Atlas / MCP servers / dmontgomery40 / Bambu Printer

Bambu PrinterBLOCK

mcp/dmontgomery40/bambu-printer

MCP server for Bambu Lab 3D printers — STL manipulation, BambuStudio or FULU/orca slicing, Blender MCP integration, and direct printer control

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
45 27r · 16w · 2d
Transport
stdio · streamable-http
License
GPL-2.0
Stars
174
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Thank you, [FULU Foundation](https://www.fulu.org/), [Louis Rossmann](https://www.youtube.com/watch?v=1jhRqgHxEP8), and the [OrcaSlicer-bambulab contributors](https://github.com/FULU-Foundation/OrcaSlicer-bambulab). We stand with open-source developers, the right to repair, and your right to control hardware you own. You should be able to choose your software and print without a vendor cloud standing in the way. Want to skip Bambu's software and cloud? Use FULU OrcaSlicer-bambulab to slice and export, then this MCP's direct LAN path on supported printers and firmware. That workflow does not require Bambu Studio, Bambu Connect, or Bambu Cloud. Start with the FULU setup guide. The optional BambuNetwork bridge is a separate path that still uses Bambu's networking runtime; cloud jobs still use Bambu's services.

[](https://www.npmjs.com/package/bambu-printer-mcp) [](https://www.gnu.org/licenses/old-licenses/gpl-2.0.en.html) [](https://www.typescriptlang.org/) [](https://nodejs.org/en/download/) [](https://github.com/DMontgomery40/bambu-printer-mcp) [](https://www.npmjs.com/package/bambu-printer-mcp)

A Bambu Lab-focused MCP server for controlling Bambu printers, manipulating STL files, and managing end-to-end 3MF print workflows from Claude Desktop, Claude Code, or any MCP-compatible client.

[Browse the documentation site](https://dmontgomery40.github.io/bambu-printer-mcp/) for searchable

Read from source at commit dac5c7bfed4cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add bambu-printer-mcp-site --env BAMBU_CLIENT_KEY=${BAMBU_CLIENT_KEY} --env BAMBU_PRINTER_ACCESS_TOKEN=${BAMBU_PRINTER_ACCESS_TOKEN} --env BAMBU_TOKEN=${BAMBU_TOKEN} -- npx -y bambu-printer-mcp-site
claude-desktop
{
  "mcpServers": {
    "bambu-printer-mcp-site": {
      "command": "npx",
      "args": [
        "-y",
        "bambu-printer-mcp-site"
      ],
      "env": {
        "BAMBU_CLIENT_KEY": "${BAMBU_CLIENT_KEY}",
        "BAMBU_PRINTER_ACCESS_TOKEN": "${BAMBU_PRINTER_ACCESS_TOKEN}",
        "BAMBU_TOKEN": "${BAMBU_TOKEN}"
      }
    }
  }
}
03

Exposed tools (45)

27 read · 16 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
bambu_connect_import_filewriteOpen an existing G-code or sliced 3MF file in the signed-in Bambu Connect app through its official URL scheme. This is a cloud-mode handoff and does not start printing by itself.
bambu_network_bridge_statusreadInspect or probe the FULU OrcaSlicer-bambulab BambuNetwork bridge runtime used for cloud and restored BambuNetwork printing.
bambu_network_callreadCall a raw FULU OrcaSlicer-bambulab BambuNetwork bridge method, optionally with an initialized network agent injected into the payload.
blender_mcp_callreadCall a discovered tool on the configured Blender MCP server, preserving its full MCP content and errors. Discover tool schemas with blender_mcp_status first; execute_blender_code accepts Python code and user_prompt. Calls can modify the active Blender scene and are never automatically retried.
blender_mcp_edit_modelwriteImport, edit, and export a local STL through standard Blender MCP with verified output and existing scene objects preserved. Requires a shared local filesystem and Blender Object Mode. Also supports a separately configured legacy executable bridge.
blender_mcp_statusreadInspect Blender MCP configuration or connect and discover the remote server
camera_snapshotreadCapture a single JPEG frame from the printer
cancel_printreadCancel the current print job on the Bambu Lab printer
center_modelreadTranslate the model so its geometric center is at the origin (0,0,0)
clear_hms_errorsdestructiveClear HMS or print error state on the Bambu Lab printer using the clean_print_error MQTT command.
delete_printer_filedestructiveDelete a file from the Bambu Lab printer
extend_stl_basereadExtend the base of an STL file by a specified amount
get_printer_filamentsreadGet the live AMS/external filament inventory from the printer over MQTT, including loaded/empty slot summary, resolved slicer profile paths, match confidence, and recommended load_filaments when the printer model is known.
get_printer_statusreadGet the current status of the Bambu Lab printer
get_slice_settingsreadInspect slicer settings from a saved 3MF template or a JSON/config slicer profile without slicing anything.
get_stl_inforeadGet detailed information about an STL file (bounding box, face count, dimensions)
lay_flatreadRotate the model so its largest flat face lies on the XY plane (Z=0)
list_3mf_plate_objectsreadList object IDs from a sliced 3MF plate. Use these IDs with skip_objects during a running print.
list_printer_filesreadList files stored on the Bambu Lab printer
list_templatesreadList saved slicing templates from the local template registry directory.
merge_verticeswriteMerge vertices in an STL file closer than the specified tolerance
pause_printreadPause the current print job on the Bambu Lab printer (resumable via resume_print)
print_3mfreadPrint a 3MF file on a Bambu Lab printer. Auto-slices if the 3MF has no gcode. IMPORTANT: bambu_model must be specified to ensure safe printer operation.
print_3mf_bambu_networkreadPrint a 3MF through FULU OrcaSlicer-bambulab
print_collar_charmreadPrint a prepared two-part dog collar charm project using the fixed tray policy: inner/smaller object -> black on AMS 1 slot 1, outer/larger object -> white on AMS 2 slot 1.
reread_ams_rfidwriteTrigger a Bambu AMS RFID re-read for one AMS slot. X2D on macOS uses the native official plug-in route. This can move AMS filament; use only when the printer is idle and unloaded.
resolve_3mf_ams_slotsreadInspect a sliced 3MF and match its tray_info_idx filament requirements against the live AMS inventory. Does not upload or start a print.
resume_printreadResume a paused print job on the Bambu Lab printer
rotate_stlreadRotate an STL file by specified angles (degrees)
save_templatewriteCopy a 3MF, JSON, or config file into the local template registry and register it under a template name.
scale_stlreadScale an STL file by specified factors
set_airduct_modewriteSet H2/P2 airduct mode to cooling or heating.
set_ams_dryingwriteStart or stop the AMS filament drying cycle. X2D on macOS uses the native official plug-in route and supports AMS-HT id 128.
set_fan_speedwriteSet a Bambu printer fan speed percentage. X2D on macOS uses the installed Bambu networking plug-in without UI automation; other models use MQTT.
set_lightwriteSet a Bambu printer light node mode using the printer
set_print_speedwriteSet the active print speed mode: silent, standard, sport, or ludicrous.
set_temperaturewriteSet a checked bed or nozzle temperature. Positive heating requires matching fresh printer telemetry; nozzle heating also requires declared material. Zero turns the heater off.
skip_objectsreadSkip specific object IDs during a running multi-object print using the printer
slice_stlreadSlice an STL or 3MF file using a slicer to generate printable G-code or sliced 3MF. IMPORTANT: bambu_model must be specified to ensure the slicer generates safe G-code for the correct printer.
slice_with_templatereadSlice an STL or 3MF using a named template from the local registry. This is a higher-level wrapper around slice_stl for template-based workflows.
start_printwriteStart printing a G-code file already on the Bambu Lab printer. Alias of start_print_job for upstream MCP compatibility.
start_print_jobwriteStart printing a G-code file already on the Bambu Lab printer
upload_filewriteUpload a local file to the Bambu Lab printer
upload_gcodewriteInspect a G-code file and upload a uniquely named copy without overwriting existing printer files.
x2d_native_controlwriteRead calibration results or update X2D AMS metadata/calibration selection through the installed plug-in. Raw motion, heating, task control, and safety-setting changes are rejected.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
dist/printers/bambu.js:164
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
dist/printers/bambu.js:225
const opts = { rejectUnauthorized: false, host };
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
dist/printers/bambu.js:1578
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
scripts/probe-h2-raw.mjs:79
{ host, port: 6000, rejectUnauthorized: false },
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/printers/bambu.ts:219
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
AGENTS.md:52
- Validate the selected bundled model's BBL/cli_config.json entry. Apply machine_limits when supplied; official P1S/H2D entries may intentionally contain only downward_check. Distinguish a validated n
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_hms_errors, delete_printer_file
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
dist/printers/bambu.js:441
const md5 = createHash("md5").update(gcodeBuffer).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/printers/bambu.ts:543
const md5 = createHash("md5").update(gcodeBuffer).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/behavior.test.mjs:59
const md5 = createHash("md5").update(Buffer.from(gcode)).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/safety/archive.test.mjs:122
assert.equal(selected.md5, createHash('md5').update(safe + 'G1 X2\n').digest('hex'));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/behavior.test.mjs:1485
bambu.deleteFile("127.0.0.1", "S", "T", "../../etc/passwd", true),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/fixtures/blender-stl-validation.mjs:2
import { BlenderMcpBridge } from "../../dist/blender-mcp-bridge.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/safety/archive.test.mjs:7
import { inspectPrintFile } from '../../dist/safety/print-file.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/safety/archive.test.mjs:8
import { BambuImplementation } from '../../dist/printers/bambu.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/safety/print-file.test.mjs:8
import { resolveBblMachineProfile } from '../../dist/slicer/profile-flatten.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/behavior.test.mjs:2305
const endpoint = `http://127.0.0.1:${port}/mcp`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/behavior.test.mjs:2369
const wrongPathResponse = await fetch(`http://127.0.0.1:${port}/not-mcp`, { method: "POST" });
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/server-temp.test.mjs:100
await client.connect(new StreamableHTTPClientTransport(new URL(`http://127.0.0.1:${port}/mcp`)));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, bambu-js, basic-ftp, dotenv, jszip, mqtt, three, xml2js
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CONTRIBUTORS.md:17
| [Sebastian (sebas1986)](https://github.com/sebas1986) | Isolates the multi-filament CLI crash with real BambuStudio bisection, contributes per-slot colours and multi-nozzle prime-tower placement, an
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:382
- `bambu-cli print start <file>` and `bambu-cli files upload` both fail with `522 SSL connection failed: session reuse required`. Bambu's FTPS server requires TLS session reuse between the control and
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:323
**FTPS (port 990, implicit TLS):** File operations (upload and directory listing) use FTPS. The printer's SD card is accessible as a filesystem with directories including `cache/` (for 3MF and G-code
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:339
await client.access({ host, port: 990, user: "bblp", password: token,
Why it matters. asks the agent to read credentials

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha dac5c7bfed4cfull audit observations/trust-audit/mcp-server/dmontgomery40__bambu-printer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07dac5c7bfed4cBLOCKD69first audit
06

Questions

What is the Bambu Printer MCP server?

MCP server for Bambu Lab 3D printers — STL manipulation, BambuStudio or FULU/orca slicing, Blender MCP integration, and direct printer control

What tools does Bambu Printer expose?

45 in total: 27 read-only, 16 that write, and 2 that can delete or overwrite (clear_hms_errors, delete_printer_file). Every one is listed on this page with its risk.

Is Bambu Printer safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Bambu Printer need?

It reads BAMBU_CLIENT_KEY, BAMBU_PRINTER_ACCESS_TOKEN and BAMBU_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Bambu Printer run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as bambu-printer-mcp-site.

How current is this page?

The grade is for one exact copy of the source (dac5c7bfed4c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement