SvgmakerSAFE
Model Context Protocol server for SVGMaker - AI-powered SVG generation and editing. Seamlessly integrate SVG creation into AI workflows.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A powerful MCP server for generating, editing, and converting SVG images using SVGMaker API.
[](https://svgmaker.io) [](https://www.npmjs.com/package/@genwave/svgmaker-mcp) [](https://github.com/GenWaveLLC/svgmaker-mcp/blob/main/LICENSE) [](https://github.com/GenWaveLLC/svgmaker-mcp/actions) [](https://www.npmjs.com/package/@genwave/svgmaker-mcp)
🎨 MCP Server in Action
This very illustration came to life through our own SVGMaker MCP server—a living example of AI assistants and vector graphics working in perfect harmony via the Model Context Protocol.
🌟 Highlights
- 🎨 AI-Powered SVG Generation: Create SVGs from text descriptions
- ✏️ Smart SVG Editing: Edit existing SVGs with natural language
- 🖼️ Raster Mode: Skip vectorization and get a quick PNG instead of SVG
- 🔄 Image-to-SVG Conversion: Convert any image to scalable SVG
- 🪄 Background Removal: Isolate the foreground subject and get a clean SVG with transparency
- 👁️ Inline Image Preview: Preview generations and gallery items directly in chat
- 🔒 Secure File Operations: Built-in path validation and security
- ⚡ Real-Time Progress: Live updates during operations
- 📝 Type Safety: Full TypeScript support with type definitions
📋 Table of Contents
- Requirements
- Installation
- Quick Start
- LLM Integrations
- Available Tools
- Configuration
- Development
- [Contributing](#-
68169ba4288eOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add svgmaker-mcp --env SVGMAKER_API_KEY=${SVGMAKER_API_KEY} --env SVGMAKER_AUTH_SERVER_URL=${SVGMAKER_AUTH_SERVER_URL} -- npx -y @genwave/[email protected]{
"mcpServers": {
"svgmaker-mcp": {
"command": "npx",
"args": [
"-y",
"@genwave/[email protected]"
],
"env": {
"SVGMAKER_API_KEY": "${SVGMAKER_API_KEY}",
"SVGMAKER_AUTH_SERVER_URL": "${SVGMAKER_AUTH_SERVER_URL}"
}
}
}
}Exposed tools (9)
7 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
svgmaker_account_usage | read | Get SVGMaker API usage statistics for the account: request counts, credits used, success and error counts, and breakdowns by category and by day. Use this to answer |
svgmaker_gallery_get | read | Get the details of a public gallery item by id: the prompt used, type, quality, hashtags and categories. Returns metadata as text, not the image — use svgmaker_gallery_preview to see the image itself. |
svgmaker_gallery_list | read | Browse the public SVGMaker gallery and list item ids, with optional filters and pagination. Use this to find reference or inspiration images made by other users. For images the caller made themselves, use svgmaker_generations_list instead. Returns ids and page counts only, not images. |
svgmaker_gallery_preview | read | Show a public gallery item in the conversation as a PNG image. Use this to check what a gallery item looks like, on any transport, and it costs no credits. Use svgmaker_gallery_download instead when the user wants the file or a URL, and svgmaker_generations_preview for generations the caller made. |
svgmaker_generations_delete | destructive | Delete one of your generations and its files. The deletion is permanent and cannot be undone, so confirm the exact id with the user before you call this. Requires a paid account. Returns a confirmation message. |
svgmaker_generations_get | read | Get the details of one of your generations by id: the prompt used, type, quality, public/private state, hashtags and categories. Returns metadata as text, not the image — use svgmaker_generations_preview to see the image itself. |
svgmaker_generations_preview | read | Show one of your generations in the conversation as a PNG image. Use this to check what a generation looks like, on any transport. Use svgmaker_generations_download instead when the user wants the file or a URL, and svgmaker_gallery_preview for a public gallery item. |
svgmaker_generations_share | read | Make one of your generations publicly visible and return its permanent share URL. Use this when the user wants a link other people can open. This exposes the image publicly, so ask first if the intent is unclear. |
svgmaker_upload | write | Create a short-lived upload URL so a local image can be used with svgmaker_edit, svgmaker_convert or svgmaker_remove_background over HTTPS. This tool only mints the URL — you must upload the bytes yourself, in three steps. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
svgmaker_generations_delete
.eslintignore
.eslintrc.cjs
.prettierignore
@modelcontextprotocol/sdk, dotenv, jose, sharp, zod-to-json-schema, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Gates applied: no_behavioural_pass.
68169ba4288efull audit observations/trust-audit/mcp-server/genwavellc__svgmaker.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 68169ba4288e | SAFE | B | 89 | first audit |
Questions
What is the Svgmaker MCP server?
Model Context Protocol server for SVGMaker - AI-powered SVG generation and editing. Seamlessly integrate SVG creation into AI workflows.
What tools does Svgmaker expose?
9 in total: 7 read-only, 1 that write, and 1 that can delete or overwrite (svgmaker_generations_delete). Every one is listed on this page with its risk.
Is Svgmaker safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Svgmaker need?
It reads SVGMAKER_API_KEY and SVGMAKER_AUTH_SERVER_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Svgmaker run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @genwave/svgmaker-mcp at 2.1.0.
How current is this page?
The grade is for one exact copy of the source (68169ba4288e), read on 2026-10-07. The repository is watched and re-audited when it changes.