_HMAC_KEY, KILN_AUTH_ENABLED, KILN_AUTH_HOME, KILN_AUTH_KEY, KILN_CREDENTIAL_DB_PATH, KILN_CULTS3D_API_KEY, KILN_GEMINI_API_KEY, KILN_LICENSE_KEY, KILN_LIVE_OCTOPRINT_KEY, KILN_MASTER_KEY and KILN_MESHY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kiln run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as kiln3d at 1.2.0.

How current is this page?

The grade is for one exact copy of the source (6b5e5ba35f29), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement