Atlas / MCP servers / jinzcdev / Markmap

MarkmapSAFE

mcp/jinzcdev/markmap

An MCP server for converting Markdown to interactive mind maps with export support (PNG/JPG/SVG).

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 3r · 0w · 1d
Transport
stdio
License
MIT
Stars
289
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@jinzcdev/markmap-mcp-server) [](https://www.npmjs.com/package/@jinzcdev/markmap-mcp-server) [](LICENSE) [](README_zh-CN.md) [](https://github.com/jinzcdev/markmap-mcp-server)

Markmap MCP Server is based on the Model Context Protocol (MCP). It converts Markdown into interactive mind maps using markmap, and can optionally export PNG / JPG / SVG on the server for Agent-friendly delivery. Generation runs locally — no third-party API keys required.

Features

  • Markdown → Mind Map: Convert Markdown (headings + nested lists) to interactive HTML mind maps
  • Agent-friendly returns: Return a file path, inline HTML, and/or image content (configured at startup)
  • Server-side export: Export PNG / JPG / SVG via Playwright for chat/inline preview
  • Browser preview: Configurable open behavior — always, never, or agent-decided (startup setting)
  • Browser export toolbar: When viewing HTML, also export PNG/JPG/SVG or copy Markdown in the page UI
  • Offline HTML: Startup --offline inlines assets so the page works without CDN access
  • File workflows: Read from inputPath, list recent outputs, clean up old files
  • Privacy-first: Fully local conversion; no cloud mind-map API

Prerequisites

  1. Node.js v20 or above
  2. For server-side image export (format: png|jpg|svg): install Playwright and Chromium
npm install playwright
npx playwright install chromium

(playwright is an opti

Read from source at commit 7580f5e87e92OBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add markmap-mcp-server -- npx -y @jinzcdev/[email protected]
claude-desktop
{
  "mcpServers": {
    "markmap-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@jinzcdev/[email protected]"
      ]
    }
  }
}
03

Exposed tools (4)

3 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cleanup_mindmapsdestructivePermanently delete markmap* files from the output directory. DESTRUCTIVE and irreversible when dryRun is false.\n\ndryRun defaults to false — omitting it WILL delete. Always call once with dryRun=true to preview, then again with dryRun=false to commit. Prefer list_mindmaps beforehand.\n\nReturns {
get_mindmapreadRetrieve a generated mind map file by absolute path. Read-only — no side effects. Only paths inside the configured output directory are allowed (path traversal denied).\n\nReturns JSON {
list_mindmapsreadList markmap* files (html/png/jpg/jpeg/svg) in the output directory, newest first. Read-only — no side effects. Missing/empty dirs return {
markdown_to_mindmapread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
cleanup_mindmaps
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/tools/markmap-tools.ts:5
import { createMarkmap } from "../../markmap/createMarkmap.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/tools/markmap-tools.ts:10
} from "../../markmap/exportImage.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/tools/markmap-tools.ts:15
} from "../../markmap/lifecycle.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/tools/tool-registry.ts:2
import { RegistryBase } from "../../common/registry-base.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/services/markmap.test.ts:5
import { createMarkmap } from "../../src/markmap/createMarkmap.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, html-to-image, markmap-cli, minimist, open, pino, zod, @eslint/js
Why it matters. 26 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 7580f5e87e92full audit observations/trust-audit/mcp-server/jinzcdev__markmap.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-057580f5e87e92SAFEB89first audit
06

Questions

What is the Markmap MCP server?

An MCP server for converting Markdown to interactive mind maps with export support (PNG/JPG/SVG).

What tools does Markmap expose?

4 in total: 3 read-only, 0 that write, and 1 that can delete or overwrite (cleanup_mindmaps). Every one is listed on this page with its risk.

Is Markmap safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Markmap need?

No credential environment variables were found in its source, so it appears to need none.

How does Markmap run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @jinzcdev/markmap-mcp-server at 0.2.0.

How current is this page?

The grade is for one exact copy of the source (7580f5e87e92), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement