Atlas / MCP servers / memi-design / Memi

MemiBLOCK

mcp/memi-design/memi-1

The design layer for agentic AI — design context, interface checks, and verification for coding agents.

Verdict
BLOCK
Grade
F
Trust score
45 /100
Exposed tools
73 62r · 10w · 1d
Transport
stdio
License
MIT
Stars
47
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The design layer for agentic AI.

Give your coding agent an interface brief before it edits. Memi maps the UI already in your repository, surfaces file-anchored accessibility and design-system risks, and gives you a deterministic check to rerun before merge. Start with the CLI, then add the same gate to every pull request.

Memi Studio is available today; Memi Canvas is currently in development. No account, API key, Figma file, global install, or daemon is required for the first audit.

Start with your next interface · Get Memi Studio · Read the research

Quickstart: find your first interface issue

Run one non-destructive audit in any frontend repository. It needs no account, API key, Figma file, global install, or daemon.

npx -y @memi-design/cli@latest diagn
Read from source at commit 8d605e42202fOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add cli -- npx -y @memi-design/[email protected] mcp start --no-figma
03

Exposed tools (73)

62 read · 10 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AccessibilityreadThe interface works across keyboard, screen reader, contrast, motion, and touch needs.
ClarityreadUsers can tell what matters, what each control does, and what to do next.
ConsistencyreadThe product repeats tokens, components, copy patterns, and interaction rules.
ControlreadUsers can review, undo, cancel, and steer consequential actions.
EvidencereadVisible proof
FeedbackreadThe system acknowledges user actions, progress, loading, success, and failure.
NavigationreadNavigation evidence
SecondaryreadAnother
Top_NamereadExplicit
TrustreadRisk clarity
analyze_designread
audit-frontend-designreadEvidence-backed frontend design review for accessibility, hierarchy, tokens, states, and responsive behavior.
audit_interface_craftread
audit_ux_tenets_trapsread
better-uireadBuild and polish a general interface screen.
cancel_probereadCancellation probe
capture_screenshotreadCapture a screenshot of a Figma node (or the current page) as image data. Prereq: bridge + plugin connected (check_bridge_health); node IDs from get_selection or get_page_tree. Returns: { type:
check_bridge_healthreadCheck health of the Figma WebSocket bridge. Works with no plugin connected; never throws. Returns: { status:
check_skill_complianceread
composeread
create_specdestructiveCreate or overwrite a spec in the registry (Zod-validated). Same-name specs are silently overwritten — check get_specs first. Returns: \
design_docread
design_systems_contextread
diagnose_app_qualityreadDiagnose local project source without network access, command execution, or report persistence.
enforce-design-cireadDeterministic pull-request checks for accessibility, design tokens, component structure, responsive behavior, and UI states.
generate_coderead
generate_health_reportread
get_ai_usageread
get_page_treereadGet the hierarchical node tree of the current Figma file. Prereq: bridge + plugin connected. Returns: array of pages { id, name, type:
get_registry_itemreadReturn one shadcn registry-item.json-compatible item from the workspace. Returns: files, targets, dependencies, cssVars, and Atomic Design metadata. Errors: isError if the item is unknown (discover names via get_shadcn_registry).
get_researchreadLoad and return the project
get_selectionread
get_shadcn_registryreadBuild a shadcn registry.json-compatible index from the workspace (component specs; tokens map to a registry:theme item when present). Returns: { $schema, name, homepage, items[] } with file targets, registryDependencies, cssVars. For a single item use get_registry_item.
get_specreadFetch the full body of one spec by name. Returns: full spec JSON — ComponentSpec: atomicLevel, props, variants, composesSpecs, codeConnect, WCAG fields; PageSpec: sections, meta; DataVizSpec: chartType, dataShape. Errors: isError if the name is not found (list names via get_specs).
get_specsreadList all saved specs (cheap summary operation). Returns: [{ name, type:
get_tokensreadGet design tokens from the local registry, optionally filtered. Prereq: none — local read; run pull_design_system if empty. Returns: [{ name, type:
legacy-skillreadPlain description
local_extensionreadAudited local extension
measure_textread
mermaid_jam_exportwriteWrite Mermaid Jam-ready FigJam source artifacts from research or a simulation run. This is source + open friendly: it writes .mmd/.md files under .memoire/mermaid-jam and returns next steps. It does not attempt clipboard or direct paste automation.
namedreadNamed
nested-skillreadHeading
network_extensionreadTest
plan_ui_fixesread
prepare_apple_design_briefreadPrepare a local Apple design brief without running Xcode or writing files.
prepare_design_agent_briefreadPrepare a bounded local design brief without executing commands, integrations, or models.
prepare_frontend_briefreadInspect existing components, props, tokens and stories before editing frontend code. Optionally resolve supplied Figma/Paper evidence; no network, model, config execution or writes. Unknown behavior remains unassessed.
pull_design_systemreadPull the full design system from Figma (tokens, components, styles) into the local registry. Prereq: Figma bridge running + plugin connected — verify with check_bridge_health; start via \
pull_design_system_restreadPull the design system from Figma via REST API — no plugin or bridge required. Prereq: FIGMA_TOKEN and FIGMA_FILE_KEY env vars. Returns: { tokens, components, styles, lastSync }. Errors: missing env vars, or Figma API errors (403 = bad token, 404 = bad file key). Use in CI/headless; equivalent to \
remember-design-systemreadA repository-specific preflight brief for tokens, components, routes, conventions, and verification commands before interface work.
research_design_packageread
research_generate_specsread
run_auditwriteRun a deterministic design-system audit (WCAG contrast, token completeness, spec accessibility) and return structured findings. Prereq: none — token/spec level, no Figma, no AI. Returns: { success, results: issues[], score, level, summary }. focus=
scaffold_agent_design_filesread
scaffold_swiftui_filesread
simulation_comparereadCompare completed simulation runs by adoption, confidence, evidence coverage, risk, and cost.
simulation_costswriteSummarize token and cost usage for a simulation run.
simulation_export_specreadConvert a simulation report into a product-spec impact artifact that agents can paste into specs or handoff docs.
simulation_generate_agentsreadGenerate a 20-60 agent model-swarm cohort from Memoire research evidence without starting a run.
simulation_interviewreadInterview a simulated product stakeholder from a completed local or model-swarm run.
simulation_list_runsreadList persisted simulation runs with lightweight summaries. Use this to discover runIds for simulation_status, simulation_stream, simulation_transcript, simulation_costs, simulation_report, and simulation_compare.
simulation_modelsreadList Codex-first model profiles available to Memoire model-swarm simulations. Live model execution is opt-in; unavailable providers automatically fall back to deterministic clean-room simulation.
simulation_planread
simulation_reportreadExport a simulation report with recommendations, risks, assumptions, events, interviews, and evidenceFindingIds.
simulation_runwriteRun a prepared local or model-swarm product simulation scenario. Prerequisites: Call simulation_plan first and pass the returned scenario.id. Returns on success: SimulationRun with status, events, eventCount, and persisted run id.
simulation_run_matrixwritePlan and run multiple model-swarm hypotheses, then compare outcomes for product-spec decision work.
simulation_statuswriteRead a local simulation run status from .memoire/simulations/runs.
simulation_streamwriteRead persisted simulation events in stream order. Paginated — use offset/limit to page through long runs instead of materializing the full event log.
simulation_transcriptwriteRead model-swarm transcript memory for a run.
swiftui-design-engineeringreadBuild and verify accessible SwiftUI screens and navigation.
sync_design_tokenswrite
top-namereadExplicit
update_tokenwrite
04

Trust audit

BLOCKgrade F · trust 45/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
scripts/lib/offline-bundle.mjs:70
/^(?:id_dsa|id_ecdsa|id_ed25519|id_rsa)$/i,
Why it matters. touches a credential store
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/commands/compose.ts:164
console.log(ui.dots("AI", payload.ai.apiKey ? ui.green("enabled") : ui.dim("heuristic")));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/commands/connect.ts:346
console.log(ui.ok(`Token valid — connected as @${user.handle} (${user.email})`));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/commands/connect.ts:403
console.log(ui.ok("Figma token found " + ui.dim(token.value.startsWith("figd_") ? "(figd_...)" : "(configured)")));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/commands/diff.ts:84
console.log(ui.ok(`${diff.tokens.added.length} new token${diff.tokens.added.length > 1 ? "s" : ""}`));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/commands/diff.ts:92
console.log(ui.warn(`${diff.tokens.removed.length} removed token${diff.tokens.removed.length > 1 ? "s" : ""}`));
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
SECURITY_FIXES.md:919
const token = "figd_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/trust-core-e2e.mjs:47
const secret = "dualentry-trust-core-secret-canary";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/preview/__tests__/api-server.test.ts:307
const token = "preview-session-token";
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
create_spec
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
benchmarks/designworkbench-v2/evidence/browser-playwright/performance-trace.zip
performance-trace.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/site-bundle/notes/accessibility-audit/accessibility-audit-2.0.0.tgz
accessibility-audit-2.0.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/site-bundle/notes/agent-memory-profiles/agent-memory-profiles-0.1.0.tgz
agent-memory-profiles-0.1.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/site-bundle/notes/agent-messaging-gateway/agent-messaging-gateway-0.1.0.tgz
agent-messaging-gateway-0.1.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/site-bundle/notes/agent-session-checkpoints/agent-session-checkpoints-0.1.0.tgz
agent-session-checkpoints-0.1.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
docs/research/memi-2.7-prospective-study/v15-2.7.3-confirmatory/analysis/notebook_executor.py:41
exec(compile(code, f"{path}::cell-{cell_index}", "exec"), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
docs/research/memi-2.7-prospective-study/v16-2.7.5-native-pilot/build-v16-task-manifests.mjs:41
await exec(maestro, ["--udid", udid, "test", flow, "--format", "junit", "--output", trace], {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
docs/research/memi-2.7-prospective-study/v16-2.7.5-native-pilot/build-v16-task-manifests.mjs:57
const hierarchy = await exec(maestro, ["--udid", udid, "hierarchy"], {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/commands/__tests__/supply-chain-security.test.ts:41
expect(pluginMain).not.toContain("eval(");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/plugin/__tests__/ast-guard.test.ts:28
{ name: "new Function()", code: "new Function('return 1');" },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/lib/release-manifest.mjs:767
const actualSha1 = createHash("sha1").update(buffer).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/registry/npm-fetch.ts:154
const actual = createHash("sha1").update(bytes).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/release/__tests__/published-tarball-readme.test.ts:16
function args(bytes: Buffer) { return {bytes, integrity: `sha512-${createHash("sha512").update(bytes).digest("base64")}`, shasum: createHash("sha1").update(bytes).digest("hex"), expectedPhrase: phrase
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/release/__tests__/release-state-machine.test.ts:259
const sha1 = createHash("sha1").update(bytes).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/research/design-package.ts:543
return createHash("sha1").update(values.join("\n")).digest("hex").slice(0, 10);

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 8d605e42202ffull audit observations/trust-audit/mcp-server/memi-design__memi-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088d605e42202fBLOCKF45first audit
06

Questions

What is the Memi MCP server?

The design layer for agentic AI — design context, interface checks, and verification for coding agents.

What tools does Memi expose?

73 in total: 62 read-only, 10 that write, and 1 that can delete or overwrite (create_spec). Every one is listed on this page with its risk.

Is Memi safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (45/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Memi need?

It reads ANTHROPIC_API_KEY, CLAUDE_CODE_OAUTH_TOKEN, FIGMA_FILE_KEY, FIGMA_TOKEN, GEMINI_API_KEY, GITHUB_TOKEN, GOOGLE_API_KEY, MEMOIRE_PUBLISH_READY_SKIP_AUTH, OPENAI_API_KEY and PENPOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Memi run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @sarveshsea/memi-studio-types at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (8d605e42202f), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement