DesignlangBLOCK
Extract any website's complete design system with one command. DTCG tokens, semantic+primitive+composite, MCP server for Claude Code/Cursor/Windsurf, multi-platform emitters (iOS SwiftUI, Android Compose, Flutter, WordPress), Tailwind v4, Figma variables, shadcn/ui, CSS health audit, WCAG remediatio
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Built by Manav Arya Singh (@Manavarya09)
f27906d699a8OBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add website --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ATLASCLOUD_API_KEY=${ATLASCLOUD_API_KEY} --env ATLAS_CLOUD_API_KEY=${ATLAS_CLOUD_API_KEY} --env BLOB_READ_WRITE_TOKEN=${BLOB_READ_WRITE_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"website": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"ATLASCLOUD_API_KEY": "${ATLASCLOUD_API_KEY}",
"ATLAS_CLOUD_API_KEY": "${ATLAS_CLOUD_API_KEY}",
"BLOB_READ_WRITE_TOKEN": "${BLOB_READ_WRITE_TOKEN}"
}
}
}
}Exposed tools (16)
15 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cancel_job | read | Cancel a running extraction job; its result is discarded. |
compute_drift | write | Compare two finished jobs (e.g. production vs a preview deploy): colours, typography, spacing, accessibility and components that changed. |
export | read | Render a finished job in a target format. |
extract_design | read | Extract the design system of a live URL in a real browser. Returns a job_id immediately; poll get_job_status, then pass the job_id to get_tokens, get_colors, get_typography, get_components, get_findings, compute_drift or export. |
find_nearest_color | read | Find the nearest palette color that passes the requested WCAG contrast rule against the given hex. |
get_colors | read | Colour system for a finished job: primary/secondary/accent, backgrounds, text, full palette with usage. |
get_component | read | Return the component cluster with matching kind, optionally narrowed to a variant index. |
get_components | read | Component styles for a finished job: buttons, inputs, cards, links and their variants. |
get_findings | read | Design-system quality findings for a finished job: token lint (colour sprawl, scale consistency) and WCAG contrast summary. |
get_job_status | read | Status of an extraction job (running, done, failed, cancelled). A done job includes a short summary: primary colour, font families, counts. |
get_region | read | Return the region with the given role (e.g. hero, nav, footer). |
get_tokens | read | W3C DTCG design tokens (primitive + semantic tiers) for a finished job. |
get_typography | read | Typography for a finished job: families, type scale, weights, line heights. |
list_failing_contrast_pairs | read | Return the accessibility remediation array (failing fg/bg pairs with suggestions). |
list_jobs | read | All extraction jobs in this session. |
search_tokens | read | Case-insensitive substring match over all token dot-paths. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
.option('--insecure', 'ignore HTTPS/SSL certificate errors (self-signed, dev, proxies)')designlang-vscode-0.1.0.vsix
console.log(`**${total} token changes** vs baseline (${changed.length} changed, ${added.length} added, ${removed.length} removed).`);`A colour counts when it is within ΔE ${COLOR_TOLERANCE} (CIE76) of the site's brand colour; a font counts when it names the body-text family.`,.vscodeignore
new Function('module', out)(mod);new Function('module', out)(mod);new Function('module', out)(mod);const url = new URL('../../package.json', import.meta.url);const { version } = JSON.parse(readFileSync(new URL('../../package.json', import.meta.url), 'utf-8'));import { extractDesignLanguage } from '../../../../../src/index.js';import { formatScoreBadge } from '../../../../../src/formatters/badge.js';import { validateTargetUrl } from '../../../../lib/url-safety.js';test('rejects IPv4-mapped IPv6 cloud metadata ::ffff:169.254.169.254', () => {const r = validateTargetUrl('http://[::ffff:169.254.169.254]');const r = validateTargetUrl('http://[64:ff9b::169.254.169.254]');const r = validateTargetUrl('http://127.0.0.1');const r = validateTargetUrl('http://10.1.2.3');const r = validateTargetUrl('http://192.168.0.1');const r = validateTargetUrl('http://172.20.0.5');const r = validateTargetUrl('http://172.15.0.1');background-image: linear-gradient(rgba(0, 0, 0, 0.6) 0%, rgb(18, 18, 18) 100%), url("data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4KPHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vc--background-noise: url(data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4KPHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIzMDAiIGhlaWdodD0iMzAwIj4KICAgPGZpbH
<div class="swatch"><div class="swatch-color" style="background-image:linear-gradient(rgba(0, 0, 0, 0.6) 0%, rgb(18, 18, 18) 100%), url("data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZ--background-noise: url(data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4KPHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIzMDAiIGhlaWdodD0iMzAwIj4KICAgPGZpbH
Gates applied: no_behavioural_pass.
f27906d699a8full audit observations/trust-audit/mcp-server/manavarya09__designlang.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | f27906d699a8 | BLOCK | D | 69 | source changed, verdict held |
Questions
What is the Designlang MCP server?
Extract any website's complete design system with one command. DTCG tokens, semantic+primitive+composite, MCP server for Claude Code/Cursor/Windsurf, multi-platform emitters (iOS SwiftUI, Android Compose, Flutter, WordPress), Tailwind v4, Figma variables, shadcn/ui, CSS health audit, WCAG remediatio
What tools does Designlang expose?
16 in total: 15 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Designlang safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Designlang need?
It reads ANTHROPIC_API_KEY, ATLASCLOUD_API_KEY, ATLAS_CLOUD_API_KEY, BLOB_READ_WRITE_TOKEN, BROWSERLESS_TOKEN and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Designlang run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as website at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (f27906d699a8), read on 2026-09-22. The repository is watched and re-audited when it changes.