Shadcn UIBLOCK
A mcp server to allow LLMS gain context about shadcn ui component structure,usage and installation,compaitable with react,svelte 5,vue & React Native
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://badge.fury.io/js/@jpisnice%2Fshadcn-ui-mcp-server) [](https://opensource.org/licenses/MIT)
[](https://archestra.ai/mcp-catalog/jpisnice__shadcn-ui-mcp-server)
🚀 The fastest way to integrate shadcn/ui components into your AI workflow
A Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to shadcn/ui v4 components, blocks, demos, and metadata. Seamlessly retrieve React, Svelte, Vue, and React Native implementations for your AI-powered development workflow.
✨ Key Features
- 🎯 Multi-Framework Support - React, Svelte, Vue, and React Native implementations
- 📦 Component Source Code - Latest shadcn/ui v4 TypeScript source
- 🎨 Component Demos - Example implementations and usage patterns
- 🏗️ Blocks Support - Complete block implementations (dashboards, calendars, forms)
- 📋 Metadata Access - Dependencies, descriptions, and configuration details
- 🔍 Directory Browsing - Explore repository structures
- ⚡ Smart Caching - Efficient GitHub API integration with rate limit handling
- 🌐 SSE Transport - Server-Sent Events support for multi-client deployments
- 🐳 Docker Ready - Production-ready containerization with Docker Compose
🚀 Quick Start
# Basic usage (60 requests/hour) npx @jpisnice/shadcn-ui-mcp-server # With GitHub token (5000 requests/hour) - Recommended npx @jpisnice/shadcn-ui-mcp-server --github-api-key ghp_your_token_here # Switch frameworks npx @jpisnice/shadcn-ui-mcp-server --framework svelte npx @jpisnice/shadcn-ui-mcp-server --framework vue npx @jpisnice/shadcn-ui-mcp-server --framework react-native # Use Base UI instead of Radix (React only) npx @jpisnice/shadcn-
1edd6fb55113OBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add shadcn-ui-mcp-server --env GITHUB_PERSONAL_ACCESS_TOKEN=${GITHUB_PERSONAL_ACCESS_TOKEN} -- npx -y @jpisnice/[email protected]{
"mcpServers": {
"shadcn-ui-mcp-server": {
"command": "npx",
"args": [
"-y",
"@jpisnice/[email protected]"
],
"env": {
"GITHUB_PERSONAL_ACCESS_TOKEN": "${GITHUB_PERSONAL_ACCESS_TOKEN}"
}
}
}
}Exposed tools (33)
27 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
actions | destructive | Row actions (edit, delete, view, custom) |
apply_theme | write | Apply a TweakCN theme preset to the project |
authType | read | Authentication type (login, register, forgot-password, two-factor) |
build-shadcn-page | read | Generate a complete shadcn/ui page using v4 components and blocks |
component | read | Component name to optimize |
create-auth-flow | write | Generate authentication pages using shadcn/ui v4 login blocks |
create-dashboard | write | Create a comprehensive dashboard using shadcn/ui v4 blocks and components |
create-data-table | write | Create advanced data tables with shadcn/ui components |
dashboardType | read | Type of dashboard (analytics, admin, user, project, sales) |
dataType | read | Type of data to display (users, products, orders, analytics) |
features | read | Specific features or components needed (comma-separated) |
get_block | read | Get source code for a specific shadcn/ui v4 block (e.g., calendar-01, dashboard-01) |
get_component | read | Get the source code for a specific shadcn/ui v4 component |
get_component_demo | read | Get demo code illustrating how a shadcn/ui v4 component should be used |
get_component_metadata | read | Get metadata for a specific shadcn/ui v4 component |
get_components | read | List of available shadcn/ui components that can be used in the project |
get_directory_structure | read | Get the directory structure of the shadcn-ui v4 repository |
get_install_script_for_component | write | Generate installation script for a specific shadcn/ui component based on package manager |
get_installation_guide | read | Get the installation guide for shadcn/ui based on build tool and package manager |
get_theme | read | Get details of a specific tweakcn theme |
get_theme_metadata | read | Returns metadata about the currently configured theme |
layout | read | Layout preference (sidebar, header, full-width, centered) |
list_blocks | read | Get all available shadcn/ui v4 blocks with categorization |
list_components | read | Get all available shadcn/ui v4 components |
list_themes | read | List available tweakcn themes |
navigation | read | Navigation style (sidebar, top-nav, breadcrumbs) |
optimization | read | Type of optimization (performance, accessibility, responsive, animations) |
optimize-shadcn-component | read | Optimize or enhance existing shadcn/ui components with best practices |
pageType | read | Type of page to build (dashboard, login, calendar, sidebar, products, custom) |
providers | read | Auth providers (email, google, github, apple) |
style | read | Design style (minimal, modern, enterprise, creative) |
useCase | read | Specific use case or context for the component |
widgets | read | Dashboard widgets needed (charts, tables, cards, metrics) |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
const obj = new Function(`return (${sanitized})`)();const obj = new Function(`return (${sanitized})`)();shadcn-ui-mcp-server.mcpb
actions
.mcpbignore
import { getAxiosImplementation, getFramework } from "../../utils/framework.js";import { logError } from "../../utils/logger.js";import { getAxiosImplementation, getFramework } from "../../utils/framework.js";import { logError } from "../../utils/logger.js";import { getAxiosImplementation } from '../../utils/framework.js';@modelcontextprotocol/sdk, axios, cheerio, cors, express, joi, uuid, winston
# Add to your shell profile (~/.bashrc, ~/.zshrc, etc.)
Gates applied: no_behavioural_pass.
1edd6fb55113full audit observations/trust-audit/mcp-server/jpisnice__shadcn-ui-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | 1edd6fb55113 | BLOCK | D | 69 | source changed, verdict held |
Questions
What is the Shadcn UI MCP server?
A mcp server to allow LLMS gain context about shadcn ui component structure,usage and installation,compaitable with react,svelte 5,vue & React Native
What tools does Shadcn UI expose?
33 in total: 27 read-only, 5 that write, and 1 that can delete or overwrite (actions). Every one is listed on this page with its risk.
Is Shadcn UI safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Shadcn UI need?
It reads GITHUB_PERSONAL_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Shadcn UI run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @jpisnice/shadcn-ui-mcp-server at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (1edd6fb55113), read on 2026-09-22. The repository is watched and re-audited when it changes.