Atlas / MCP servers / embedded-society / Altium Designer

Altium DesignerCAUTION

mcp/embedded-society/altium-designer

MCP server for AI-assisted management of Altium Designer component libraries

Verdict
CAUTION
Grade
C
Trust score
76 /100
Exposed tools
—
Transport
stdio
License
GPL-3.0
Stars
76
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/embedded-society/altium-designer-mcp/actions/workflows/ci_main.yml) [](https://app.codecov.io/gh/embedded-society/altium-designer-mcp)

Let an AI build your Altium libraries — it does the engineering, this tool writes the files.

An MCP server that gives AI assistants (Claude Code, Claude Desktop, Cursor, Antigravity, VS Code Copilot — any MCP client) file I/O and primitive-placement tools for Altium Designer .PcbLib (footprint) and .SchLib (symbol) libraries — so the AI can create and maintain any component, not just pre-programmed packages.

The Problem

Building Altium component libraries by hand is slow and repetitive — every footprint means looking up IPC-7351B pad sizes, courtyards, and silkscreen, then placing each primitive by hand. AI assistants are excellent at exactly that reasoning, but they cannot write Altium's binary `.PcbLib`/`.SchLib` files — an undocumented OLE compound format that is easy to corrupt, and Altium silently refuses to open a malformed file.

The Core Idea

The AI handles the intelligence. The tool handles file I/O.

This means the AI can create **any f

Read from source at commit 4d7a3b15a59fOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add altium-designer-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "altium-designer-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Trust audit

CAUTIONgrade C · trust 76/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp/http.rs:426
"https://127.0.0.1:8443",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp/http.rs:436
"http://127.0.0.2",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/Verify-RoundTrip.ps1:69
$SymbolNames = @('PLAIN_ASCII', 'Резистор', '電阻', 'Ωmega', 'Ελλάδα')
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/altium/schlib/mod.rs:2438
for name in ["Резистор", "電阻", "Ωmega", "Ελλάδα", "מעגל"] {
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/ConvertFrom-WireName.ps1:1
<#
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/Verify-Libraries.ps1:1
<#
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/Verify-MaskCacheState.ps1:1
<#
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/Verify-RoundTrip.ps1:1
<#
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/Watch-AltiumDialog.ps1:1
<#
LOWInventory / provenance · inv.binary · CWE-1104
scripts/samples/embed.bmp
embed.bmp
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
scripts/samples/footprints.PcbLib
footprints.PcbLib
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
scripts/samples/manual/cavity.PcbLib
cavity.PcbLib
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
scripts/samples/manual/footprint_link.SchLib
footprint_link.SchLib
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
scripts/samples/manual/i18n4.PcbLib
i18n4.PcbLib
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.local.example
.env.local.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint-cli2.jsonc
.markdownlint-cli2.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.json
.markdownlint.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/altium/mod.rs:1234
include_bytes!("../../scripts/samples/section_keys/AD21_PCB_Lib.SectionKeys.bin");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/server.rs:1070
"instructions": include_str!("../../docs/AGENT_GUIDE.md"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/server.rs:2226
include_str!("../../docs/AGENT_GUIDE.md"),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CLIENT_SETUP.md:378
The endpoint is `http://127.0.0.1:8080/mcp`. For example, in Claude Code:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CLIENT_SETUP.md:381
claude mcp add --transport http altium http://127.0.0.1:8080/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CLIENT_SETUP.md:387
{ "servers": { "altium": { "type": "http", "url": "http://127.0.0.1:8080/mcp" } } }
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/mcp_e2e.rs:1645
let omega = "10kΩ"; // Greek capital omega — not in Windows-1252
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
markdownlint-cli2
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4d7a3b15a59ffull audit observations/trust-audit/mcp-server/embedded-society__altium-designer.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084d7a3b15a59fCAUTIONC76first audit
05

Questions

What is the Altium Designer MCP server?

MCP server for AI-assisted management of Altium Designer component libraries

Is Altium Designer safe to connect to an agent?

With care. The audit graded it C (76/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Altium Designer need?

No credential environment variables were found in its source, so it appears to need none.

How does Altium Designer run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as altium-designer-mcp at 1.2.0.

How current is this page?

The grade is for one exact copy of the source (4d7a3b15a59f), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement