Atlas / MCP servers / meshy-dev / Meshy

MeshySAFE

mcp/meshy-dev/meshy

MCP server for Meshy AI 3D generation platform

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
24 23r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
51
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Model Context Protocol (MCP) server for the Meshy AI 3D generation platform. Enables AI agents to create, manage, and download 3D models, textures, images, rigged characters, and animations through natural conversation.

Features

24 tools covering the full Meshy API:

Key Capabilities

  • Text to 3D: Generate 3D models from text descriptions (preview + refine pipeline)
  • Image to 3D: Convert single or multiple images into 3D models
  • Meshy 7.1 (v0.6.0): ai_model: "meshy-7.1" (and latest) on text-to-3d, image-to-3d and multi-image-to-3d. geometry_resolution: "standard" | "2k" | "4k" picks the geometry pass (+5 credits for 2k/4k; multi-image supports standard/2k). ultra_mode is deprecated
  • Meshy 6 Lite (v0.6.0): ai_model: "meshy-6-lite" — fast, 5-credit mesh (15 textured, 2K textures only) on every generation endpoint
  • Smart Topology: model_type: "smart-topology" with ai_model: "meshy-t2" on text-to-3d (new in v0.6.0) and image-to-3d. Clean, part-separated triangle mesh generated directly at 100–15,000 faces (default 4,000) for 5 credits of mesh
  • **Multi-view texture on multi-image
Read from source at commit b8a8f0fca7edOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add meshy-mcp-server --env MESHY_API_KEY=${MESHY_API_KEY} -- npx -y @meshy-ai/[email protected]
claude-desktop
{
  "mcpServers": {
    "meshy-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@meshy-ai/[email protected]"
      ],
      "env": {
        "MESHY_API_KEY": "${MESHY_API_KEY}"
      }
    }
  }
}
03

Exposed tools (24)

23 read · 1 write · 0 destructive.

ToolRiskDescription
meshy_analyze_printabilityread
meshy_animateread
meshy_cancel_taskread
meshy_check_balanceread
meshy_convertread
meshy_creative_labread
meshy_download_modelread
meshy_get_task_statusread
meshy_image_to_3dread
meshy_image_to_imageread
meshy_list_modelsread
meshy_list_tasksread
meshy_multi_image_to_3dread
meshy_process_multicolorread
meshy_remeshread
meshy_repair_printabilityread
meshy_resizeread
meshy_retextureread
meshy_rigread
meshy_send_to_slicerwrite
meshy_text_to_3dread
meshy_text_to_3d_refineread
meshy_text_to_imageread
meshy_uv_unwrapread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/auth.test.mjs:23
return { requests, url: `http://127.0.0.1:${api.address().port}`, close: () => api.close() };
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, dotenv, express, zod, @types/express, @types/node, tsx
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha b8a8f0fca7edfull audit observations/trust-audit/mcp-server/meshy-dev__meshy.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08b8a8f0fca7edSAFEB89first audit
06

Questions

What is the Meshy MCP server?

MCP server for Meshy AI 3D generation platform

What tools does Meshy expose?

24 in total: 23 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Meshy safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Meshy need?

It reads MESHY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Meshy run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @meshy-ai/meshy-mcp-server at 0.6.1.

How current is this page?

The grade is for one exact copy of the source (b8a8f0fca7ed), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement