Atlas / MCP servers / dmontgomery40 / 3D Printer Server

3D Printer ServerBLOCK

mcp/dmontgomery40/3d-printer-server

Connects MCP to major 3D printer APIs (Orca, FULU's Orca/Bambu, OctoPrint, Klipper, Duet, Repetier, Prusa, Creality). Control prints, monitor status, and perform advanced STL operations like scaling, rotation, sectional editing, and base extension. Includes slicing and visualization.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
28 18r · 10w · 0d
Transport
stdio · streamable-http
License
GPL-2.0
Stars
245
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Thank you, [FULU Foundation](https://www.fulu.org/), [Louis Rossmann](https://www.youtube.com/@rossmanngroup), and the [OrcaSlicer-bambulab contributors](https://github.com/FULU-Foundation/OrcaSlicer-bambulab). Thank you for standing up for consumer ownership, open-source developers, repair rights, and owners whose working hardware should not be made worse by locked-down software. This server treats the FULU OrcaSlicer-bambulab fork as a first-class slicer for Bambu Lab projects. See the FULU guide for setup and current status.

[](https://www.npmjs.com/package/mcp-3d-printer-server) [](https://www.npmjs.com/package/mcp-3d-printer-server) [](https://www.gnu.org/licenses/old-licenses/gpl-2.0.en.html) [](https://nodejs.org/en/download/) [](https://github.com/DMontgomery40/mcp-3D-printer-server)

An MCP server that connects Claude, Codex, and other MCP clients to 3D printers running OctoPrint, Klipper (Moonraker), Duet, Repetier-Server, Bambu Lab, PrusaLink or Prusa Connect, and Creality. Your agent can check status, upload and start jobs, cancel prints, edit STL meshes, run your slicer, and hand models to Blender through an optional Blender MCP bridge.

[Browse the documentation site](https://dmontgomery40.github.io/mcp-3D-printer-server/) for searchable setup guides, per-printer credentials, slicing, and the full tool reference. It is generated from this README and the docs folder.

Only print on Bambu Lab printers? [bambu-printer-

Read from source at commit c3b24229d856OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-3d-printer-server-site --env API_KEY=${API_KEY} --env BAMBU_TOKEN=${BAMBU_TOKEN} -- npx -y mcp-3d-printer-server-site
claude-desktop
{
  "mcpServers": {
    "mcp-3d-printer-server-site": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-3d-printer-server-site"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "BAMBU_TOKEN": "${BAMBU_TOKEN}"
      }
    }
  }
}
03

Exposed tools (28)

18 read · 10 write · 0 destructive.

ToolRiskDescription
blender_mcp_callreadCall a discovered tool on the configured Blender MCP server, preserving its full MCP content and errors. Discover tool schemas with blender_mcp_status first; execute_blender_code accepts Python code and user_prompt. Calls can modify the active Blender scene and are never automatically retried.
blender_mcp_edit_modelwriteImport, edit, and export a local STL through standard Blender MCP with verified output and existing scene objects preserved. Requires a shared local filesystem and Blender Object Mode. Also supports a separately configured legacy executable bridge.
blender_mcp_statusreadInspect Blender MCP configuration or connect and discover the remote server
cancel_printreadCancel the current print job
center_modelreadTranslate the model so its geometric center is at the origin (0,0,0).
check_fulu_orca_setupwriteInspect a FULU OrcaSlicer-bambulab install, platform runtime payload, setup commands, and optionally probe the BambuNetwork bridge.
confirm_temperaturesreadReport every heater target in a G-code file (S and R forms, tool-addressed, RepRapFirmware G10/M568 and Klipper SET_HEATER_TEMPERATURE). An expected temperature matches only when it equals the file
execute_blender_codewriteExecute arbitrary Python code in Blender.\n\n Parameters: long details that status summaries omit.
extend_stl_basereadExtend the base of an STL file by a specified amount
generate_stl_visualizationreadGenerate an SVG visualization of an STL file from multiple angles
get_printer_statusreadGet the current status of the 3D printer
get_slice_settingsreadInspect slicer settings in a 3MF template or JSON/config profile without slicing (layer height, infill, walls, supports, brim, bed, printer, filaments).
get_stl_inforeadGet detailed information about an STL file
lay_flatreadAttempt to rotate the model so its largest flat face lies on the XY plane (Z=0).
list_printer_filesreadList files available on the 3D printer
list_templatesreadList saved slicing templates (.3mf, .json, .config) in the local template registry directory.
merge_verticeswriteMerge vertices in an STL file that are closer than the specified tolerance.
modify_stl_sectionwriteApply a specific transformation to a selected section of an STL file
print_3mfreadPrint a 3MF file on a Bambu Lab printer. The exact selected plate is inspected (model, nozzle, bed type, materials, every heater target) and checked against a fresh MQTT report of the printer
process_and_print_stlwriteProcess an STL file (extend base), slice it, and start printing through the same checked print gate as upload_gcode/print_3mf. Expected temperatures are enforced: a mismatch refuses before upload.
rotate_stlreadRotate an STL model around specific axes
save_templatewriteCopy a .3mf, .json, or .config file into the local template registry under a template name.
scale_stlreadScale an STL model uniformly or along specific axes
set_printer_temperaturewriteSet the temperature of a printer component. Temperature 0 switches a heater off and is never gated. Positive targets are validated before connecting, limited by independent hardware and material ceilings, require a ready printer and a human confirmation.
slice_stlreadSlice an STL or 3MF file to generate G-code or a sliced 3MF. For Bambu-compatible CLI slicing
slice_with_templatereadSlice an STL or 3MF with a named template from the local template registry (BAMBU_TEMPLATE_DIR).
translate_stlwriteMove an STL model along specific axes
upload_gcodewriteUpload G-code content or a local G-code file path to the printer. With print=true the exact uploaded bytes are inspected first (every S/R heater target, tool changes, hardware and material ceilings), printer state is checked, and a human confirmation is requested before the print starts.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/printers/bambu.ts:743
secureOptions: { host, rejectUnauthorized: false, minVersion: "TLSv1.2" as const, maxVersion: "TLSv1.2" as const },
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHContainer / deploy · priv.container · CWE-250, CWE-16
scripts/docker-run.sh:13
--network host \
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
README.md:538
Call one FULU BambuNetwork bridge method for diagnostics. Read-only methods such as `bridge.handshake`, `bridge.runtime_info`, and `net.get_user_print_info` are allowed by default. Agent and session s
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/fulu-orca.ts:159
return existingPath(["/usr/local/bin/orcaslicer", "/usr/bin/orcaslicer"]) || "orcaslicer";
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/index.ts:122
"/usr/local/bin/orcaslicer",
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/index.ts:134
"/usr/local/bin/bambustudio",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/test-package.mjs:52
const endpoint = new URL(`http://127.0.0.1:${port}/mcp`);
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/fixtures/ftps/key.pem:1
-----BEGIN PRIVATE KEY-----
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/printers/bambu.ts:249
md5: createHash("md5").update(gcodeBuffer).digest("hex"),
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/safety/archive.test.mjs:122
assert.equal(selected.md5, createHash('md5').update(safe + 'G1 X2\n').digest('hex'));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/safety/archive.test.mjs:7
import { inspectPrintFile } from '../../dist/safety/print-file.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/safety/archive.test.mjs:8
import { BambuImplementation } from '../../dist/printers/bambu.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/safety/bambu-dispatch.test.mjs:7
import { BambuImplementation } from "../../dist/printers/bambu.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/safety/gcode-thermal.test.mjs:12
} from "../../dist/safety/gcode-thermal.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/safety/gcode-thermal.test.mjs:13
import { STLManipulator } from "../../dist/stl/stl-manipulator.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/SETUP.md:415
The endpoint is `http://127.0.0.1:3000/mcp` by default. The server binds to `127.0.0.1` unless you set `MCP_HTTP_HOST`. It has no built-in authentication, so keep it on a trusted network and restrict 
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/behavior.test.mjs:117
const endpoint = `http://127.0.0.1:${port}/mcp`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/behavior.test.mjs:730
expectedUrl: "http://192.168.1.50:8080/api/v1/status",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/behavior.test.mjs:1238
const endpoint = `http://127.0.0.1:${port}/mcp`;
LOWContainer / deploy · priv.container · CWE-250, CWE-16
docs/SETUP.md:396
docker run --rm -i --network host --env-file .env mcp-3d-printer-server
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, bambu-js, basic-ftp, dotenv, form-data, jszip, three
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CONTRIBUTORS.md:19
| [Lickitysplitted](https://github.com/Lickitysplitted) | Diagnoses Bambu FTPS "Premature close" upload failures on an X1C as missing TLS session reuse in [#22](https://github.com/DMontgomery40/mcp-3D
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/SETUP.md:352
- **FTPS (port 990, implicit TLS):** Uploads use `basic-ftp` directly with TLS 1.2 on both channels and TLS session reuse, which the printer requires. This addresses the "Premature close" failures in 
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/SETUP.md:360
The adapter sends the key as both `X-Api-Key` and `Authorization: Bearer`. If a PrusaLink install only accepts username/password (HTTP digest) authentication, this adapter cannot authenticate yet. Req
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
src/test/3DBenchy.3mf
src/test/3DBenchy.3mf
Why it matters. 4871678 bytes not read

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha c3b24229d856full audit observations/trust-audit/mcp-server/dmontgomery40__3d-printer-server.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06c3b24229d856BLOCKD69first audit
06

Questions

What is the 3D Printer Server MCP server?

Connects MCP to major 3D printer APIs (Orca, FULU's Orca/Bambu, OctoPrint, Klipper, Duet, Repetier, Prusa, Creality). Control prints, monitor status, and perform advanced STL operations like scaling, rotation, sectional editing, and base extension. Includes slicing and visualization.

What tools does 3D Printer Server expose?

28 in total: 18 read-only, 10 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is 3D Printer Server safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does 3D Printer Server need?

It reads API_KEY and BAMBU_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does 3D Printer Server run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-3d-printer-server-site.

How current is this page?

The grade is for one exact copy of the source (c3b24229d856), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement