Magic UISAFE
Magic UI components, searchable and installable from your AI editor.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@magicuidesign/mcp)
Official ModelContextProtocol (MCP) server for Magic UI.
Install MCP configuration
npx @magicuidesign/cli@latest install
Supported Clients
- [x] cursor
- [x] windsurf
- [x] claude
- [x] cline
- [x] roo-cline
Manual Installation
Add to your IDE's MCP config:
{
"mcpServers": {
"magicuidesign-mcp": {
"command": "npx",
"args": ["-y", "@magicuidesign/mcp@latest"]
}
}
}Example Usage
Once configured, you can questions like:
"Make a marquee of logos"
"Add a blur fade text animation"
"Add a grid background"
Available Tools
The server provides the following tools callable via MCP:
d475ca8b39ceOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp -- npx -y @magicuidesign/[email protected]
{
"mcpServers": {
"mcp": {
"command": "npx",
"args": [
"-y",
"@magicuidesign/[email protected]"
]
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
getRegistryItem | read | Gets detailed information for a single Magic UI registry item. |
listRegistryItems | read | Lists Magic UI registry items with optional filtering by kind, query, and limit. |
searchRegistryItems | read | Searches Magic UI registry items by keyword or use case. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
.release-it.json
@modelcontextprotocol/sdk, zod, @release-it/conventional-changelog, @types/node, nodemon, release-it, shx, typescript
Gates applied: no_behavioural_pass.
d475ca8b39cefull audit observations/trust-audit/mcp-server/magicuidesign__magic-ui-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | d475ca8b39ce | SAFE | B | 89 | first audit |
Questions
What is the Magic UI MCP server?
Magic UI components, searchable and installable from your AI editor.
What tools does Magic UI expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Magic UI safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Magic UI need?
No credential environment variables were found in its source, so it appears to need none.
How does Magic UI run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @magicuidesign/mcp at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (d475ca8b39ce), read on 2026-10-06. The repository is watched and re-audited when it changes.