Atlas / MCP servers / f2c-ai / F2C

F2CCAUTION

mcp/f2c-ai/f2c

F2C MCP Server

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
5 5r · 0w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
411
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@f2c-ai/f2c-mcp) [![npm version][npm-version-src]][npm-version-href] [![npm downloads][npm-downloads-src]][npm-downloads-href] [![github][github-src]][github-href] [![node][node-src]][node-href]

[npm-version-src]: https://img.shields.io/npm/v/@f2c/mcp?style=flat&colorA=18181B&colorB=F0DB4F [npm-version-href]: https://npmjs.com/package/@f2c/mcp [npm-downloads-src]: https://img.shields.io/npm/dm/@f2c/mcp?style=flat&colorA=18181B&colorB=F0DB4F [npm-downloads-href]: https://npmjs.com/package/@f2c/mcp [github-src]: https://img.shields.io/badge/github-@f2c/mcp-blue?style=flat&colorA=18181B&colorB=F0DB4F [github-href]: https://github.com/f2c-ai/f2c-mcp [node-src]: https://img.shields.io/node/v/@f2c/mcp?style=flat&colorA=18181B&colorB=F0DB4F [node-href]: https://nodejs.org/en/about/previous-releases

Due to Figma REST API rate limits, if you are affected, please switch to @f2c/mcp-plugin for normal operation.

English | 简体中文

A Model Context Protocol server for Figma Design to Code using F2C.

Features

  • 🎨 Pixel-Perfect HTML/CSS:F2C converts Figma designs to pixel-perfect HTML/CSS with precision.
  • ⚛️ Multi-Framework Support:F2C generates React, CSS Modules, and Tailwind CSS code for fast development.
  • 🧠 Figma Design Context:F2C integrates design context, ensuring compatibility with AI tools like Cursor.
  • 🔗 Figma File URL Parsing:F2C converts design nodes via Figma URLs,
Read from source at commit 50c2968197c7OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp --env FIGMA_API_KEY=${FIGMA_API_KEY} -- npx -y @f2c/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@f2c/[email protected]"
      ],
      "env": {
        "FIGMA_API_KEY": "${FIGMA_API_KEY}"
      }
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
figma_get_file_datareadGet detailed information about a Figma file
figma_get_imagesreadGet images of Figma nodes
figma_to_codereadTransform Figma designs into production-ready code. This tool converts selected Figma nodes into HTML,enabling seamless design-to-code workflow.
get_coderead
get_imageread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/server/figma/config.ts:15
logger.debug('personalToken', token)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/transports/streamable-http/http-server.ts:75
logger.info(`Setting up progress notifications for token ${progressToken} on session ${sessionId}`)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/Info.md:52
"url": "http://172.29.97.170:3000/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/Info.md:66
"url": "http://172.29.97.170:3000/sse",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
cors, express, node-fetch, zod, @f2c/data-reporter, @biomejs/biome, @empjs/biome-config, @types/bun
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 50c2968197c7full audit observations/trust-audit/mcp-server/f2c-ai__f2c.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0150c2968197c7CAUTIONB89first audit
06

Questions

What is the F2C MCP server?

F2C MCP Server

What tools does F2C expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is F2C safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does F2C need?

It reads FIGMA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does F2C run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @f2c/mcp at 0.4.9.

How current is this page?

The grade is for one exact copy of the source (50c2968197c7), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement