Sketch ContextSAFE
MCP server to provide Sketch layout information to AI coding agents like Cursor
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!NOTE] This repository has been archived as of February 5, 2026. Please refer to the official Sketch MCP at https://www.sketch.com/docs/mcp-server/
Note: This project was currently in dev/testing phase and was not fully stable.
A Model Context Protocol (MCP) server for integrating Sketch designs with IDEs such as Cursor, Cline, or Windsurf.
Overview
This tool allows Cursor IDE to access and interpret Sketch design files, enabling AI-powered design-to-code workflows. It works by:
- Providing a server that parses Sketch files (.sketch)
- Implementing the MCP protocol that Cursor or other IDEs use for context
- Allowing you to reference specific components and layers from your Sketch files
- Providing a UI interface for Sketch that communicates with Cursor
- Enabling real-time bidirectional communication between Sketch and Cursor
Components
This project consists of two main components:
- MCP Server: A Node.js server that implements the Model Context Protocol to provide Sketch file data to Cursor IDE
- Sketch Plugin: A Sketch plugin with UI interface that communicates with the MCP server via WebSockets
Available MCP Tools
The server provides the following tools to Cursor:
get_file: Retrieve contents of a Sketch file or specific node within itlist_components: List all components/symbols in a Sketch fileget_selection: Get information about currently selected elementscreate_rectangle: Create new rectangles with specified dimensions and propertiescreate_text: Create new text elements with custom content and styling
These tools enable Cursor to:
- Access and inspect Sketch design files
- Query specific components and layers
- Create and modify design elements through
78a002ecc29dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sketch-context-mcp --env SKETCH_API_KEY=${SKETCH_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"sketch-context-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"SKETCH_API_KEY": "${SKETCH_API_KEY}"
}
}
}
}Exposed tools (5)
3 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create_rectangle | write | Create a new rectangle in the Sketch document |
create_text | write | Create a new text layer in the Sketch document |
get_file | read | Get the contents of a Sketch file |
get_selection | read | Get information about selected elements in a Sketch document |
list_components | read | List all components in a Sketch file |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAB4AAAAeCAYAAAA7MK6iAAAACXBIWXMAAAsTAAALEwEAmpwYAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAOISURBVHgBrZdLbExRGMf/d++dmU5nKFOdYqpT08aziCdJI7qwaES6IKTEo
adm-zip, body-parser, cors, dotenv, express, node-fetch, tmp, yargs
Use your Sketch Cloud credentials (email and password) to generate an access token by making a POST request to the authentication endpoint:
curl -X "POST" "https://auth.sketch.cloud/oauth/token" \
Gates applied: no_behavioural_pass.
78a002ecc29dfull audit observations/trust-audit/mcp-server/jshmllr__sketch-context.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 78a002ecc29d | SAFE | B | 89 | first audit |
Questions
What is the Sketch Context MCP server?
MCP server to provide Sketch layout information to AI coding agents like Cursor
What tools does Sketch Context expose?
5 in total: 3 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Sketch Context safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Sketch Context need?
It reads SKETCH_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (78a002ecc29d), read on 2026-10-07. The repository is watched and re-audited when it changes.