Atlas / MCP servers / ie3jp / Illustrator

IllustratorBLOCK

mcp/ie3jp/illustrator-4

MCP server for Adobe Illustrator with 63 tools — read, create, and export design data. Everything the official Illustrator MCP (beta) can do and more, on stable Illustrator.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
67 48r · 18w · 1d
Transport
stdio
License
MIT
Stars
148
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🇺🇸 English | 🇯🇵 日本語 | 🇨🇳 简体中文 | 🇰🇷 한국어 | 🇪🇸 Español | 🇩🇪 Deutsch | 🇫🇷 Français | 🇵🇹 Português (BR)

🇯🇵 日本語の README は README.ja.md にあります。

[](https://www.npmjs.com/package/illustrator-mcp-server) [](LICENSE) []() [](https://www.adobe.com/products/illustrator.html) [](https://modelcontextprotocol.io/) [](https://ko-fi.com/cyocun)

An MCP (Model Context Protocol) server for reading, manipulating, and exporting Adobe Illustrator design data — with 66 built-in tools.

Control Illustrator directly from AI assistants like Claude — extract design information for web implementation, verify print-ready data, and export assets.

Everything Adobe's official Illustrator MCP (beta) can do — and more. See the comparison.

[](https://glama.ai/mcp/servers/ie3jp/illustrator-mcp-server)

[!NOTE] In Claude's extension directory and plugin marketplace, this project is listed as Design Bridge by IE3. Anthropic's directories don't allow other companies' brand names in listing names, so the listing name differs — i
Read from source at commit 8f0085e163e8OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add illustrator-mcp-server -- npx -y [email protected]
03

Exposed tools (67)

48 read · 18 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
align_objectsread
apply_graphic_stylewrite
apply_text_stylewrite
check_contrastread
check_text_consistencyread
close_documentread
convert_coordinateread
convert_to_outlinesread
create_crop_markswrite
create_documentwrite
create_ellipsewrite
create_gradientwrite
create_linewrite
create_pathwrite
create_path_textwrite
create_rectanglewrite
create_text_framewrite
delete_objectsdestructive
duplicate_objectsread
exportread
export_pdfread
extract_design_tokensread
find_objectsread
get_artboardsread
get_colorsread
get_document_inforead
get_document_structureread
get_effectsread
get_groupsread
get_guidelinesread
get_imagesread
get_layersread
get_overprint_inforead
get_path_itemsread
get_selectionread
get_separation_inforead
get_symbolsread
get_text_frame_detailread
group_objectsread
import_svg_as_editablewrite
list_fontsread
list_graphic_stylesread
list_text_framesread
list_text_stylesread
manage_artboardsread
manage_datasetsread
manage_layersread
manage_linked_imagesread
manage_swatchesread
modify_objectwrite
move_to_layerwrite
open_documentread
place_color_chipsread
place_imageread
place_style_guideread
place_symbolread
preflight_checkread
replace_colorread
resize_for_variationread
save_documentwrite
select_objectsread
set_illustrator_versionwrite
set_workflowwrite
set_z_orderwrite
tread
undoread
ungroup_objectsread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/jsx/helpers/common.jsx:64
return eval("(" + str + ")"); // eslint-disable-line no-eval
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_objects
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/unit/color-paint-tools.test.ts:82
return new Function('__env', '__params', code)(env, sentParams) as Result; // NOSONAR
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/unit/common-helpers.test.ts:68
const factory = new Function(wrappedCode); // NOSONAR
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/unit/crop-marks.test.ts:236
new Function(...names, body)(...names.map((n) => (globals as Record<string, unknown>)[n])); // NOSONAR
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/unit/data-loss-guards.test.ts:77
const commonLayerHelpers = new Function(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/export/export-pdf.ts:4
import { executeJsxHeavy } from '../../executor/jsx-runner.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/export/export-pdf.ts:8
import { checkAbsoluteOutputPath, normalizeOutputExtension, resolveOutputPath } from '../../utils/output-path.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/export/export.ts:5
import { executeJsxHeavy } from '../../executor/jsx-runner.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/export/export.ts:8
import { checkAbsoluteOutputPath, normalizeOutputExtension, resolveOutputPath } from '../../utils/output-path.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/modify/apply-graphic-style.ts:3
import { executeJsx } from '../../executor/jsx-runner.js';
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/ci.yml:112
sudo mv mcp-publisher /usr/local/bin/
Why it matters. asks for elevated privileges
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, p-limit, @types/node, tsx, typescript, vitest
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 8f0085e163e8full audit observations/trust-audit/mcp-server/ie3jp__illustrator-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-078f0085e163e8BLOCKD69first audit
06

Questions

What is the Illustrator MCP server?

MCP server for Adobe Illustrator with 63 tools — read, create, and export design data. Everything the official Illustrator MCP (beta) can do and more, on stable Illustrator.

What tools does Illustrator expose?

67 in total: 48 read-only, 18 that write, and 1 that can delete or overwrite (delete_objects). Every one is listed on this page with its risk.

Is Illustrator safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Illustrator need?

No credential environment variables were found in its source, so it appears to need none.

How does Illustrator run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as illustrator-mcp-server at 1.10.3.

How current is this page?

The grade is for one exact copy of the source (8f0085e163e8), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement