Atlas / MCP servers / mhyrr / Sketchup

SketchupBLOCK

mcp/mhyrr/sketchup-1

Sketchup Model Context Protocol

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
10 4r · 5w · 1d
Transport
—
License
—
Stars
474
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

SketchupMCP connects Sketchup to Claude AI through the Model Context Protocol (MCP), allowing Claude to directly interact with and control Sketchup. This integration enables prompt-assisted 3D modeling, scene creation, and manipulation in Sketchup.

Big Shoutout to Blender MCP for the inspiration and structure.

Features

  • Two-way communication: Connect Claude AI to Sketchup through a TCP socket connection
  • Component manipulation: Create, modify, delete, and transform components in Sketchup
  • Material control: Apply and modify materials and colors
  • Scene inspection: Get detailed information about the current Sketchup scene
  • Selection handling: Get and manipulate selected components
  • Ruby code evaluation: Execute arbitrary Ruby code directly in SketchUp for advanced operations

Components

The system consists of two main components:

  1. Sketchup Extension: A Sketchup extension that creates a TCP server within Sketchup to receive and execute commands
  2. MCP Server (`sketchup_mcp/server.py`): A Python server that implements the Model Context Protocol and connects to the Sketchup extension

Installation

Python Packaging

We're using uv so you'll need to ``brew install uv``

Sketchup Extension

  1. Download or build the latest .rbz file
  2. In Sketchup, go to Window > Extension Manager
  3. Click "Install Extension" and select the downloaded .rbz file
  4. Restart Sketchup

Usage

Starting the Connection

  1. In Sketchup, go to Extensions > SketchupMCP > Start Server
  2. The server will start on the default port (9876)
  3. Make sure the MCP server is running in your terminal

Using with Claude

Configure Claude to use the MCP server by adding the following to your Claude configuration:

"mcpServers": {
"sketchup": {
"command": "uvx",
"args": [
"ske
Read from source at commit 9e4279249c3cOBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add sketchup-mcp -- uvx sketchup-mcp
claude-desktop
{
  "mcpServers": {
    "sketchup-mcp": {
      "command": "uvx",
      "args": [
        "sketchup-mcp"
      ]
    }
  }
}
03

Exposed tools (10)

4 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_componentwriteCreate a new component in Sketchup
create_dovetailwriteCreate a dovetail joint between two components
create_finger_jointwriteCreate a finger joint (box joint) between two components
create_mortise_tenonwriteCreate a mortise and tenon joint between two components
delete_componentdestructiveDelete a component by ID
eval_rubyreadEvaluate arbitrary Ruby code in Sketchup
export_scenereadExport the current scene
get_selectionreadGet currently selected components
set_materialwriteSet material for a component
transform_componentreadTransform a component
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
su_mcp/su_mcp/main.rb:1835
result = eval(params["code"], binding)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
.local-index/sketchup_mcp-0.1.0-py3-none-any.whl
sketchup_mcp-0.1.0-py3-none-any.whl
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_component
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, websockets, aiohttp
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
examples/README.md:81
5. **Security**: Be careful when evaluating user-provided Ruby code, as it has full access to the SketchUp API.

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-02 · audit v0.4.1 · source sha 9e4279249c3cfull audit observations/trust-audit/mcp-server/mhyrr__sketchup-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-029e4279249c3cBLOCKD69first audit
06

Questions

What is the Sketchup MCP server?

Sketchup Model Context Protocol

What tools does Sketchup expose?

10 in total: 4 read-only, 5 that write, and 1 that can delete or overwrite (delete_component). Every one is listed on this page with its risk.

Is Sketchup safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Sketchup need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (9e4279249c3c), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement