SketchupBLOCK
Sketchup Model Context Protocol
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
SketchupMCP connects Sketchup to Claude AI through the Model Context Protocol (MCP), allowing Claude to directly interact with and control Sketchup. This integration enables prompt-assisted 3D modeling, scene creation, and manipulation in Sketchup.
Big Shoutout to Blender MCP for the inspiration and structure.
Features
- Two-way communication: Connect Claude AI to Sketchup through a TCP socket connection
- Component manipulation: Create, modify, delete, and transform components in Sketchup
- Material control: Apply and modify materials and colors
- Scene inspection: Get detailed information about the current Sketchup scene
- Selection handling: Get and manipulate selected components
- Ruby code evaluation: Execute arbitrary Ruby code directly in SketchUp for advanced operations
Components
The system consists of two main components:
- Sketchup Extension: A Sketchup extension that creates a TCP server within Sketchup to receive and execute commands
- MCP Server (`sketchup_mcp/server.py`): A Python server that implements the Model Context Protocol and connects to the Sketchup extension
Installation
Python Packaging
We're using uv so you'll need to ``brew install uv``
Sketchup Extension
- Download or build the latest
.rbzfile - In Sketchup, go to Window > Extension Manager
- Click "Install Extension" and select the downloaded
.rbzfile - Restart Sketchup
Usage
Starting the Connection
- In Sketchup, go to Extensions > SketchupMCP > Start Server
- The server will start on the default port (9876)
- Make sure the MCP server is running in your terminal
Using with Claude
Configure Claude to use the MCP server by adding the following to your Claude configuration:
"mcpServers": {
"sketchup": {
"command": "uvx",
"args": [
"ske9e4279249c3cOBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add sketchup-mcp -- uvx sketchup-mcp
{
"mcpServers": {
"sketchup-mcp": {
"command": "uvx",
"args": [
"sketchup-mcp"
]
}
}
}Exposed tools (10)
4 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_component | write | Create a new component in Sketchup |
create_dovetail | write | Create a dovetail joint between two components |
create_finger_joint | write | Create a finger joint (box joint) between two components |
create_mortise_tenon | write | Create a mortise and tenon joint between two components |
delete_component | destructive | Delete a component by ID |
eval_ruby | read | Evaluate arbitrary Ruby code in Sketchup |
export_scene | read | Export the current scene |
get_selection | read | Get currently selected components |
set_material | write | Set material for a component |
transform_component | read | Transform a component |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
result = eval(params["code"], binding)
sketchup_mcp-0.1.0-py3-none-any.whl
delete_component
mcp, websockets, aiohttp
5. **Security**: Be careful when evaluating user-provided Ruby code, as it has full access to the SketchUp API.
Gates applied: no_behavioural_pass, no_license.
9e4279249c3cfull audit observations/trust-audit/mcp-server/mhyrr__sketchup-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | 9e4279249c3c | BLOCK | D | 69 | first audit |
Questions
What is the Sketchup MCP server?
Sketchup Model Context Protocol
What tools does Sketchup expose?
10 in total: 4 read-only, 5 that write, and 1 that can delete or overwrite (delete_component). Every one is listed on this page with its risk.
Is Sketchup safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Sketchup need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (9e4279249c3c), read on 2026-10-02. The repository is watched and re-audited when it changes.