Atlas / MCP servers / helloggx / Shadcn-Vue

Shadcn-VueBLOCK

mcp/helloggx/shadcn-vue

Shadcn-vue and Tailwind CSS are essential for component development, offering developers a fast and high-quality experience in Vue component development.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
5 5r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
108
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful AI Agent tool that helps developers instantly create high-quality UI components

[](https://GitHub.com/HelloGGX/shadcn-vue-mcp/network/) [](https://GitHub.com/HelloGGX/shadcn-vue-mcp/stargazers/) [](https://GitHub.com/HelloGGX/shadcn-vue-mcp/commit/) [](https://smithery.ai/server/@HelloGGX/shadcn-vue-mcp) [](https://github.com/HelloGGX/shadcn-vue-mcp/blob/main/LICENSE) [](https://github.com/HelloGGX/shadcn-vue-mcp/graphs/contributors)

[](https://mseep.ai/app/helloggx-shadcn-vue-mcp)

Shadcn-vue MCP Server is a powerful AI-driven tool that helps developers instantly create beautiful, modern UI components through natural language descriptions. It integrates the shadcn-vue component library and tailwindcss, seamlessly connects with mainstream IDEs, and provides a streamlined UI development workflow.

🌐 Available Languages:

Read from source at commit 35d5031ac892OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
component-builderreadRetrieve documentation for all filtered components and charts to prepare for component generation, This tool ONLY returns the text snippet for that UI component. After calling this tool, you must edit or add files to integrate the snippet into the codebase.
component-quality-checkreadAutomatically check Vue component quality and provide detailed feedback. Use this tool when you need to validate component quality, accessibility, performance, and best practices compliance. or when mentions /check.
component-usage-docreadread usage doc of a component, Use this tool when mentions /doc.
components-filterreadfilter components with shadcn/ui components and tailwindcss, Use this tool when mentions /filter
requirement-structuringreadanalyze the user
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/server/previewer/_next/static/chunks/polyfills-42372ed130431b0a.js:1
!function(){var t="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:{};function e(t){var e={exports:{}};return
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/server/previewer/_next/static/chunks/webpack-38b142dcef310521.js:1
(()=>{"use strict";var e={},t={};function r(o){var n=t[o];if(void 0!==n)return n.exports;var a=t[o]={exports:{}},i=!0;try{e[o](a,a.exports,r),i=!1}finally{i&&delete t[o]}return a.exports}r.m=e,(()=>{v
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
src/server/previewer/_next/static/chunks/e58a7f8f-9475e998f9e8dc00.js:1
".env" ... fetch(
Why it matters. reads secrets in the same file that sends data out
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/server/callback-server.ts:234
const url = `http://127.0.0.1:${availablePort}?id=${this.sessionId}`;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/server/previewer/_next/static/chunks/870.3764a5ed5edda507.js:1
"use strict";(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[870],{9870:(e,t,r)=>{r.r(t),r.d(t,{SandpackNode:()=>en});var n=r(7192),i=Object.create,s=Object.defineProperty,o=Object.getOwnProp
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, cors, express, fast-glob, fastmcp, marked, open, zod
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 35d5031ac892full audit observations/trust-audit/mcp-server/helloggx__shadcn-vue.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0735d5031ac892BLOCKD69first audit
06

Questions

What is the Shadcn-Vue MCP server?

Shadcn-vue and Tailwind CSS are essential for component development, offering developers a fast and high-quality experience in Vue component development.

What tools does Shadcn-Vue expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Shadcn-Vue safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Shadcn-Vue need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (35d5031ac892), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement