MarkmapSAFE
An MCP server for converting Markdown to interactive mind maps with export support (PNG/JPG/SVG).
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@jinzcdev/markmap-mcp-server) [](https://www.npmjs.com/package/@jinzcdev/markmap-mcp-server) [](LICENSE) [](README_zh-CN.md) [](https://github.com/jinzcdev/markmap-mcp-server)
Markmap MCP Server is based on the Model Context Protocol (MCP). It converts Markdown into interactive mind maps using markmap, and can optionally export PNG / JPG / SVG on the server for Agent-friendly delivery. Generation runs locally — no third-party API keys required.
Features
- Markdown → Mind Map: Convert Markdown (headings + nested lists) to interactive HTML mind maps
- Agent-friendly returns: Return a file path, inline HTML, and/or image content (configured at startup)
- Server-side export: Export PNG / JPG / SVG via Playwright for chat/inline preview
- Browser preview: Configurable open behavior — always, never, or agent-decided (startup setting)
- Browser export toolbar: When viewing HTML, also export PNG/JPG/SVG or copy Markdown in the page UI
- Offline HTML: Startup
--offlineinlines assets so the page works without CDN access - File workflows: Read from
inputPath, list recent outputs, clean up old files - Privacy-first: Fully local conversion; no cloud mind-map API
Prerequisites
- Node.js v20 or above
- For server-side image export (
format: png|jpg|svg): install Playwright and Chromium
npm install playwright npx playwright install chromium
(playwright is an opti
7580f5e87e92OBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add markmap-mcp-server -- npx -y @jinzcdev/[email protected]
{
"mcpServers": {
"markmap-mcp-server": {
"command": "npx",
"args": [
"-y",
"@jinzcdev/[email protected]"
]
}
}
}Exposed tools (4)
3 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
cleanup_mindmaps | destructive | Permanently delete markmap* files from the output directory. DESTRUCTIVE and irreversible when dryRun is false.\n\ndryRun defaults to false — omitting it WILL delete. Always call once with dryRun=true to preview, then again with dryRun=false to commit. Prefer list_mindmaps beforehand.\n\nReturns { |
get_mindmap | read | Retrieve a generated mind map file by absolute path. Read-only — no side effects. Only paths inside the configured output directory are allowed (path traversal denied).\n\nReturns JSON { |
list_mindmaps | read | List markmap* files (html/png/jpg/jpeg/svg) in the output directory, newest first. Read-only — no side effects. Missing/empty dirs return { |
markdown_to_mindmap | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
cleanup_mindmaps
import { createMarkmap } from "../../markmap/createMarkmap.js";} from "../../markmap/exportImage.js";
} from "../../markmap/lifecycle.js";
import { RegistryBase } from "../../common/registry-base.js";import { createMarkmap } from "../../src/markmap/createMarkmap.js";@modelcontextprotocol/sdk, html-to-image, markmap-cli, minimist, open, pino, zod, @eslint/js
Gates applied: no_behavioural_pass.
7580f5e87e92full audit observations/trust-audit/mcp-server/jinzcdev__markmap.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 7580f5e87e92 | SAFE | B | 89 | first audit |
Questions
What is the Markmap MCP server?
An MCP server for converting Markdown to interactive mind maps with export support (PNG/JPG/SVG).
What tools does Markmap expose?
4 in total: 3 read-only, 0 that write, and 1 that can delete or overwrite (cleanup_mindmaps). Every one is listed on this page with its risk.
Is Markmap safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Markmap need?
No credential environment variables were found in its source, so it appears to need none.
How does Markmap run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @jinzcdev/markmap-mcp-server at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (7580f5e87e92), read on 2026-10-05. The repository is watched and re-audited when it changes.