Atlas / MCP servers / daobataotie / Cad

CadSAFE

mcp/daobataotie/cad-1

CAD MCP Server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
24 18r · 6w · 0d
Transport
streamable-http
License
MIT
Stars
574
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

Project Introduction

CAD-MCP is an innovative CAD control service that allows controlling CAD software for drawing operations through natural language instructions. This project combines natural language processing and CAD automation technology, enabling users to create and modify CAD drawings through simple text commands without manually operating the CAD interface.

Version 2.0 is fully upgraded based on the latest MCP specification (FastMCP, structured output, tool annotations, progress notifications, Streamable HTTP), and adds 35 tools in total covering querying, editing, layers, drawing management, blocks, and command passthrough — forming a complete "draw → inspect → correct" feedback loop.

Features

CAD Control Functions

  • Multiple CAD Software Support: Supports mainstream CAD software including AutoCAD, GstarCAD (GCAD) and ZWCAD
  • Basic Drawing Functions:
  • Line drawing
  • Circle drawing
  • Arc drawing
  • Ellipse drawing
  • Rectangle drawing
  • Polyline drawing
  • Text addition
  • Pattern filling
  • Dimension annotation
  • Query Functions (the AI can see the actual drawing content):
  • List all layers
  • List entities in model space (returns editable entity handles)
  • Query detailed entity properties by handle (coordinates/radius/text content, etc.)
  • Screenshot of the CAD window for preview
  • Editing Functions: erase, move, rotate, scale, copy, mirror, offset, array (linear/polar), undo/redo
  • Layer Management: Create and switch layers, query layer states
  • Drawing Management: New / open / close / save drawings (DWG/DXF)
  • Block Operations: Create, insert, and list blocks
  • Command Passthrough: Execute any CAD command via send_command (an escape hatch for everything else)

MCP Protocol Features

  • Structured Output: All tools return structuredContent with an outputSchema that clients
Read from source at commit 9d178617ba21OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add cad-mcp -- uvx cad-mcp
claude-desktop
{
  "mcpServers": {
    "cad-mcp": {
      "command": "uvx",
      "args": [
        "cad-mcp"
      ]
    }
  }
}
03

Exposed tools (24)

18 read · 6 write · 0 destructive.

ToolRiskDescription
add_dimensionwrite在CAD中添加线性标注(text_position 不指定时自动放在中点上方)
array_linear_entityread矩形阵列:沿位移向量方向复制 count-1 份(含原实体共 count 个)
array_polar_entityread环形阵列:绕中心点在 total_angle 角度范围内复制 count-1 份
copy_entityread复制实体并平移指定位移,返回新实体句柄
create_blockwrite创建图块定义(若同名图块已存在则直接返回)
create_layerwrite创建新图层并设为当前图层(若已存在则直接激活)
draw_arcread在CAD中绘制弧(角度单位:度)
draw_circleread在CAD中绘制圆
draw_ellipseread在CAD中绘制椭圆(rotation 为旋转角度,单位:度)
draw_hatchread在CAD中绘制填充(points 为闭合边界点集,至少3个点)
draw_lineread在CAD中绘制直线
draw_polylineread在CAD中绘制多段线(closed=True 时闭合)
draw_rectangleread在CAD中绘制矩形(由两个对角点确定)
draw_textread在CAD中添加单行文本
insert_blockwrite在模型空间插入图块引用(返回图块引用实体的句柄)
mirror_entityread沿两点确定的镜像轴镜像实体(保留原实体),返回新实体句柄
move_entitywrite移动实体(displacement 为位移向量 [dx, dy, dz])
offset_entityread偏移实体(正负值决定偏移方向),返回新实体句柄
process_commandread处理自然语言命令并转换为CAD操作(遗留接口)
redoread重做被撤销的操作
rotate_entityread绕基点旋转实体(角度单位:度,逆时针为正)
scale_entityread绕基点缩放实体(scale_factor>1 放大,<1 缩小)
set_current_layerwrite切换当前图层(图层必须已存在)
undoread撤销上一步操作
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:123
# Clients connect to http://127.0.0.1:8000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:143
For Streamable HTTP mode, point the client to `http://127.0.0.1:8000/mcp` instead.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_en.md:123
# Clients connect to http://127.0.0.1:8000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_en.md:143
For Streamable HTTP mode, point the client to `http://127.0.0.1:8000/mcp` instead.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README_zh.md:123
# 客户端连接 http://127.0.0.1:8000/mcp
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, pywin32, pydantic, Pillow
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
imgs/demo.gif
imgs/demo.gif
Why it matters. 6645021 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 9d178617ba21full audit observations/trust-audit/mcp-server/daobataotie__cad-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-309d178617ba21SAFEB89first audit
06

Questions

What is the Cad MCP server?

CAD MCP Server

What tools does Cad expose?

24 in total: 18 read-only, 6 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Cad safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Cad need?

No credential environment variables were found in its source, so it appears to need none.

How does Cad run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as cad-mcp.

How current is this page?

The grade is for one exact copy of the source (9d178617ba21), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement